ThreatGEN
Back to case studies

Case Study

Tabletop vs. the Shutdown: What Ten Colonial Pipeline Exercises Missed

This case study examines a cybersecurity tabletop exercise simulating the 2021 Colonial Pipeline ransomware attack, reviewing what they missed

Robert C. Rhodes
October 4, 2024
Tabletop vs. the Shutdown: What Ten Colonial Pipeline Exercises Missed

Summary

The Colonial Pipeline ransomware attack from May 2021 is one of the largest cybersecurity incidents in history in its impact on the United States. ThreatGEN created a AutoTableTop™ Pre-Built Scenario (Colonial Pipeline 2021 Scenario) which it used to quality test before the release of version 1.0.

Using all the results from the production ready version 1.0, ThreatGEN created this case study to outline what we think the Colonial Pipeline team missed.


Case study: ten exercises against May 2021

→ Colonial Pipeline Incident, Case Study on tabletop exercises vs. reality ←

ThreatGEN ran this scenario ten times in AutoTableTop™ version 2.1 and compared the pattern with the public record. Colonial did not participate. The benchmark is the known timeline: shutdown on May 7, notification of the FBI, CISA, the Department of Energy, and DHS, Mandiant engaged, 75 bitcoin paid the same day, restart May 12, normal operations May 15, about 100 gigabytes stolen, and 63.7 bitcoin recovered by the Department of Justice on June 7.

Shared with the real incident:

  • Entry through a compromised VPN account
  • Corporate IT hit, including billing
  • Pipeline operations disrupted

Where the exercises diverged:

  • Plan activated immediately, versus days to fully assess and respond
  • Partial, controlled shutdown, versus a full shutdown of about five days
  • Ransom payment never debated; Colonial paid about $4.4 million
  • Mandiant engaged proactively, versus after detection
  • Simulated notices to DHS, the FBI, and CISA, versus wider agency involvement
  • Public impact stayed thin, versus shortages and panic buying

A representative October 7, 2024 run with the CIO, CISO, and IT security manager scored 85 out of 100.

  • Worked: early activation, isolation that kept ransomware on the IT side, SCADA restored first, credentials reissued, multifactor authentication required
  • Missed: late identification of the VPN foothold, weak partner and regulator coordination, thin stakeholder communication (five points each)
  • Planning estimate about $1.2 million before any ransom ($300,000 internal, $400,000 Mandiant, $200,000 restoration, $300,000 customer communication)
  • Techniques in the scenario: valid accounts (T1078), remote services (T1021), data encrypted for impact (T1486)

Recommendations from the ten runs: multifactor authentication on every access path, especially VPN; scheduled audits and penetration tests; a written protocol for DHS, FBI, CISA, customers, and the press; a retest that includes the shutdown call and the 8-K call; and a prior decision on who may discuss payment. A tabletop that always restores the pipe and never debates the ransom will overstate readiness.

© 2026 by Derezzed Inc. D/B/A ThreatGEN. AutoTableTop™ is a trademark and ThreatGEN® Red vs. Blue is a registered trademark of Derezzed Inc.