3. Scenarios and Alternative Futures

Building Plausible Strategic Cyber Scenarios

Combine structural drivers and critical uncertainties into distinct, internally coherent futures that expose consequential choices without pretending to predict one outcome.

In this lesson, you will learn to:

  • Construct a set of distinct and plausible strategic cyber scenarios using scoped focal questions, evidence-based drivers, critical uncertainties, causal pathways, organizational consequences, and explicit assumptions.

Building Plausible Strategic Cyber Scenarios

Learn a repeatable scenario-development method grounded in evidence, causal logic, organizational exposure, business consequence, and decision relevance.

Define the focal question, horizon, and scenario drivers

Scenario analysis helps leaders prepare for several plausible futures when prediction is unreliable and the cost of waiting may be high. A scenario is not a forecast, threat-actor story, or worst-case narrative. It is a structured account of how selected drivers and critical uncertainties could interact to create decision-relevant conditions.

The purpose is to improve choices under uncertainty. Good scenarios reveal assumptions, test strategies, expose consequences, identify warning indicators, and preserve options. They do not claim that one imagined future will occur.

Begin with a focal question

A scenario exercise requires a decision-centered focal question. It should identify:

  • the accountable consumer;
  • the strategic choice or preparation at issue;
  • the organizational outcomes in scope;
  • the future horizon;
  • the external and internal boundaries;
  • the reason alternative futures could change the decision.

Compare:

Weak prompt Problem Stronger focal question
“What will cybercrime look like?” No consumer, boundary, or decision How could changes in criminal access markets and identity abuse affect Northbridge’s regional payment strategy over the next three years?
“Imagine a catastrophic cloud attack.” Begins with a preferred dramatic outcome Under which plausible conditions could cloud and identity concentration create material service disruption, and how would alternative operating models perform?
“Will AI increase phishing?” Binary prediction with unclear consequence How could different rates of automation and defensive adaptation change support-channel fraud and identity exposure during the expansion horizon?

A useful pattern is:

How might [critical external and organizational conditions] develop over [horizon], and what would each plausible future mean for [decision and critical outcomes]?

The question should be broad enough to permit meaningfully different futures but narrow enough to support evidence, causal reasoning, and action.

Select the horizon deliberately

The scenario horizon should match decision lead time and the pace of relevant change.

Ask:

  • When must leadership commit resources or design choices?
  • How long will implementation take?
  • When could benefits or risks become visible?
  • Which drivers can plausibly change during that period?
  • Beyond what point does evidence become too weak for useful detail?

For Northbridge, a three-year horizon is appropriate because operating-model and identity-resilience decisions require long implementation, while criminal markets, platform controls, regulation, and regional exposure could change materially within that period.

Do not fill distant scenarios with unnecessary technical specificity. Detail should decrease as uncertainty grows. Long-horizon scenarios are usually strongest when they describe conditions, incentives, dependencies, and consequences rather than naming exact tools or actors.

Establish the present baseline

Scenarios begin from a dated baseline, not an abstract present. Record:

  • critical services and organizational objectives;
  • operating model and major dependencies;
  • current threat patterns and relevant actors or ecosystems;
  • control and recovery capabilities;
  • planned transformations and investments;
  • applicable regulation and contractual duties;
  • stakeholder assumptions and risk tolerances;
  • known intelligence and evidence gaps.

The baseline is the starting state from which change unfolds. If it changes during the exercise, version it. Otherwise, participants may build different futures from incompatible understandings of the organization.

For Northbridge, the baseline includes centralized identity administration, planned regional expansion, incomplete alternate recovery testing, dependence on two communications providers, and moderate evidence of increasing session and support-channel abuse.

Gather candidate drivers

Drivers are forces capable of shaping the future. Generate them from diverse evidence and perspectives rather than relying on the latest threat report.

Candidate driver families include:

  • geopolitical competition, conflict, sanctions, and state tolerance;
  • criminal profitability, specialization, access markets, and disruption;
  • platform concentration, security improvements, and technology adoption;
  • regulation, disclosure, liability, and executive accountability;
  • organizational growth, outsourcing, acquisition, and operating-model change;
  • supplier concentration, resilience, transparency, and substitutability;
  • workforce availability, support processes, and social trust;
  • customer behavior and dependence on digital service;
  • defensive investment, automation, law enforcement, and market intervention;
  • physical infrastructure, energy, telecommunications, and regional instability.

