mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.2 KiB
2.2 KiB
Ransomware Tabletop Exercise Template
Exercise Overview
| Field | Value |
|---|---|
| Exercise Name | |
| Date | |
| Duration | 3-4 hours |
| Facilitator | |
| Scenario | [Threat Actor] ransomware attack |
| Industry |
Participants
| Name | Role | Department | Present (Y/N) |
|---|---|---|---|
| CISO | Security | ||
| CIO | IT | ||
| General Counsel | Legal | ||
| VP Comms | PR | ||
| COO | Operations | ||
| CFO | Finance |
Phase 1: Detection SITREP
[Insert scenario text]
Discussion Questions
- Who declares the incident?
- What is the immediate containment action?
- Who is notified at this stage?
Decisions Made
| Decision | Rationale | Owner |
|---|---|---|
Phase 2: Escalation SITREP
[Insert scenario text]
Discussion Questions
- What is the scope assessment process?
- How do we maintain business operations?
- Do we engage law enforcement?
Decisions Made
| Decision | Rationale | Owner |
|---|---|---|
Phase 3: Critical Decisions SITREP
[Insert scenario text]
Discussion Questions
- Under what conditions do we pay?
- What are notification obligations?
- How do we respond to data leak?
Decisions Made
| Decision | Rationale | Owner |
|---|---|---|
Phase 4: Recovery SITREP
[Insert scenario text]
Discussion Questions
- What is recovery priority order?
- What do we tell customers?
- What is the media statement?
Decisions Made
| Decision | Rationale | Owner |
|---|---|---|
Evaluation Scorecard
| Area | Score (1-5) | Notes |
|---|---|---|
| Detection & Escalation | ||
| Containment | ||
| Internal Communication | ||
| External Communication | ||
| Recovery Planning | ||
| Legal & Compliance | ||
| Business Continuity | ||
| Payment Decision | ||
| Overall |
Key Findings
Strengths
Gaps
| Gap | Severity | Owner | Remediation | Deadline |
|---|---|---|---|---|
| Critical/High/Medium |
Sign-Off
| Role | Name | Signature | Date |
|---|---|---|---|
| Exercise Sponsor | |||
| Facilitator |