MOVEit Breach Tabletop Exercise: When Your Supplier Loses Your Data

MOVEit Breach Tabletop Exercise: When Your Supplier Loses Your Data
Your payroll provider emails you on a Wednesday: a zero-day in their file-transfer tool, already exploited. Your systems are fine. Your data isn't.
That was the reality for thousands of organisations in 2023. The MOVEit attack is the clearest example of a risk most tabletop exercises still skip: a breach that happens entirely outside your network.
This post is part of our Boardroom Drill series: one real incident, three leadership dilemmas, and a way to rehearse them.
What happened
On 31 May 2023, Progress Software disclosed a critical SQL injection flaw (CVE-2023-34362) in MOVEit Transfer, a tool many organisations use to exchange large files. The Cl0p criminal group had already been exploiting it for several days.
Cl0p didn't encrypt anything. It quietly stole files from MOVEit servers, then published victims' names on its leak site and demanded payment. Public trackers counted more than 2,500 affected organisations and tens of millions of individuals.
Many victims were hit indirectly. In the UK, staff data at the BBC, British Airways and Boots was exposed through their shared payroll provider, Zellis. Plenty of organisations learned they were affected from a supplier's email, or from the leak site itself.
Dilemma 1: Whose breach is it?
The data was yours. The server was your supplier's.
- Who notifies the regulator, and when does the clock start: when the supplier found out, or when they told you?
- Under GDPR and NIS2-style rules, you may still be the one responsible for the notification, even though you didn't run the system.
- Does your contract say how fast the supplier must tell you, and what they must share?
Discussion question: Do you know which suppliers hold your most sensitive data, and do you have a contact there for a Sunday-night incident?
Dilemma 2: Negotiate with a group that already has the files?
There's no encryption key to buy. The only thing on offer is a promise to delete the data, from a criminal group.
- Paying may keep your name off the leak site. It doesn't prove the files are gone.
- Not paying means your data may be published, and customers may hear about it there first.
- Your supplier may make its own choice, which affects your data, without asking you.
Discussion question: If your supplier decides to pay, or not to pay, do you have any say?
Dilemma 3: What do you tell staff before you know what was taken?
Payroll files hold names, addresses, bank details and national ID numbers. Employees will ask the moment the news breaks.
- Tell them early, with incomplete facts, and risk correcting yourself later.
- Wait for the forensic report, and risk them reading about it in the press first.
- Decide whether you offer credit monitoring or identity protection, and who pays for it: you or the supplier.
Discussion question: Who drafts the internal message, and who approves it? The CMT roles guide has a template for assigning this.
The lesson for leadership
Most of the hard questions in MOVEit weren't technical. They were about contracts, regulators and trust. That's why a third-party breach is a boardroom exercise, not just an IT one.
How to run this as a 45-minute tabletop
- Set the scene (5 min). Your payroll provider tells you it was hit by a zero-day. It doesn't yet know whose files were taken.
- Inject 1 (10 min). 48 hours later: your company appears on a leak site. The supplier still has no file list. Do you notify the regulator now?
- Inject 2 (10 min). The supplier says it is "considering its options" with the attackers. What do you ask for, and who asks?
- Inject 3 (10 min). An employee posts on LinkedIn asking why they heard about it from the news. What do you send to all staff today?
- Debrief (10 min). Which decisions depended on information only the supplier had? What would you change in your contracts?
Build it as a branching scenario in the builder, or play our SolarWinds supply-chain drill now, no signup, to see the format.
Related Reading
- Colonial Pipeline Tabletop Exercise — the shutdown decision, from the same series.
- Executive Cyber Drill vs. Technical Incident Response — why this one belongs in the boardroom.
- Incident Response Tabletop Exercise: Complete Guide — prep, facilitation and debrief.
Ready to Put This Into Practice?
Use our free scenario builder to create custom cyber tabletop exercises based on these strategies.