For every candidate, state a causal proposition:

If this driver changes, what condition changes, through which mechanism, and why could that matter to the focal decision?

Discard drivers that are fashionable but lack a plausible pathway to the scoped outcome.

Separate predetermined elements from critical uncertainties

Not every future condition is equally uncertain.

Predetermined elements are developments already in motion or highly constrained during the horizon. Examples may include signed expansion commitments, long technology replacement cycles, demographic change, or regulation already scheduled to take effect.

Critical uncertainties are both highly consequential and genuinely uncertain in direction or outcome. Examples include:

  • whether provider security improvements outpace adversary adaptation;
  • whether access markets consolidate and scale or fragment under disruption;
  • whether regional regulation becomes harmonized or divergent;
  • whether Northbridge validates independent recovery before expansion;
  • whether managed providers offer meaningful transparency and substitutability.

Classify drivers using two questions:

  1. How much could this condition affect the focal decision?
  2. How uncertain is its direction or state during the horizon?
Driver classification Treatment
High impact, high uncertainty Candidate axis or central scenario differentiator
High impact, lower uncertainty Include as a common element across scenarios
Lower impact, high uncertainty Monitor or use as a secondary modifier
Lower impact, lower uncertainty Keep in background unless it affects a pathway

The ratings are judgments. Record the rationale and disagreements.

Avoid false axes

Scenario matrices often use two uncertainties as axes, creating four futures. This method is useful only when the axes are:

  • genuinely uncertain;
  • highly consequential;
  • reasonably independent;
  • expressed as clear contrasting states;
  • capable of producing distinct decision conditions.

Weak axes include:

  • “low risk versus high risk,” because they merely restate the outcome;
  • two versions of the same variable;
  • conditions leadership directly controls but has not yet decided;
  • vague labels such as “technology good versus bad”;
  • dimensions selected only because they make dramatic stories.

For Northbridge, stronger uncertainties might be:

  • Adversary access ecosystem: fragmented and costly ↔ specialized and scalable
  • Defensive and institutional response: effective and coordinated ↔ uneven and lagging

Organizational recovery maturity may then be tested as a decision variable across all four environments rather than embedded as an external axis.

Assess axis independence

If one axis mechanically determines the other, the four cells are not distinct. Test:

  • Can both high/high and low/low combinations plausibly exist?
  • What mechanism would produce each combination?
  • Does evidence support independent movement?
  • Would a change in one always cause the same change in the other?

For example, scalable criminal access could coexist with strong defensive response if both attackers and providers innovate rapidly. Fragmented access could coexist with weak defense if economic disruption reduces criminal coordination while organizations still fail to improve controls.

The unusual combinations are often valuable because they challenge linear assumptions.

Use morphological analysis when two axes are insufficient

Some decisions depend on more than two critical uncertainties. A morphological approach defines several dimensions and plausible states:

Dimension State A State B State C
Access ecosystem Fragmented Specialized Platform-disrupted
Provider security Uneven Strong direct controls Strong controls with displaced abuse
Regulation Stable Coordinated resilience rules Divergent regional obligations
Northbridge architecture Centralized Regional Hybrid or managed
Recovery maturity Untested Partially validated Independently exercised

Analysts combine compatible states into a small number of coherent scenarios. They do not explore every mathematical combination. Remove combinations that contradict established constraints, but document why they are excluded.

This method exposes choices that a simple matrix might hide, though it requires stronger discipline to avoid an unmanageable scenario set.

Choose drivers with diverse challenge

Scenario selection improves when participants represent different evidence and incentives. Include relevant expertise from:

  • CTI and security operations;
  • architecture and identity;
  • enterprise risk and resilience;
  • business and regional operations;
  • legal, privacy, and regulation;
  • procurement and supplier management;
  • fraud and financial control;
  • strategy, finance, or transformation leadership.

Ask participants to submit drivers independently before discussion. This reduces anchoring on the first senior voice.

During the workshop:

  • separate evidence from assumptions;
  • record minority views;
  • identify interests that may shape judgments;
  • prevent consensus from substituting for support;
  • keep analysts accountable for integrating the final analytic model.

Stakeholders contribute expertise; they do not vote a scenario into truth.

