The Poisoned Alliance
Third-Party Supply Chain Compromise
A trusted ally has been compromised. Your realm's managed services provider — once a stalwart guardian of your fortress walls — has fallen to dark forces. The enemy now holds the keys to your kingdom, and the true extent of the betrayal remains shrouded in fog.
Compliance Frameworks
🛡️ Roles & Party Members
War Chief Required
Incident CommanderLeads the response team, makes containment and escalation decisions
Arcane Engineer Required
IT Operations LeadProvides technical context, manages vendor access, proposes containment
Shadow Watcher Required
SOC AnalystConducts threat hunting, reviews authentication logs, monitors for compromise indicators
Keeper of the Codex Required
Compliance / DPOAssesses regulatory implications, manages SWIFT CSP obligations
Loremaster Optional
Legal CounselReviews vendor contracts, advises on liability and legal remedies
Alliance Keeper Optional
Third-Party / Vendor ManagerManages vendor relationship, coordinates incident response with SecureOps
High Council Elder Optional
Senior ManagementProvides executive decision authority, manages systemic risk implications
⚡ Inject Timeline
Vendor Notification — A Raven Bearing Dark Tidings
T+0 MinutesThe bank's managed IT services provider, 'SecureOps Ltd' (fictitious), has issued an urgent notification to all clients. SecureOps provides privileged remote access for system administration, patch ma...
Evidence of Access — The Enemy Was Already Inside
T+20 MinutesInternal threat hunting has identified suspicious activity. Authentication logs show that a SecureOps service account authenticated to three of the bank's domain controllers at 04:30 UTC, six days ago...
📋 Debrief Questions
Post-Battle Assessment
- Were vendor access controls adequate?
- Was the threat hunting response timely and effective?
- Were SWIFT CSP obligations understood and met?
- Were contractual protections with SecureOps adequate?
- What improvements should be made to third-party risk management?
- How should vendor access be restructured going forward?