# project / synthetic incident-response case study
INCIDENT RESPONSE · CUI · ENTRA · FORTIGATE · SPLUNK · DATTO · TABLETOP
Asterion Defense Systems: the operational follow-up
This is the response program that follows the Asterion NIST readiness assessment. It takes the six GRC findings and turns them into roles, provider handoffs, evidence requirements, playbooks, recovery gates, communications, and a realistic ransomware/CUI-exfiltration tabletop.
Asterion Defense Systems is fictional. The company, architecture, evidence, providers, scores, owners, dates, and incident scenarios are synthetic. This is an operational design exercise—not a representation of a real employer, customer, incident, certification, or legal determination.
Asterion may support programs involving classified information, including Top Secret material, but that work is handled in a separate accredited facility and classified information system boundary. Classified systems and handling are not stored in, transmitted through, or assessed by this unclassified corporate/CUI incident-response program.
01 / GRC → IR handoff
The response program begins where the assessment leaves off
The companion GRC assessment found an incomplete CUI boundary, inconsistent privileged access, telemetry gaps, weak transfer evidence, unproven restoration, and immature incident/supplier processes. This page is the operational answer to those findings.
Workbook transcription, six findings, risk register, evidence register, and six-action POA&M.
Directive plan, provider model, playbooks, detection evidence, recovery runbook, case forms, and tabletop.
Exercise and incident lessons return to the risk register, owners, due dates, detections, and retest evidence.
02 / architecture and trust boundaries
Response decisions follow the actual environment
The fictional environment has one ISP, one FortiGate edge, Microsoft Entra ID, an on-premises directory dependency, Windows laptops and desktops, one file server, one application server, one SQL server, Splunk, Datto BCDR, and two separate third-party providers.
EDGE-FGT-01
Internet edge
One ISP → FortiGate perimeter firewall
Preserve traffic, VPN, policy, admin, and configuration-change evidence; use the edge as one containment control.
CORE-CISCO-01
Core switching
Cisco internal switching and segmented networks
Record isolation changes, affected VLAN/path, approving owner, and rollback condition.
ENTRA-01
Cloud identity
Microsoft Entra ID is the primary cloud identity plane
Disable or restrict identities, revoke sessions, review privileged roles, and preserve sign-in/audit evidence.
AD-DC01
Directory dependency
On-premises Windows domain controller
Scope for lateral movement, privileged access, authentication, and recovery dependencies.
FS01
File services
Windows file server for shared engineering and business data
Check share access, mass-change indicators, staged archives, permissions, and restore-point integrity.
APP01 / SQL01
Application tier
Windows application server with SQL database dependency
Contain credentials separately; validate application behavior, database access, and transaction integrity.
SPLUNK-01
Detection
Splunk SIEM receiving identity, endpoint, server, and network telemetry
Record source health, query window, query owner, evidence export location, and retention limits.
BAK-REPO-01
Recovery
Datto BCDR protection with cloud recovery copies
Protect the backup plane, preserve retention changes, and restore only from a trusted isolated recovery point.
ENDPOINTS
Workstations
Windows laptops and desktops
Isolate affected endpoints, preserve host context, collect Defender/Windows evidence, and reimage when required.
The CUI engineering enclave is the primary boundary for this exercise. Classified operations remain a separate accredited system and are excluded from these response decisions.
03 / roles and provider handoffs
Providers execute tasks; the organization owns the decision
The third-party SOC and third-party IT company are intentionally separate. The SOC provides monitoring and investigation. IT provides infrastructure execution and recovery. The internal security/GRC lead owns incident command, CUI-impact decisions, communications, and corrective actions.
Internal security / GRC lead
Declares and leads the incident, assesses CUI impact, sets communications cadence, owns evidence quality, and assigns corrective actions.
Third-party SOC company
Monitors, triages, investigates in Splunk, preserves telemetry, tunes detections, escalates, and hands off with timestamps and queries.
Third-party IT company
Executes approved FortiGate, Entra, Windows, server, and Datto actions; records technical changes and supports recovery.
Leadership / service owners
Accept business risk, prioritize recovery, approve customer/contract decisions, and authorize return to service.
04 / master response lifecycle
A common clock keeps the response usable under pressure
- 01Detect and open
Open one case, capture the initial signal, assign an incident lead, preserve the time window, and record unknowns.