Rank drivers transparently

For each candidate driver, record:

Field Purpose
Driver Clear statement of the force
Current evidence Observations, sources, and baseline
Mechanism How it could alter threat, exposure, or consequence
Direction Current movement, if assessable
Impact Effect on the focal decision if it changes materially
Uncertainty Range of plausible future states
Persistence Temporary, sustained, structural, or unclear
Interaction Reinforcing, constraining, conditional, or displacing relationships
Organizational pathway Link to Northbridge outcomes
Indicators Evidence that would clarify future direction

A one-line driver name such as “AI,” “geopolitics,” or “regulation” is too broad. Define the specific mechanism and contrasting future states.

Identify predetermined elements carefully

Predetermined does not mean certain. It means sufficiently constrained to appear in every scenario, though consequences may vary.

Northbridge might treat these as common elements:

  • regional expansion remains an approved objective unless a major shock occurs;
  • identity and cloud services remain central to payment operations;
  • criminal actors continue to seek monetizable access;
  • regulatory scrutiny of operational resilience does not disappear;
  • architectural change requires significant lead time.

Each scenario incorporates these elements but shows how their effects differ. If a supposed predetermined element is actually contested, return it to the uncertainty set.

Define scenario boundaries

Prevent uncontrolled storytelling by setting rules:

  • no supernatural capabilities or impossible access;
  • no precise incident counts without supporting models;
  • no actor intent inferred solely from capability;
  • no consequence without an exposure pathway;
  • no control assumed effective without evidence or explicit condition;
  • no scenario designed merely to justify a preferred investment;
  • no omission of counterforces or adaptation;
  • no claim that scenario plausibility implies probability equality.

Scenarios can include shocks, but explain their role. A shock may be a stressor applied to every scenario or a defining condition of one future. Do not use a catastrophe to conceal weak causal logic.

Create a scenario design brief

Before writing narratives, document:

  • focal question and decision owner;
  • horizon and decision deadline;
  • organizational baseline date;
  • scope and exclusions;
  • predetermined elements;
  • selected critical uncertainties;
  • rejected axes and rationale;
  • key evidence and gaps;
  • participants and review roles;
  • intended products and decision interactions;
  • signpost and warning expectations;
  • handling restrictions.

This brief makes the method reviewable and helps prevent the scenario exercise from drifting into general futures discussion.

Worked selection: Project Horizon

Northbridge launches a strategic scenario exercise called Project Horizon to support its regional operating-model decision.

The focal question is:

How could changes in criminal access ecosystems and defensive institutional response shape identity-enabled disruption of Northbridge’s regional payment services over the next three years, and which operating-model choices remain robust?

The team gathers 18 candidate drivers. After evidence review and challenge, it identifies four high-impact conditions:

  1. specialization and scale of criminal access services;
  2. effectiveness of platform security and ecosystem disruption;
  3. regulatory requirements for service continuity and evidence;
  4. Northbridge’s identity concentration and recovery maturity.

The first two become scenario axes because they are external, uncertain, consequential, and sufficiently independent. Regulation becomes a secondary modifier because its direction is better established but regional implementation varies. Northbridge recovery maturity becomes a controllable strategic variable tested across every scenario.

The resulting matrix creates four starting environments:

Access ecosystem Defensive response Initial scenario condition
Fragmented Effective Attack opportunities narrow, but isolated sophisticated pathways remain.
Specialized and scalable Effective Rapid offense-defense adaptation creates persistent but observable pressure.
Fragmented Uneven Fewer organized markets coexist with widespread weak control and opportunistic abuse.
Specialized and scalable Uneven Accessible intrusion capability meets concentrated exposure and delayed adaptation.

The team avoids ranking these scenarios by preference. It will next develop causal pathways, consequences, signposts, and option performance for each.

Driver-selection quality check

Before advancing, ask:

  • Does the focal question identify a consequential choice and a realistic horizon?
  • Is the baseline dated and accepted by relevant owners?
  • Does every driver have a plausible causal mechanism?
  • Are collection and reporting effects distinguished from real-world change?
  • Are predetermined elements separated from critical uncertainties?
  • Are selected axes high-impact, uncertain, distinct, and reasonably independent?
  • Have unusual but plausible combinations been retained?
  • Are organizational choices treated separately from uncontrollable external conditions where useful?
  • Have rejected drivers and axes been documented?
  • Are evidence gaps, dissent, and handling constraints visible?
  • Can the selected drivers produce meaningfully different implications and options?
Analyst habit

For every proposed scenario axis, complete four sentences:

The uncertainty is…

Its contrasting states are…

It matters to the decision because…

These states can vary independently of the other axis because…

If the final sentence cannot be defended, choose a different structure.

