CASE FILE 2026-2A — SECURING XTENSR LABS AP Cybersecurity · Unit 2 · Physical Vulnerability Assessment
0 / 14 answered

Unit 2 Scenario 2A: Securing Xtensr Labs

Physical Security Team · Acquisition Support · Investigator Copy

Xtensr Research Labs is acquiring Meridian BioAnalytics, a smaller research company across town, to expand its genomics operations. You've been assigned to the physical security team supporting the acquisition.

Across the five cases below, you will review the facility's building plans and current security controls, identify physical vulnerabilities, assess the risk each one poses, recommend physical controls to mitigate them, and recommend where to place monitoring equipment to detect breaches.

Work through the cases in order — each one builds on the vulnerabilities and risk ratings you identify earlier. Every text box autosaves as you type.

CASE 2026-2A-1 Physical Intrusion Risk

Site Survey & Vulnerability Identification

SUBJECT: Meridian BioAnalytics facility, 4410 Corbett Mill Road · Single-story, ~22,000 sq ft · Built 1998 · Acquisition closes in 60 days

Meridian BioAnalytics never handled data or materials considered high-value targets, so its physical security has drifted for years: small fixes get deferred, and inconvenient controls get quietly worked around by staff. Once Xtensr's genomics division moves in, this building will house a proprietary sequencing lab and a server room holding unpublished research data.

You walked the site with Meridian's facilities manager and logged what you observed. The Facility Survey Log below records each location, what you observed, and the control currently in place. Click a row's Flag pill to mark it as a vulnerability worth carrying into your risk assessment.

Facility Survey Log — click a row to flag it as a vulnerability
Location Observation Current Control Flag
Saved
Saved
Saved
Saved
CASE 2026-2A-2 Risk Rating Required

Risk Assessment

METHOD: Risk = Likelihood × Impact, rated Low / Medium / High for each factor

A vulnerability isn't automatically a crisis — it becomes a priority based on how likely it is to be exploited and how severe the consequences would be if it were. Consider impact in terms of research data loss or theft, disruption to lab operations, regulatory exposure, and physical safety.

For each vulnerability below, set a Likelihood and Impact rating. The Risk Level updates automatically using the matrix your instructor has taught in class.

Risk Register
Vulnerability Likelihood Impact Risk Level
Saved
Saved
Saved
CASE 2026-2A-3 Remediation Plan

Control Recommendations

CONSTRAINT: Leadership has approved a limited hardening budget for the first 90 days post-acquisition only

Xtensr's leadership wants a prioritized, budget-aware set of physical controls — not a wish list. As you select controls, think about what type each one is: preventive (stops an incident), detective (notices one happening), deterrent (discourages an attempt), or corrective (fixes a broken control so it works as intended).

Click Recommend on every control from the catalog below that you want to include in your remediation plan.

Control Options Catalog
Candidate Control Type Cost Tier Recommend
Saved
Saved
Saved
CASE 2026-2A-4 Surveillance Design

Monitoring Equipment Placement

GOAL: Detect a breach that a physical control failed to prevent, and alert someone fast enough to respond

Controls try to stop an incident before it happens. Monitoring equipment assumes something might get through anyway, and is designed to detect it and trigger a response. Click a zone on the floor plan below to cycle through equipment options: None → Camera → Motion Sensor → Door/Window Contact → None.

SOUTH PARKING LOT LOBBY SERVER ROOM SEQUENCING LAB RECEPTION BREAK ROOM FREEZER / STORAGE Front Entrance (no windows) Ground-floor windows Roof hatch Exterior door Loading dock Fence gap Unlit area
Camera Motion Sensor Door / Window Contact
Monitoring Placement Log (synced with the floor plan)
ZoneEquipment Assigned
Saved
Saved
Saved
CASE 2026-2A-5 Executive Briefing

Executive Summary

AUDIENCE: Xtensr leadership — non-technical, decision-makers, limited time

Leadership doesn't need the full survey log — they need to make a decision. Translate your assessment into language a non-technical executive can act on.

Saved