- 02Classify and scope
Identify affected users, endpoints, servers, network paths, providers, data types, and possible CUI exposure.
- 03Contain deliberately
Choose identity, endpoint, network, server, or backup-plane containment with an owner, expected impact, rollback condition, and timestamp.
- 04Eradicate and validate
Remove persistence, rotate exposed secrets, close the entry path, verify telemetry, and confirm that the threat is no longer active.
- 05Recover from trusted state
Restore in an isolated network, validate identity and application dependencies, confirm data integrity, and document RTO/RPO.
- 06Communicate and close
Provide scheduled leadership updates, coordinate customer/contract decisions through authorized owners, and close only after actions are assigned.
05 / playbook catalog
Five playbooks cover the highest-consequence paths
Trigger: Mass file changes, ransom note, archive staging, or suspicious transfer from FS01/engineering endpoints.
First move: Isolate endpoints; protect identity and backup planes; preserve evidence; assess CUI impact before broad restore.
Trigger: Risky sign-in, MFA abuse, token/session anomaly, unexpected role assignment, or admin activity outside change windows.
First move: Restrict identity, revoke sessions, scope downstream access, and verify persistence/new privileged principals.
Trigger: Defender alert, suspicious PowerShell, persistence, credential theft, or lateral movement from a laptop/desktop.
First move: Network-isolate, preserve host context, scope adjacent systems, then remediate or reimage from a trusted baseline.
Trigger: Datto retention change, protected-device deletion, unusual console access, or failed jobs during an incident.
First move: Protect Datto administration, preserve console evidence, validate recovery points, and restore only in isolation.
Trigger: Mailbox rule, credential phishing, payment fraud, supplier impersonation, or suspicious forwarding.
First move: Contain identity/mailbox persistence, validate requests out of band, and check for CUI access or forwarding.
06 / detection and evidence
Telemetry is part of the response product
The SOC must preserve enough context for the organization to explain what happened, what was affected, what was contained, and why recovery was trusted. Missing source coverage is recorded as a response limitation and a corrective action—not silently treated as “no evidence.”
Identity
Entra sign-in/audit logs, risky sign-ins, privileged-role changes, MFA and session state
SOC / security lead
Perimeter
FortiGate traffic, VPN, admin, policy, and configuration-change logs
IT provider / SOC
Windows
Defender alerts, Security logs, PowerShell, tasks, services, autoruns, and endpoint timeline
SOC / IT provider
File activity
FS01 share access, mass-change indicators, staged archives, permissions, and shadow-copy status
IT provider
Application / SQL
APP01 application logs, SQL01 authentication, query, job, and integrity indicators
Application owner / IT provider
Backups
Datto job history, retention changes, protected-device status, recovery points, and restore logs
IT provider / security lead
07 / case records and communications
The program produces records that can survive handoffs
Record affected account/assets, source signal, current confidence, business owner, and next update time.
Capture containment, recovery, notification, and risk-acceptance decisions with the assumption being made.
Preserve query names, export locations, source systems, collection times, and chain-of-custody notes.
Close only after eradication, recovery validation, communications, lessons learned, and POA&M linkage are complete.
Leadership update
Decision support
Known impact, unknowns, containment, business effect, current risk, next decision, and next update time.
Provider handoff
Execution clarity
Case ID, action requested, affected asset/account, evidence location, approval, rollback, and completion criteria.
Customer/contract review
Authorized external decision
Facts only, CUI/classification assessment status, contract owner, approval path, and unresolved questions.
Closure summary
Accountability
Timeline, root cause, affected scope, recovery result, residual risk, corrective actions, and retest owner/date.
08 / tabletop exercise
A realistic inject tests the seams between teams
The exercise starts with an Entra alert and ends with an isolated Datto recovery. It crosses the SOC, IT provider, security/GRC lead, leadership, and business owners so it tests coordination—not just whether one person knows a command.
01 / detect
SOC receives an Entra risky-sign-in alert for a user who recently accessed engineering shares.
Who opens the case, what severity is declared, and what evidence is preserved before account action?
02 / scope
The user’s Windows laptop shows PowerShell activity and an archive staged for transfer.
How do SOC and IT isolate the endpoint while security assesses possible CUI exposure?