Key takeaways
  • Scenarios are structured alternative futures designed to improve decisions, not forecasts or predictions.
  • Start with a focal question, decision owner, horizon, scope, and dated organizational baseline.
  • Select drivers through evidence, causal relevance, diverse challenge, and explicit organizational pathways.
  • Separate predetermined elements from high-impact critical uncertainties.
  • Use two-axis matrices only when the uncertainties are distinct and sufficiently independent; use morphological analysis when more dimensions are essential.
  • Treat organizational choices as variables to test across futures rather than assumptions hidden inside the scenario.
  • Document selection logic, rejected alternatives, evidence gaps, and boundaries before writing narratives.
  • A strong scenario design creates distinct conditions that can change implications, warning indicators, and strategic choices.

Build distinct futures with causal logic and consequence

Selected drivers and uncertainties are only the scaffolding of a scenario. Analysts must next construct distinct futures with coherent causal logic, organizational consequences, and decision implications. The goal is not literary richness. It is a set of testable models that help leaders see how different conditions could emerge and which choices remain useful.

Build from conditions, not dramatic incidents

Begin each scenario by defining its operating conditions:

  • the state of each critical uncertainty;
  • predetermined elements shared across scenarios;
  • important secondary drivers;
  • the organizational baseline and decisions already made;
  • constraints affecting adversaries, defenders, suppliers, and regulators;
  • the time path from the present to the scenario horizon.

Do not begin with a spectacular breach and work backward to justify it. Start with the environment, then derive plausible behaviors, exposure, controls, and consequences.

A scenario condition statement might be:

Criminal access services become specialized and scalable while platform defenses improve rapidly but unevenly. Direct session theft becomes harder on mature platforms, yet abuse shifts toward support channels, delegated administration, suppliers, and recovery processes. Organizations with concentrated identity dependencies face persistent pressure, while those with tested recovery and behavior monitoring contain most events before material disruption.

This statement defines a future environment without predicting a named actor, exact incident, or guaranteed outcome.

Use a causal chain

Develop every scenario through the same analytic sequence:

Drivers → environmental conditions → actor incentives and constraints → likely behaviors → organizational exposure → control performance → operational effects → business consequences → leadership implications

For each link, identify evidence, assumptions, and alternatives.

Causal layer Questions
Drivers Which forces moved, persisted, or interacted?
Environment What became easier, harder, cheaper, more visible, or more consequential?
Actors How did capability, intent, opportunity, and constraint change?
Behaviors Which pathways became more or less attractive?
Exposure Which Northbridge dependencies intersect with those behaviors?
Controls Which protections perform, fail, or displace activity?
Effects How do services, integrity, recovery, or decision processes change?
Consequences Which objectives, obligations, customers, or investments are affected?
Implications Which choices become urgent, robust, reversible, or unavailable?

A scenario should not jump from “criminal automation increases” directly to “regional expansion fails.” The intermediate pathway is where analysis can be tested.

Develop a time path

A scenario describes change, not only an endpoint. Use three phases:

  1. Emergence: Early developments weaken or strengthen current assumptions.
  2. Acceleration or adaptation: Actors, providers, organizations, and regulators respond.
  3. Horizon condition: The interaction produces the environment leaders must plan for.

For example:

Phase Project Horizon development
Emergence Access brokers increasingly offer trusted sessions, while providers deploy stronger token controls.
Adaptation Direct theft becomes less reliable; operators target support desks, delegated administrators, and recovery workflows.
Horizon Identity abuse remains persistent but concentrates around organizational exceptions and suppliers; recovery maturity determines consequence.

The time path exposes intervention opportunities. Northbridge may not control the criminal ecosystem, but it can change support verification, delegated access, supplier governance, monitoring, and recovery before the horizon condition matures.

Keep scenarios internally coherent

Internal coherence means the parts can plausibly coexist. Test:

  • Would actors respond to the stated incentives and constraints in the proposed way?
  • Can defensive improvement coexist with persistent adversary pressure?
  • Does regulatory action occur quickly enough to affect the horizon?
  • Are supplier and organizational adaptations represented?
  • Do consequences follow from the stated exposure and control conditions?
  • Are important counterforces included?
  • Does the scenario contradict a predetermined element without explaining a shock?

Coherence does not mean familiarity. A surprising combination can be valuable if its causal logic is defensible.

