1 of 27

Day 1 Group Exercise

Agency Exposure Assessment

[Names of Group Members]

2 of 27

Exercise Objective

  • Assess digital footprint, breach exposure, internet-facing assets, and threat intelligence exposure of agencies represented in your group.

3 of 27

Scenario

  • Leadership wants to know what information about personnel, systems, and agencies is already visible on the Internet.

4 of 27

Group Composition

  • 4-6 participants. Assign Team Leader, Research Lead, Infrastructure Analyst, Exposure Analyst, Presenter.

5 of 27

Rules of Engagement

  • Use only public information. No hacking, bypassing controls, downloading illegal data, or unauthorized access.

6 of 27

Investigation Workflow

  • Digital Footprint → Breach Exposure → Infrastructure Exposure → Threat Intelligence → Risk Assessment → Action Plan.

7 of 27

Tools to Use

  • BuiltWith, Wayback Machine, Have I Been Pwned, DeHashed, Shodan, SOCRadar, SpyCloud.

8 of 27

Task 1 – Digital Footprint

  • Identify websites, subdomains, technologies, archived content, exposed information, and employee references.

9 of 27

Task 2 – Breach Exposure

  • Determine whether agency emails, employees, or credentials appear in known breaches.

10 of 27

Task 3 – Infrastructure Exposure

  • Identify public-facing systems, VPNs, servers, administrative interfaces, and visible technologies.

11 of 27

Task 4 – Threat Intelligence

  • Review dark web and threat intelligence sources for agency mentions, leaks, and exposures.

12 of 27

Agency Assessment Template

  • Agency Name, Representatives, Findings, Sources, Risks, and Observations.

13 of 27

Risk Assessment Methodology

  • Risk Score = Likelihood × Impact.

14 of 27

Likelihood Scale

  • 1 Very Low, 2 Low, 3 Medium, 4 High, 5 Very High.

15 of 27

Impact Scale

  • 1 Very Low, 2 Low, 3 Medium, 4 High, 5 Very High.

16 of 27

Risk Matrix

  • Use the 5x5 matrix to determine overall risk level.

17 of 27

Risk Register Template

  • Finding | Likelihood | Impact | Risk Score | Risk Level | Recommended Action

18 of 27

Action Plan Development

  • Create Immediate (0–30 days), Short-Term (1–3 months), and Long-Term (3–12 months) actions.

19 of 27

Comparative Analysis

  • Compare agencies represented in the group and identify common exposure themes.

20 of 27

Executive Summary

  • Largest attack surface, highest breach exposure, strongest posture, common issues, and priorities.

21 of 27

Presentation Requirements

  • 10-minute briefing covering findings, risks, and action plan.

22 of 27

Deliverables

  • Completed assessment template, risk register, executive summary, and presentation deck.

23 of 27

5x5 Risk Matrix Reference

  • Critical: 21-25
  • Very High: 16-20
  • High: 11-15
  • Moderate: 6-10
  • Low: 1-5

  • Risk Score = Likelihood × Impact

24 of 27

Risk Assessment Methodology

After identifying findings, the group shall evaluate each finding using:

Likelihood

How likely is it that the finding can be exploited or abused?

Impact

If exploited, how severe would the consequences be to the agency

25 of 27

Likelihood Rating Guide

Score

Rating

Description

1

Very Low

Unlikely to occur. Requires specialized capability, resources, or insider access.

2

Low

Possible but difficult to exploit. Limited exposure exists.

3

Medium

Exploitation is reasonably possible using publicly available information or tools.

4

High

Exploitation is likely. Exposure is easily discoverable and actionable.

5

Very High

Active exposure exists and can be exploited immediately with minimal effort.

26 of 27

Impact Rating Guide

Score

Rating

Description

1

Very Low

Minimal operational impact. Little to no effect on agency operations.

2

Low

Limited impact affecting a small number of users or systems.

3

Medium

Noticeable impact affecting a department or service.

4

High

Significant disruption affecting multiple units, operations, or sensitive information.

5

Very High

Severe impact affecting mission-critical operations, public trust, national security, or large-scale data exposure.

27 of 27

Risk Rating Interpretation

Score

Risk Level

Recommended Action

1–5

Low

Monitor and address as resources permit.

6–10

Moderate

Management attention recommended. Plan corrective actions.

11–15

High

Prioritize remediation and assign ownership.

16–20

Very High

Immediate action required. Senior leadership attention recommended.

21–25

Critical

Urgent action required. Significant agency exposure exists.