Illustrative scenarios

Real threat patterns. Illustrative responses.

Conversation aids about how See · Think · Act · Verify · Tell is meant to feel. Not published case studies, detection timers, or performance guarantees.

Illustrative onlyOn-prem loopVerify emphasisedNo invented stats
Threat levels (illustrative):CRITICAL — National security or public safety riskHIGH — Significant operational or financial impact
SCENARIO 01Federal AgencyCRITICAL

The Silent Infiltration

Nation-State APT pattern

What happened

Illustrative: a spear-phish against a procurement officer leads to quiet lateral movement and credential harvesting — the kind of low-and-slow activity legacy SIEMs often under-prioritise.

How the loop might catch it

Illustrative loop: See/Think notice unusual service-account access outside normal patterns and correlate related micro-anomalies on the premises. Operators get a narrative — not a claim of a fixed minute SLA.

Act · Verify · Tell

Illustrative Act → Verify: contain under policy, re-check that containment held, then Tell a plain-language account for your operators. Optional light Aegis support if you want help framing next steps — not a staffed 24/7 SOC claim.

ILLUSTRATIVE OUTCOMEIllustrative outcome: compromise mapped and contained before mission objectives succeed. Remediations are yours to prioritise. Not a published case study.
SCENARIO 02County GovernmentHIGH

Overnight Encryption Pattern

Ransomware overnight

What happened

Illustrative: ransomware-like encryption behaviour starts on file shares after a compromised VPN credential — often after days of quiet persistence.

How the loop might catch it

Illustrative: the on-prem loop flags anomalous write/entropy patterns and can trigger policy-driven containment. We do not invent “under N seconds” detection guarantees here.

Act · Verify · Tell

Illustrative: Act isolates affected paths where policy allows; Verify re-checks the outcome per host/segment; Tell briefs your operators in the morning. Restoration depends on your backups and staffing — not an invented on-call SLA.

ILLUSTRATIVE OUTCOMEIllustrative: early containment limits blast radius; recovery follows your runbooks. No ransom-paid theatre, no fake file counts.
SCENARIO 03Hospital SystemCRITICAL

The Device Pathway

Medical device pathway

What happened

Illustrative: compromise of a vendor remote-monitoring gateway, then attempted movement from a biomedical VLAN toward IT — a care-delivery risk as much as an IT one.

How the loop might catch it

Illustrative: See/Think flag disallowed VLAN-to-VLAN behaviour (scanning, credential testing) that should never occur between clinical and IT segments.

Act · Verify · Tell

Illustrative: Act severs the bad pathway under policy; Verify confirms it stayed severed; clinical devices are not casually disrupted. Your clinical engineering and IR process own device follow-up.

ILLUSTRATIVE OUTCOMEIllustrative: patient-safety-first framing — contain the pathway, then harden. Not a claim of zero clinical impact in every environment.
SCENARIO 04Water UtilityCRITICAL

The Treatment Plant Probe

OT reconnaissance

What happened

Illustrative: internet-facing contractor remote access reaches toward SCADA HMI themes — reconnaissance against chemical dosing parameters rather than immediate sabotage.

How the loop might catch it

Illustrative: unusual accounts, sources, or OT parameter queries that match no known operator workflow raise operator signals on-prem.

Act · Verify · Tell

Illustrative: terminate the session, suspend the contractor path, preserve evidence for your OT specialists and any agency notifications you choose. Light Aegis support is optional capacity — not a flying squad claim.

ILLUSTRATIVE OUTCOMEIllustrative: stop at reconnaissance; no invented “zero public-risk” guarantees. Briefings discuss OT constraints honestly.
SCENARIO 05Police DepartmentHIGH

The Evidence System Probe

Evidence system abuse

What happened

Illustrative: social-engineered VPN credentials used to probe digital evidence systems — seeking case files and witness-related material.

How the loop might catch it

Illustrative: behavioural signals when an account accesses case material far outside its unit baseline. No invented “340% above baseline” scorecards.

Act · Verify · Tell

Illustrative: constrain the account under policy, preserve logs, involve your IA/prosecution process. Court outcomes depend on your counsel — we do not invent them.

ILLUSTRATIVE OUTCOMEIllustrative: investigation integrity protected enough for your process to continue. CJIS conversations are framing aids, not certifications.
SCENARIO 06Defence ContractorCRITICAL

The Suspect Update

Supply-chain update risk

What happened

Illustrative: a routine vendor update package that passes basic signing checks but carries undocumented callback behaviour — supply-chain risk against CUI-adjacent systems.

How the loop might catch it

Illustrative: anomalous update behaviour and policy gates before broad rollout — operator review before trust. We do not claim a magic “binary deep analysis platform” product name here.

Act · Verify · Tell

Illustrative: hold deployment, Verify the hold, notify the vendor through your process, scan for prior exposure. Government partner notifications are yours to make.