Make scenarios meaningfully distinct

Different titles and anecdotes do not create different futures. Scenarios should vary in conditions that change decisions.

Compare them across a common structure:

Dimension Scenario A Scenario B Scenario C Scenario D
Access availability Limited and unreliable Scalable but contested Fragmented and opportunistic Scalable and dependable
Defensive adaptation Coordinated and effective Fast but uneven Weak and inconsistent Delayed and reactive
Dominant behavior Narrow specialist intrusion Continuous adaptation Local fraud and exploitation Industrialized identity abuse
Warning visibility High Moderate Low and noisy Moderate but overwhelmed
Northbridge exposure Concentration manageable with recovery Exceptions and suppliers dominate Regional variance dominates Common-cause exposure is material
Leadership priority Maintain capability Adapt controls quickly Raise baseline consistency Accelerate resilience and preserve separation options

If all scenarios produce the same exposure, consequence, and recommendation, either the futures are insufficiently distinct or the proposed action is genuinely robust. Analysts should determine which explanation applies.

Give scenarios neutral names

Names help memory but can bias interpretation. Avoid labels such as best case, disaster, safe future, or inevitable crisis. Use names that describe the operating logic without declaring preference.

Project Horizon uses:

  • Narrow Channels: Fragmented access and effective defense
  • Adaptive Contest: Scalable access and effective defense
  • Uneven Ground: Fragmented access and uneven defense
  • Open Market: Scalable access and uneven defense

The names are concise and distinct, but the scenario brief—not the title—carries the meaning.

Write a structured scenario brief

Use the same fields for every future:

  1. Core condition: One paragraph describing the scenario logic.
  2. Path from the present: Developments that could plausibly produce it.
  3. Actor and ecosystem behavior: Capabilities, incentives, opportunities, and constraints.
  4. Northbridge exposure: Dependencies and control conditions that matter.
  5. Operational and business consequences: Conditional effects, not guaranteed outcomes.
  6. Leadership implications: Decisions, preparations, or options affected.
  7. Signposts: Observable evidence that the environment is moving toward or away from the scenario.
  8. Pivotal assumptions: Conditions on which the analysis depends.
  9. Counterforces: Developments that could redirect the path.
  10. Confidence and gaps: Evidentiary strengths and weaknesses.

This structure prevents one scenario from receiving much more detail than the others merely because analysts find it more plausible or interesting.

Project Horizon scenario 1: Narrow Channels
Core condition

Criminal access services fragment under sustained disruption, reduced trust, and stronger platform controls. Defensive coordination among providers, law enforcement, and major organizations makes scalable identity abuse costly. Sophisticated operators retain niche capability, but broad access is less dependable.

Path from the present

Providers improve token protection and restrict risky recovery workflows. Successful enforcement actions damage broker reputation and payment channels. Buyers become cautious as fraudulent access listings increase. Organizations adopt stronger support verification and privileged-access monitoring.

Northbridge exposure

Centralized identity remains a concentration risk, but successful exploitation is less frequent and more observable. The greatest residual exposure lies in privileged insiders, specialized supplier access, and recovery design.

Consequences and implications

A material event remains plausible but requires greater attacker effort. Northbridge gains value from maintaining tested recovery, high-quality monitoring, supplier assurance, and targeted specialist defense. Large irreversible redesign based solely on attack-frequency expectations is less compelling.

Signposts
  • declining trusted evidence of access-market transactions;
  • sustained effectiveness of token and recovery protections;
  • increased attacker cost and narrower targeting;
  • successful disruption without rapid market replacement;
  • lower relevant incident rates in sources with stable coverage.
Project Horizon scenario 2: Adaptive Contest
Core condition

Access services become specialized and scalable, while providers and mature defenders adapt quickly. Offense and defense improve together. Direct techniques have short useful lives, and adversaries move rapidly toward exceptions, suppliers, support processes, and novel trust relationships.

Path from the present

Automation improves discovery and social manipulation. Providers deploy stronger defaults and share abuse information. Criminal services professionalize, but defensive telemetry also improves. The environment becomes a continuous contest rather than a one-sided decline in security.

Northbridge exposure

Standard controls perform well, but inconsistent regional processes, delegated administration, and supplier access become decisive. Centralization provides visibility and policy consistency yet increases the consequence of a rare control-plane failure.

