Scenario library / Insider threat
Insider Source Code Theft: a tabletop exercise scenario
A departing engineer copies repositories and a customer export to personal storage during their notice period. Detection lands two days before their last day.
75–90 min · Executive + HR + legal + technical

What this is modelled on
Modelled on departure-window insider cases, where an employee with legitimate access bulk-copies code and customer data in the weeks before resigning, and the organisation must act without alerting them prematurely.
Why it matters
Everything the insider did was authorised. The exercise tests evidence handling, employment law constraints and coordination between functions that rarely rehearse together.
Exercise objectives
- Rehearse evidence preservation before confrontation
- Test HR, legal and security coordination under time pressure
- Confirm access revocation sequencing for a leaver
- Assess monitoring coverage for bulk data movement
Decision points tested
- Confront now or gather more evidence first
- Revoke access immediately versus preserve activity visibility
- Injunctive action and competitor notification
- Internal messaging to the engineer's team
Sample inject timeline
- T+0
Alert
DLP flags a large transfer of repository archives to a personal account.
- T+20
Scope grows
A customer contact export is also found in the transfer.
- T+45
Competitor signal
The employee's new role is at a direct competitor, starting next week.
- T+65
Legal constraint
Counsel warns that device seizure requires specific process to remain usable.
What the after-action report should capture
- Evidence chain quality
- Leaver process and monitoring gaps
- Cross-function coordination speed
- Intellectual property control actions
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
