Not part of a guided workflow —
Next best move:Open the platform atlas Atlas
AutoResilienceCommand
Ops clock2026-03-17 14:00ZFirst impactT−22.4h

BMW-targeted concept demonstration. Operational entities, suppliers, parts, inventory, production, financial values and incident conditions are synthetic and do not represent BMW systems, performance or current exposure.

Reconnection gate

Reconnection stays blocked until each gate holds evidence produced outside the supplier's compromised environment.

INC-2026-0113 · S1 · responding

Reconnection blocked

Reconnection blocked. 10 of 10 mandatory gates unsatisfied: Incident scope established; Containment completed; Persistence addressed; Credentials rotated; Data integrity validated; Affected interface tested; Representative business transaction completed; Monitoring activated; Cyber approval recorded; Operations approval recorded.

0/10 gates passed

1. Incident scope established

Affected systems, accounts and data stores identified and bounded.

Blocked
Evidence requiredScope statement from the supplier's responder, with the systems named
Approving authorityCyber
MandatoryYes
Why attestation is not enoughWithout a bounded scope there is no basis for judging whether the connection is safe.
StatusNo evidence submitted. Required: Scope statement from the supplier's responder, with the systems named.

2. Containment completed

Attacker access removed from the affected environment.

Blocked
Evidence requiredContainment report naming the actions taken and the time completed
Approving authorityCyber
MandatoryYes
Why attestation is not enoughA restored service is not a contained service.
StatusNo evidence submitted. Required: Containment report naming the actions taken and the time completed.

3. Persistence addressed

Backdoors, scheduled tasks and rogue accounts removed.

Blocked
Evidence requiredPersistence sweep results from the responder or EDR platform
Approving authorityCyber
MandatoryYes
Why attestation is not enoughReconnection to an environment with persistence reopens the exposure path immediately.
StatusNo evidence submitted. Required: Persistence sweep results from the responder or EDR platform.

4. Credentials rotated

All supplier interface and service credentials replaced.

Blocked
Evidence requiredCredential rotation log covering the interface accounts
Approving authorityCyber
MandatoryYes
Why attestation is not enoughOld credentials may already be in an attacker's possession.
StatusNo evidence submitted. Required: Credential rotation log covering the interface accounts.

5. Data integrity validated

Master and transactional data reconciled against an independent record.

Blocked
Evidence requiredReconciliation result comparing supplier quantities with physical counts
Approving authorityOperations
MandatoryYes
Why attestation is not enoughData written during the incident may be wrong whether or not the attacker is gone.
StatusNo evidence submitted. Required: Reconciliation result comparing supplier quantities with physical counts.

6. Affected interface tested

The interface passes a technical connectivity and message-format test.

Blocked
Evidence requiredInterface test result with message identifiers
Approving authorityOperations
MandatoryYes
Why attestation is not enoughA live path is not a correct path.
StatusNo evidence submitted. Required: Interface test result with message identifiers.

7. Representative business transaction completed

One end-to-end order, shipment and receipt processed correctly.

Blocked
Evidence requiredTransaction record showing the document numbers on both sides
Approving authorityOperations
MandatoryYes
Why attestation is not enoughThis is the only evidence that the business process, not just the connection, works.
StatusNo evidence submitted. Required: Transaction record showing the document numbers on both sides.

8. Monitoring activated

Enhanced monitoring in place on the restored interface.

Blocked
Evidence requiredMonitoring configuration record and alert routing
Approving authorityCyber
MandatoryYes
Why attestation is not enoughReconnection without monitoring gives no detection of a second event.
StatusNo evidence submitted. Required: Monitoring configuration record and alert routing.

9. Cyber approval recorded

Named cyber authority accepts the residual connection risk.

Blocked
Evidence requiredApproval entry naming the authority and the residual risk accepted
Approving authorityCyber
MandatoryYes
Why attestation is not enoughAccountability for residual risk must be attributable to a person.
StatusNo evidence submitted. Required: Approval entry naming the authority and the residual risk accepted.

10. Operations approval recorded

Named operations authority accepts resumption of automated processing.

Blocked
Evidence requiredApproval entry naming the authority and the resumption conditions
Approving authorityOperations
MandatoryYes
Why attestation is not enoughProduction owns the consequence of a bad message reaching the schedule.
StatusNo evidence submitted. Required: Approval entry naming the authority and the resumption conditions.

Executive risk acceptance

The only route past an unsatisfied mandatory gate. It is recorded permanently.