ILLUSTRATIVE OUTCOMEIllustrative: bad update never becomes production trust. Ask in a briefing what update-gating looks like in your estate.
SCENARIO 07City HallHIGH

The Wire Transfer Fraud

Business email compromise

What happened

Illustrative: after credential phishing, an attacker learns payment cadence and spoofs a large vendor wire authorisation while the officer is on leave — dollar amounts vary; we do not invent them.

How the loop might catch it

Illustrative: lookalike domains, process mismatches (no sent copy of an “authorisation”), and out-of-band verification themes. Email security may be adjacent tooling — not a claimed 0g0 “email platform.”

Act · Verify · Tell

Illustrative: hold payment pending human verification; re-check vendor banking out-of-band; secure the mailbox. Your finance controls remain the backstop.

ILLUSTRATIVE OUTCOMEIllustrative: fraudulent transfer stopped by process + signals. No invented million-dollar theatre.
SCENARIO 08School DistrictHIGH

The Records Exfiltration

Student records exposure

What happened

Illustrative: SQL injection in a legacy SIS web app enables systematic student-record theft over several days — a privacy and regulatory event.

How the loop might catch it

Illustrative: anomalous outbound transfer patterns and application abuse signals on-prem. Optional external exposure signals are discussion topics — not a claimed “dark web intelligence platform” for every customer.

Act · Verify · Tell

Illustrative: take the vulnerable app offline, scope the database, follow your notification laws. Light support can help frame evidence trails — not invent statutory compliance outcomes.

ILLUSTRATIVE OUTCOMEIllustrative: blast radius limited by earlier detection; notifications are your legal process. No invented student counts.
SCENARIO 09Power GridCRITICAL

The Grid Probe

EMS / OT reconnaissance

What happened

Illustrative: multi-week reconnaissance against EMS/OT pathways — mapping IT–OT bridges without immediate outage commands.

How the loop might catch it

Illustrative: correlated low-confidence signals that together look like known grid-targeting patterns. Operators decide escalation — no invented 34-day clock guarantees.

Act · Verify · Tell

Illustrative: monitor carefully, then evict under a planned window; harden re-entry paths. Agency notifications (CISA, NERC, etc.) follow your process.

ILLUSTRATIVE OUTCOMEIllustrative: operations unaffected while the probe is removed. Not a claim that every utility engagement ends that way.
SCENARIO 10Court SystemCRITICAL

The Record Manipulation Attempt

Record integrity

What happened

Illustrative: stolen clerk credentials used to attempt modification of protected case-management records and evidence submissions.

How the loop might catch it

Illustrative: integrity / unusual-access signals when an account touches case files it has never owned. Write-blocking under policy where configured.

Act · Verify · Tell

Illustrative: suspend access, preserve audit trails, notify court admin/judge per your process. “Court-admissible” is a legal determination — we do not invent it.

ILLUSTRATIVE OUTCOMEIllustrative: records unchanged; forensic trail available for your counsel. Proceedings continue under your control.
SCENARIO 11Election InfrastructureCRITICAL

The Integrity Probe

Pre-election probing

What happened

Illustrative: spear-phish of election officials, probing of registration systems, and noise aimed at public confidence — technical and narrative pressure together.

How the loop might catch it

Illustrative: lookalike domains, probing of election-related systems, and operator prioritisation of those signals. We do not claim a dedicated “election security monitoring platform” product.

Act · Verify · Tell

Illustrative: disrupt vectors as found, brief election officials, coordinate with your state CISO and partners as you choose. Transparency reporting is a policy choice.

ILLUSTRATIVE OUTCOMEIllustrative: voting systems stay out of scope of compromise in the story. Real elections need your full stack — appliance is one layer.
SCENARIO 12Financial RegulatorHIGH

The Market Intelligence Theft

Pre-decisional data theft

What happened

Illustrative: compromised analyst account used to bulk-access pre-decisional regulatory documents for illicit trading advantage.

How the loop might catch it

Illustrative: access patterns inconsistent with role and hours — bulk pre-decisional reads across teams. No invented day-count guarantees.

Act · Verify · Tell

Illustrative: constrain the account, preserve evidence, involve your OIG/LE process. Analyst may be victim of remote access — investigate before assuming malice.

ILLUSTRATIVE OUTCOMEIllustrative: collection stopped early; referrals are yours. No claim that market-moving data never left in every scenario.
HONEST POSITIONING

We do not publish invented breach rates, detection timers, or framework scorecards here. Ask for a briefing to discuss the 0g0 Appliance (available now) and the Aegis services roadmap (growing practice). Built by Sky AI LLC / wesky.ai.

Next step

Which scenario describes your greatest risk?

Request a confidential briefing on the 0g0 Appliance. We'll discuss how the loop maps to your environment — honestly, without invented stats.

Request a Briefing