🔓 Data Breach Response SimulatorConfigure the scenario, then start

Start Incident

Breach detected. Choose your containment approach:

Isolate Systems Now
Investigate Full Scope First

Containment underway. Choose disclosure timing:

Notify Regulators & Customers Now
Wait for Full Scope Assessment
Elapsed
0.0 h
Compromised nodes
0 / 10
Records exposed (running)
0
How this model works
A breach starts at the public web server and spreads to connected systems each hour with a probability set by your network segmentation — tighter segmentation slows lateral movement. Monitoring investment sets the hourly chance the breach is detected. Once detected, choosing Isolate Now stops new infections immediately but may leave 1–2 already-compromised systems unidentified for a few hours (a real "blind spot" effect of moving before the investigation finishes), while Investigate First keeps the breach spreading a little longer but guarantees an accurate scope once contained. Notifying before the scope is fully known can under-report the damage — discovered later as a follow-up disclosure penalty — and notifying more than 72 simulated hours after detection triggers a late-disclosure fine multiplier, mirroring real breach-notification deadlines. Final cost = records exposed × cost/record + regulatory fine (scaled by lateness and under-reporting).
Configure the sliders, then Start Incident — decisions appear as the scenario unfolds

Incident Closed

–
Total records exposed–
Direct breach cost–
Regulatory fine–
Total incident cost–
Reputation score–
Notification timeliness–
Scope reported accurately–
Run New Scenario

Illustrative decision model for teaching incident-response trade-offs — cost and fine figures are simplified stand-ins for real breach-cost and regulatory-notification research, not legal or financial guidance.