Alignment: LO3 / A3 Objective: Route a scam incident to the right internal and external parties using severity and evidence.
Use only the simulated data supplied in this folder. Do not test live suspicious links, accounts, phone numbers or payment routes.
- Read the capstone scenario and assign an initial severity.
- Identify immediate life-safety, financial, identity, device and business impacts.
- Choose internal recipients: manager, security, finance, legal, data protection or communications.
- Choose external recipients: bank, platform, ScamShield, Police or relevant dispute channel.
- Prepare a concise escalation brief with verified facts, unknowns and requested action.
- Sequence notifications to contain loss while preserving investigation options.
- Update severity when the scenario inject introduces a second victim and public exposure.
- Complete the after-action review with control improvements and owners.
Escalation matrix, incident brief, notification sequence and after-action actions.
The brief separates facts from assumptions and includes timestamps, evidence references, impact and a clear request.
Which observable fact most changed your decision, and which uncertainty remains?