Consequences and implications

Northbridge needs adaptable detection, rapid control validation, supplier evidence, segmented privileged administration, and rehearsed recovery. Static compliance is inadequate. Investments that improve learning speed and control adaptability outperform controls optimized for one technique.

Signposts
  • shorter intervals between new abuse and provider mitigation;
  • migration toward exceptions after control deployment;
  • increased use of delegated applications and suppliers;
  • better defensive visibility but continuing incident pressure;
  • high variation between mature and lagging organizations.
Project Horizon scenario 3: Uneven Ground
Core condition

Criminal access markets remain fragmented, but defensive maturity varies widely. Opportunistic actors exploit inconsistent regional controls, legacy systems, smaller suppliers, and weak support processes. No single scalable ecosystem dominates, yet local exposure remains substantial.

Path from the present

Market disruption limits specialization, while economic and regulatory differences produce uneven security adoption. Major providers improve controls, but smaller organizations and regional partners lag. Attackers select targets based on weak local conditions rather than broad campaigns.

Northbridge exposure

A regional model limits propagation but risks control variance and scarce specialist capacity. A centralized model raises baseline consistency but may overlook local suppliers and regulatory conditions. Managed services vary significantly in transparency and quality.

Consequences and implications

Leadership should emphasize minimum control standards, regional assurance, service ownership, and evidence that local recovery works. Broad threat averages are poor guides; exposure must be assessed by region and dependency.

Signposts
  • stable overall incident levels with strong regional variation;
  • persistent exploitation of legacy and supplier pathways;
  • uneven enforcement of resilience requirements;
  • limited consolidation among access sellers;
  • repeated local incidents without common infrastructure.
Project Horizon scenario 4: Open Market
Core condition

Criminal access becomes scalable and dependable while defensive and institutional response lags. Automation, specialization, and weak disruption reduce attacker cost. Concentrated identity and service dependencies create opportunities for industrialized intrusion and extortion.

Path from the present

Access markets build reputation mechanisms and reliable supply. Provider protections deploy unevenly, organizations retain legacy exceptions, and regulatory coordination is slow. Successful operations attract more suppliers and buyers, reinforcing the ecosystem.

Northbridge exposure

Centralized identity and shared recovery create material common-cause exposure. Regional inconsistency also creates entry points, so decentralization alone is not protective. Managed-provider concentration may amplify systemic effects.

Consequences and implications

Northbridge should accelerate independent recovery, privilege segmentation, support verification, supplier controls, and continuity capabilities. Architecture decisions should preserve separation and exit options. Warning lead time may be short once access is sold.

Signposts
  • growing independent evidence of reliable access transactions;
  • falling access prices or increased seller specialization;
  • repeated identity-enabled incidents across stable source populations;
  • slow platform-control adoption or successful evasion at scale;
  • increasing provider and administrative concentration without validated recovery.
Derive consequences conditionally

A scenario does not assert that Northbridge will suffer every possible outcome. Use conditional chains:

In Open Market, if scalable access intersects with centralized privileged administration and independent recovery remains untested, then multi-service disruption becomes more plausible and potentially more persistent. If segmentation and recovery perform as intended, the same external environment may produce frequent investigations without strategic interruption.

This phrasing preserves the distinction between environmental pressure and organizational consequence.

Evaluate consequences across common dimensions:

  • service continuity and transaction integrity;
  • regulatory authorization and evidence obligations;
  • customer and partner effects;
  • financial loss and opportunity cost;
  • expansion timing and operating-model flexibility;
  • recovery capacity and leadership attention;
  • trust and strategic reputation.

Use the same consequence framework across scenarios to enable comparison.

Test organizational choices across every future

Scenarios become useful when leadership options are evaluated consistently. For Project Horizon, test:

  • centralized identity with independent recovery;
  • regional administrative separation;
  • a managed-service model;
  • a hybrid architecture;
  • stronger approval integrity and reconciliation;
  • supplier diversification and exit capability;
  • adaptive detection and continuous control validation;
  • delayed expansion pending resilience evidence.

For each option, ask:

  1. Which scenario conditions does it address?
  2. Which exposures remain?
  3. Which new dependencies or risks appear?
  4. How long does implementation take?
  5. Is the action reversible or staged?
  6. Which evidence demonstrates effectiveness?
  7. What triggers expansion, pause, acceleration, or exit?

An option that performs reasonably well across several futures is robust. An option that performs exceptionally in one future and poorly in others is contingent and should have clear activation indicators.

