🔓 Data Breach Response SimulatorConfigure the scenario, then start
Breach detected. Choose your containment approach:
Isolate Systems Now
Investigate Full Scope First
Containment underway. Choose disclosure timing:
Notify Regulators & Customers Now
Wait for Full Scope Assessment
Records exposed (running)
0
How this model works
A breach starts at the public web server and spreads to connected systems each hour with a
probability set by your network segmentation — tighter segmentation slows lateral movement.
Monitoring investment sets the hourly chance the breach is detected. Once detected, choosing
Isolate Now stops new infections immediately but may leave 1–2 already-compromised systems
unidentified for a few hours (a real "blind spot" effect of moving before the investigation
finishes), while Investigate First keeps the breach spreading a little longer but guarantees
an accurate scope once contained. Notifying before the scope is fully known can under-report the
damage — discovered later as a follow-up disclosure penalty — and notifying more than 72 simulated
hours after detection triggers a late-disclosure fine multiplier, mirroring real breach-notification
deadlines. Final cost = records exposed × cost/record + regulatory fine (scaled by lateness and
under-reporting).
Configure the sliders, then Start Incident — decisions appear as the scenario unfolds