Policy & communication
Briefing a mock Cabinet through a national grid attack
IITPSA SIGCyber Student Cyber Challenge / CSIR, Pretoria, 29 Sept 2025 / 3rd place, Team CyberOps
Seven student teams were handed the same crisis. A hacktivist group had exploited unpatched control software to trigger a thirty-hour blackout, hospitals had been forced onto generators, eighty-nine people were dead, and the group had issued a seventy-two-hour ultimatum threatening to publish their exploit. We had to write a policy brief and defend it to a judging panel playing the President's Cabinet.
The technical picture was the easy half. A vendor patch existed, but rollout was uneven: two metros and a key gateway were still exposed, an internal change freeze had slowed updates, and there was evidence of insider-enabled access. The hard half was that the group's demands were popular ones. An independent security audit and open policy hearings are things you would want anyway. Agreeing to them under a deadline means agreeing to them under extortion.
We weighed three routes: harden and prosecute, concede and negotiate, or a hybrid. We recommended the hybrid. Lock down the operational network, finish the patch rollout with checksum validation, deploy emergency power support, announce an independent audit on our own terms, and signal civil society consultations to buy time. We named its weakness out loud rather than hiding it: coordination across that many departments is where it would most likely fail.
The habit I want to bring into a security team is what we attached to the recommendation. Explicit escalation and de-escalation triggers, so decision-makers know in advance what would change the plan. Metrics they can check for themselves: substations patched, residual access points closed, regional cooperation with Eswatini and Namibia through the Southern African Power Pool. A recommendation with no way to hold it accountable is just an opinion delivered confidently.
Security work reaches people who will never read a packet capture. I want to keep doing the technical half and stay able to explain it to the room that has to sign it off.
- Result
- 3rd place, national field
- Team
- CyberOps
- Format
- Written policy brief + live panel defence
- Host
- IITPSA SIGCyber, at the CSIR