Identify robust, contingent, and no-regret actions

Use precise categories:

  • Robust action: Performs acceptably across most plausible futures.
  • Contingent action: Valuable only under specified conditions or thresholds.
  • No-regret action: Provides sufficient value even if the anticipated threat change does not occur.
  • Hedge: Limits downside while preserving the ability to shift later.
  • Option-creating action: Builds information, capability, contractual rights, or architecture that keeps future choices open.
  • Irreversible commitment: Narrows later choices and therefore requires stronger justification.

For Northbridge:

Action Classification Reason
Exercise independent identity recovery No-regret and robust Improves evidence and resilience in every scenario.
Preserve regional administrative separation capability Hedge and option-creating Limits common-cause exposure if warning strengthens.
Fully decentralize immediately Contingent Valuable in Open Market but costly and potentially inconsistent elsewhere.
Improve support verification Robust Addresses displaced and opportunistic pathways across scenarios.
Delay all expansion Irreversible or high-cost response Justified only if consequence and warning cross agreed thresholds.

Categories support reasoning; they do not decide policy automatically.

Create signposts from causal logic

A signpost is observable evidence that a scenario’s underlying conditions are strengthening or weakening. Derive signposts from drivers, mechanisms, assumptions, and exposure—not from the narrative title.

Good signposts are:

  • observable through identified sources;
  • relevant to a scenario distinction;
  • interpretable with alternative explanations;
  • timely enough to preserve a choice;
  • assigned to an owner and review cadence.

For Adaptive Contest, signposts include rapid adversary migration following provider controls and increasing exploitation of exceptions. For Open Market, signposts include reliable access-market scale, declining cost, weak disruption, and rising common identity exposure.

A signpost does not prove that a scenario has arrived. Multiple indicators and contextual analysis support warning judgments.

Represent uncertainty honestly

Do not assign equal probability merely because a matrix has four cells. Scenario sets explore plausibility and decision sensitivity. If evidence supports relative likelihood, state it cautiously and separately from scenario construction.

A useful statement is:

Adaptive Contest is currently best supported by observed provider and adversary adaptation, but evidence is insufficient to exclude Open Market during the three-year horizon. Narrow Channels would become more plausible if ecosystem disruption produces sustained decline across sources with stable coverage.

State confidence in:

  • the selected drivers;
  • the causal logic;
  • the organizational exposure;
  • the consequence assessment;
  • the relative support for each scenario;
  • the signposts and collection coverage.

These confidence levels may differ.

Challenge each scenario

Assign reviewers to test:

  • whether the path from the present is plausible;
  • whether actors and defenders would adapt differently;
  • whether a hidden assumption determines the outcome;
  • whether consequences require unsupported links;
  • whether the scenario duplicates another future;
  • whether counterforces could collapse it;
  • whether signposts actually discriminate among scenarios;
  • whether the scenario unfairly favors a preferred option.

Record changes and residual dissent. Do not revise every scenario toward a comfortable middle; distinctness is necessary for meaningful stress testing.

Scenario quality check

Before using the set for decisions, confirm:

  • each scenario begins from the same dated baseline;
  • selected uncertainties appear in their defined states;
  • causal chains contain no unsupported leaps;
  • actor, defender, supplier, regulator, and organizational adaptation are represented;
  • scenarios are internally coherent and meaningfully distinct;
  • consequences are conditional on exposure and control performance;
  • each future identifies counterforces, pivotal assumptions, gaps, and signposts;
  • the same options and consequence dimensions are tested across all scenarios;
  • no scenario is treated as a prediction or assigned probability by construction;
  • product detail matches the horizon and evidence quality.
Analyst habit

For every scenario, write:

This future becomes plausible if…

It would affect Northbridge because…

It would become less plausible if…

Leadership should preserve the option to…

Key takeaways
  • Build scenarios from operating conditions and causal mechanisms, not dramatic incidents.
  • Use a common chain from drivers through behavior, exposure, controls, consequences, and leadership implications.
  • Show how the future develops over time and where intervention remains possible.
  • Make scenarios coherent, distinct, neutrally named, and structurally comparable.
  • Express consequences conditionally and test the same strategic options across every future.
  • Distinguish robust, contingent, no-regret, hedging, option-creating, and irreversible actions.
  • Derive signposts from causal logic and pivotal assumptions.
  • Scenarios expand leadership understanding; they do not eliminate uncertainty or predict which future will occur.