SolarWinds Tabletop Exercise: A Supply-Chain Attack Scenario for Leadership Teams

SolarWinds Tabletop Exercise: A Supply-Chain Attack Scenario for Leadership Teams
Your organisation just learned that its network-monitoring vendor shipped you a backdoor. Nothing is down. Nothing looks wrong. What do you do in the first two hours?
That's the starting point of our free SolarWinds scenario, and the reason it's the most-played exercise on CyberWar24. A supply-chain attack breaks the usual incident playbook: there's no outage to fix, only a trusted tool you can no longer trust.
This post is part of our Boardroom Drill series: one real incident, three leadership dilemmas, and a way to rehearse them.
What happened
Between March and June 2020, attackers later attributed by the US and UK governments to Russia's foreign intelligence service (SVR) inserted malicious code, known as SUNBURST, into updates for SolarWinds Orion, a widely used IT monitoring platform.
About 18,000 customers installed the infected update. The attackers then chose a much smaller group for deeper intrusion, including US government agencies and major technology companies. The campaign was discovered in December 2020, when the security firm FireEye found it while investigating a breach of its own network.
The US cybersecurity agency CISA issued an emergency directive ordering federal agencies to disconnect or power down affected Orion systems immediately.
Dilemma 1: Pull the tool now, or watch quietly?
- Pull it: you cut the attacker's channel, but you go blind on the monitoring the tool provided, and the attacker may already have other ways in.
- Watch: you can learn what the attacker touched and scope the intrusion, but you leave a known backdoor open while you do it.
- Either way, IT can't make this call alone. It changes the organisation's risk for days.
Discussion question: Who decides between containment and investigation, and what information do they need first?
Dilemma 2: When do you tell the regulator?
You don't know yet whether you were one of the 18,000 or one of the few the attackers went deeper into.
- Many regulations start the clock when you become aware of a significant incident, not when you finish investigating. Under NIS2, an early warning is due within 24 hours.
- Notify too early and you may report something that turns out minor. Notify too late and the delay becomes its own finding.
- Supply-chain incidents also raise disclosure questions for listed companies. In 2023 the US SEC charged SolarWinds and its CISO over its disclosures; most of those claims were later dismissed, but the case put boards on notice.
Discussion question: What counts as "aware" in your organisation, and who signs the first notification?
Dilemma 3: Who owns the business trade-off?
Shutting down the monitoring platform may break service-level commitments to customers. The CFO asks about penalties. The CISO asks for time.
- Security wants certainty. The business wants continuity. Both are right.
- Without a named owner, the trade-off gets made by whoever speaks loudest in the room.
Discussion question: Is there one person with the authority to accept business disruption for security reasons? Our Crisis Management Team roles guide shows where this usually sits.
Play it now
You don't need to build anything to try this one. Play the SolarWinds boardroom drill free, no signup. It takes about 15 minutes and scores your decisions on availability, confidentiality, integrity, reputation and compliance.
To run it with your leadership team, use Facilitator Mode: one shared screen for the room and a private control panel for you.
Related Reading
- Golden SAML Attacks: Why Your ADFS Is the Real Target — the identity technique used in the SolarWinds campaign.
- MOVEit Breach Tabletop Exercise — another supplier-driven crisis from the same series.
- Executive Cyber Crisis Drill: Board-Ready Simulation Guide — how to run drills for leadership.
Ready to Put This Into Practice?
Use our free scenario builder to create custom cyber tabletop exercises based on these strategies.


