Scenario library / Destructive attack

Hypervisor and Backup-Targeted Attack: a tabletop exercise scenario

Backup jobs fail overnight and the backup catalogue is gone. Virtualisation hosts are then encrypted, taking several production workloads down at once.

90 min · Executive + infrastructure + technical

Abstract graphic representing hypervisor and backup-targeted attack

What this is modelled on

Modelled on intrusions that deliberately attack the recovery layer first: backup catalogues are deleted, repositories are encrypted and virtualisation hosts are targeted directly so that restoration is not an option.

Why it matters

Recovery plans usually assume backups survive. When they do not, the organisation is deciding between prolonged outage, partial rebuild and rebuilding trust in its own platform.

Exercise objectives

  • Test recovery planning when the backup layer is compromised
  • Confirm immutable or offline copy coverage
  • Rehearse prioritisation of workload restoration
  • Assess rebuild-versus-restore decision criteria

Decision points tested

  • Rebuild clean or restore from a copy of uncertain integrity
  • Restoration priority and who arbitrates
  • Whether to declare a prolonged outage externally
  • Platform trust criteria before resuming normal operations

Sample inject timeline

  1. T+0

    Backup failures

    Overnight jobs fail and the backup management console is inaccessible.

  2. T+20

    Hosts down

    Two virtualisation clusters are encrypted; four business services are offline.

  3. T+45

    Copy check

    The only untouched copy is older than the last significant configuration change.

  4. T+70

    Restoration order

    Two business units each claim priority for the first restored service.

What the after-action report should capture

  • Immutable backup coverage findings
  • Recovery time versus documented objectives
  • Prioritisation decision process
  • Platform hardening actions

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.