15 Minute Tabletop:
Publicly Facing
Misconfigured Machine
About 15 Minute Exercises
This presentation is customizable and includes template exercise objectives, scenarios, and discussion questions as well as a collection of references and resources. While this exercise can be used as-is, it can and should be customized to be more realistic for your organization. For example, you can name systems that you operate and department or team names that are specific to your organization.
License Note: This presentation is shared under Creative Commons Licensing CCBY https://creativecommons.org/licenses/by/4.0/.
If you are a school district in Michigan and need assistance running a tabletop exercise, reach out to the MISecure team.
We strongly recommend that you develop a cybersecurity incident response plan prior to running tabletop exercises. For a starting point, try the MiSecure Incident Response Planning templates (https://misecure.org/incident-response-planning-tools/)
Facilitator Notes
Focused Scope: Because the time is limited to 15–30 minutes, keep the discussion narrow. Don't try to solve the entire incident; focus on the first steps the team would take or the primary communication hurdle.
Exercise Goal | Key Participants | Length | Incident Severity |
Walk through response to learning that one of your internet-facing machines is misconfigured. | Tech Team/�Cyber Incident Response Team | 15-30 minutes | Medium |
MISecure Operations Center Calls
MISecure Operations Center Calls and informs you that you have a vulnerable server that is exposed to the internet and it might have been hacked. It appears that the server was misconfigured with SSH (22) and RDP (3389) enabled.
MISecure Operations Center Calls
MISecure Operations Center Calls and informs you that you have a vulnerable server that is exposed to the internet and it might have been hacked. It appears that the server was misconfigured with SSH (22) and RDP (3389) enabled.
Discussion
Check Your Work
Are you able to identify a machine quickly and scan it on your own for vulnerabilities?
Review log files for anomalous or malicious activity?
Determine if there was lateral movement - did this server interact abnormally with others?
Quickly remove server from the internet?
Do you have standard configurations for servers?
Do you review your externally facing machines for vulnerabilities and compromises?
Are you subscribed to the free CISA Cyber Hygiene scanning service? https://www.cisa.gov/cyber-hygiene-services
Hotwash
MISecure Incident Response Planning Tools
MISecure Cybersecurity Tabletop Exercise Library
Full TTX Library at: https://misecure.org/tabletop-exercises/
Michigan Incident Response Contacts
For School Districts in Michigan:
MISecure Operations Center �989-763-5797 �misecure@gomaisa.org
For School Districts and other entities in Michigan:
Michigan State Police Cyber Command Center �877-MI-CYBER �mc3@michigan.gov