ARTIFACT 01 / SECURITY OPERATIONS SOC investigation record A synthetic impossible-travel alert carried from triage rationale through evidence review and a human containment decision.
Download Markdown
Case SYN-IR-2026-014
Severity Medium, reduced to informational
Owner Synthetic SOC analyst
Evidence boundary Test identity and fixture logs only Alert and hypothesis Two synthetic sign-ins appeared in Auckland and Frankfurt test zones within nine minutes. Initial hypothesis: compromised valid account or pre-approved identity simulation. Evidence reviewed Identity risk event IR-EVT-0031 showed one denied MFA prompt. Device fingerprint TEST-DEVICE-09 matched the exercise register. Exercise controller record EX-2026-07 confirmed the approved test window. Decision record Analyst recommended simulated session revocation pending controller confirmation. Human incident lead rejected containment after validating the exercise record. No live session, identity or policy was changed. Follow-up Add exercise-register context to the triage runbook. Measure time from alert creation to exercise-controller confirmation. Example status: Closed - benign exercise activity confirmed
ARTIFACT 02 / GOVERNANCE CISO decision record A synthetic vendor exception showing the evidence, options, accountable owner, expiry and review conditions behind a risk decision.
Download Markdown
Decision SYN-DEC-2026-008
Risk Third-party recovery evidence gap
Accountable owner Synthetic service owner
Authority Human approval required Evidence Supplier provided a current security summary but no witnessed restore-test record. Business service has a documented four-hour recovery objective. Replacement within the current quarter would create a higher transition risk. Options considered Reject the supplier until restore evidence is available. Accept indefinitely without additional controls. Approve a time-limited exception with a witnessed restore test and alternate export path. Decision Approve the time-limited exception. Service owner must witness a restore test by 31 August 2026. Data owner must validate a documented export path and retain the result. Review triggers Missed evidence deadline. Material supplier incident or service change. Change to recovery objectives or data classification. Example status: Approved with conditions - review due 30 September 2026
ARTIFACT 03 / SECURITY VALIDATION Purple-team coverage report A benign synthetic validation that separates observed evidence, missing signals and the owned detection work that follows.
Download Markdown
Exercise SYN-PT-2026-005
Technique T1078 - Valid Accounts
Scope Dedicated identity in test tenant
Method Pre-agreed anomalous sign-in Expected evidence Identity sign-in event with test account and device fingerprint. MFA outcome and session-risk change. SOC alert linked to the exercise identifier. Observed Sign-in and MFA events arrived within two minutes. Identity alert included source region and device context. Exercise identifier was absent from the SOC case. Gap and improvement Gap: analysts had to consult the exercise calendar manually. Improvement: enrich cases with active exercise windows and named controller. Owner: detection engineering; target validation: 14 August 2026. Safety record Written scope and stop conditions confirmed before validation. No production identity, confidential data or disruptive action used. Example status: Validated with one telemetry improvement open
ARTIFACT 04 / IMPROVEMENT PLANNING vCISO 30/60/90-day roadmap A synthetic roadmap that turns an assessment baseline into sequenced work with owners, evidence and review points.
Download Markdown
Organisation Koru Services (synthetic)
Baseline Moderate risk, 58/100
Top gaps MFA, restore testing, supplier access
Review cadence Fortnightly owner check-in Days 1-30 - reduce immediate exposure Require MFA for email, administrators and the domain registrar. Name incident contacts and publish a hacked-mailbox checklist. Record critical suppliers and current access paths. Days 31-60 - prove recovery and ownership Run a restore test for one critical business process. Remove dormant supplier and leaver accounts. Assign owners and due dates to the remaining baseline gaps. Days 61-90 - validate and govern Run a short incident tabletop using the updated contact list. Review DMARC monitoring and decide whether enforcement is ready. Present completed evidence, accepted risks and the next-quarter plan. Measures MFA coverage for important accounts. Restore-test outcome and recovery time. Percentage of critical suppliers with reviewed access and contacts. Example status: Draft for accountable-owner review