About this session
Jake Alosco and Jeffrey Wu of Immersive Labs run a live, audience-voted crisis simulation instead of a slide deck, casting participants as the crisis-management team of a fictional oil transporter, Providence Pipelines, loosely modelled on the 2021 Colonial Pipeline ransomware attack. Attendees vote anonymously at each decision point while an on-screen map and metrics (oil price, operational capacity, return to operations) react to their choices. The scenario branches through a Friday-afternoon compromise: contain the affected computers or shut down the corporate and operations networks; pay the DarkSide ransom or restore from backups; how to communicate with suppliers, public and press; how to prioritise people, environment, security or compliance; how to allocate scarce fuel; a mid-incident website outage that may be a fresh attack or proactive containment; and finally how transparent to be in the root-cause report once Cobalt Strike and BloodHound are identified. The hosts narrate the trade-offs behind each option (business loss versus safety, moral stance versus reliable recovery, transparency versus reputational risk) and stress that surfacing every team member's view, not just the loudest voices, is the real value of tabletop exercises. They close noting the simulations are fully customisable per role and team.
When the worst happens not even the best incident response plans can account for the human element. You might know how your tech will work under pressure but what about you and your people? In this interactive session, you’ll use your decision-making skills to find the threat and manage the growing crisis.
Join this session to:
- See the real time impact of the human element in crisis management and response
- Gain a greater understanding of how decisions in a threat scenario have a business-wide impact
- Discover how to strengthen your organization on both sides of “the boom”, so it’s as ready before the impact as it is after it
Key takeaways
- Rehearse ransomware decisions before a real crisis: containment versus full shutdown, paying versus restoring, and communications all have to be made fast and under pressure.
- Verify that backups are clean and reachable before relying on them; restoring to a day before the breach can reinstate the compromise, and cloud backups may themselves be encrypted.
- Treat incident communications as a core decision, weighing transparency that builds trust and helps peers against the risk of panic, reputational harm or regulatory exposure.
- Supply-chain attacks are common, so hold partners and subsidiaries to your own security and compliance standards; the pivot often comes through a less-secured third party.
- Run tabletop exercises that capture every participant's vote, not just the loudest voices, to expose how divided a team really is and align the incident response plan.
Speakers

Jeffrey Wu serves as an Enterprise Sales Engineer for Immersive Labs, helping organizations to optimize their cyber workforces to meet ever-evolving threats. Prior to Immersive Labs, Jeffrey held Engineering roles at VMware, Carbon Black, and United… Read moreRead less
Jeffrey Wu serves as an Enterprise Sales Engineer for Immersive Labs, helping organizations to optimize their cyber workforces to meet ever-evolving threats. Prior to Immersive Labs, Jeffrey held Engineering roles at VMware, Carbon Black, and United Electronic Industries. Jeffrey graduated from Tufts University with a BS in Electrical Engineering.

Jake Alosco is Senior Director of Channel Sales at Immersive Labs, working closely with partners to help business leaders drive Cyber Workforce Optimization within their organization. Prior to Immersive Labs, Jake held various channel specific roles… Read moreRead less
Jake Alosco is Senior Director of Channel Sales at Immersive Labs, working closely with partners to help business leaders drive Cyber Workforce Optimization within their organization. Prior to Immersive Labs, Jake held various channel specific roles for Contrast Security, Avecto, and Veracode.