03 / contain
FS01 begins rapid file modifications; APP01 and SQL01 remain available.
Which systems are isolated, who approves the boundary change, and how is continuity weighed?
04 / recover
A Datto retention policy was modified shortly before the file changes were detected.
How is the backup plane protected, and what makes a recovery point trusted?
05 / communicate
Leadership asks about customer notification, contract review, and law-enforcement coordination.
What is known, what is unknown, who approves external communication, and when is the next update?
06 / improve
The enclave is restored in isolation and a telemetry gap is found.
Which actions become POA&M updates, detections, provider-SLA changes, or training tasks?
Who decided what, when, with which evidence, and what assumption remained open.
Participants identify the boundary, protect the backup plane, and choose a trusted restore path.
Every gap becomes an owner, due date, evidence requirement, and retest condition.
Score time to declare, time to isolate, evidence quality, provider handoff quality, and recovery confidence.
09 / recovery and validation
Recovery is not complete until the service and evidence agree
Secure Datto administration, preserve policy changes, validate recovery points, and use an isolated restore network.
Check AD-DC01 identity dependency, FS01 data integrity, APP01 behavior, and SQL01 authentication and transactions.
Confirm Entra, FortiGate, Windows, server, and Splunk visibility before reconnecting systems.
Leadership and the service owner accept recovery results, customer impact, residual risk, and remaining actions.
10 / embedded artifact index
The supporting files are represented inside the page
The source package is translated into readable web sections rather than hidden behind download links. This index makes the relationship explicit and gives each artifact a visible home in the case study.
incident-response-plan.md
Master plan
Scope, severity, roles, provider handoffs, evidence, containment, eradication, recovery, closure, metrics.
architecture-and-assumptions.md
Architecture
Trust boundaries, asset identifiers, system dependencies, assumptions, and the CUI boundary.
playbooks/01–05
Five playbooks
Enclave ransomware/CUI exfiltration, Entra compromise, Windows compromise, backup compromise, and phishing/BEC.
provider-raci-and-sla.md
Provider operating model
Separate third-party IT and SOC responsibilities, escalation, evidence requirements, and no-unilateral-closure rule.
splunk-detection-catalog.md
Detection catalog
Identity, endpoint, FortiGate, Windows, file activity, and backup-plane detection priorities.
datto-bcdr-recovery-runbook.md
Recovery runbook
Backup-plane protection, trusted restore-point selection, isolated restoration, validation, and return-to-service gates.
incident-case-forms.md
Case records
Minimum incident record, evidence log, decision log, containment record, recovery record, and closure checklist.
communications-templates.md
Communications
Leadership update, provider handoff, internal notice, customer/contract decision, and closure language.
tabletop-exercise.md
Tabletop
Entra alert → Windows compromise → CUI staging → FS01 ransomware → Datto recovery → after-action review.
grc-ir-crosswalk.md
GRC linkage
F-001 through F-006 mapped to operational response controls, POA&M closure, and retest evidence.
methodology-and-csf-profile.md
Method
Synthetic scope, NIST SP 800-171 Rev. 3 / CSF 2.0 relationship, limitations, and measurement model.
11 / GRC-to-IR crosswalk
Every major finding has an operational response hook
Read the assessment first, then follow the findings into response design, exercise evidence, and POA&M closure.
F-001 / boundary and assets
IR-01 / IR-03
The boundary map and asset register define the identities, endpoints, servers, controls, and providers to search and contain.
F-002 / privileged access
IR-02 / IR-04
Entra roles, FortiGate administration, Datto console access, and provider access are explicit containment decisions.
F-003 / telemetry
IR-01 / IR-03
Splunk source health and Windows/FortiGate/Entra coverage are part of triage; gaps are recorded as response limitations.
F-004 / CUI transfer
IR-01 / IR-05
Archive staging, forwarding, removable media, and supplier exchange paths are investigated as possible CUI movement.
F-005 / recovery evidence
IR-04
Datto recovery-point integrity, isolated restoration, RTO/RPO results, and corrective actions close the recovery gap.
F-006 / response and suppliers
IR-01 through IR-05
The plan, provider model, tabletop, and after-action workflow turn the finding into an operating capability.
Return to the Asterion NIST readiness assessment ↗ to start with the scope, exact maturity values, six findings, risk register, evidence register, and POA&M.