Direct answer
Use “quarterly” as a search topic, not a universal promise. Each advertiser approves a risk-based cadence from concentration, dependencies, custody, exposure, measurement, and incidents. It tests nine scenarios and controls; it does not predict recovery, delivery, reimbursement, or staffing. Choose explicit decision rights, preserve evidence, and stop on unsafe requests; providers retain decisions and timing.
Decision model
Synthesis/inference: A tabletop tests decisions, not theatrical failure. Label each inject controlled, observed, provider-dependent, or unknown; suspension, payment, delivery, misconfiguration, or outage is a state, not its cause. [RS-S07][PR-P10]
Synthesis/inference: Exercise more often after incidents, ownership changes, new markets, concentrated dependencies, or untested controls, and less often when exposure is low and controls are tested. This is planning guidance, not evidence for a universal quarterly rate. Record approver, rationale, findings, and next review. [RS-S08]
Diagnostic or control sequence
Facilitator guide
- Set scope/authority. Choose platform, region, entity, asset graph, and impact band. Confirm who may pause spend, revoke a session, submit an official case, notify a bank, change tracking, and authorize restart. Facilitator injects facts, not provider outcomes.
- Brief roster. Name incident lead, executor, recorder/comms, finance, asset, measurement, security/IT, legal/privacy, and observer; combined roles still need explicit rights. [RS-S09]
- Sequence the clock. Inject the symptom, wait for capture, then add one independent signal or contradiction. Do not publish elapsed-time targets as SLAs.
- Capture before mutation. Register UTC/local time, IDs, label/error, region, last-good export, changes, owner map, payment/policy/verification, and cases. Screenshots supplement exports; missing data is unknown. [RS-S03][DRS-A01]
- Accept and close. Synthesis/inference: name provider dependencies, complete checks, assign findings owners/dates, and sign closure. A green dashboard or script run alone is insufficient; scripts are best effort. [BC-S06]
Roster and authority boundary
| Role | May decide or perform | Must not imply |
|---|---|---|
| Incident lead | Classifies scope, approves one bounded reversible action, stops freelancing. | Authority over a platform, bank, agency, or insurer. |
| Operations executor | Performs the approved action and records expected/actual read-back. | That a completed run proves state. |
| Recorder/comms | Owns timeline, evidence index, case IDs, factual updates, handoffs. | Causal certainty from a status page or anecdote. |
| Asset owner | Confirms custody, spend freeze, restart, and closure scope. | That access equals legal ownership. |
| Finance owner | Reconciles billed, bank/card, served, agency, and settled records; owns issuer route. | That a dashboard proves authorization or revenue. |
| Security/measurement/legal advisers | Decide their specialist boundaries and evidence handling. | Platform outcomes, insurance coverage, or legal conclusions. |
| Facilitator | Controls inject order, safety pause, halt, and handoff to a real incident; may not authorize production mutation. | Participant, approver, or provider representative. |
| Observer | Independently records timestamps, evidence, decisions, communications, stops, dissent, and rubric artifacts; does not coach. | Incident lead or outcome advocate. |
Exercise safety boundary: These are paper, synthetic, staging, or read-only exercises. Do not revoke production access, reset production credentials, submit a live review, dispute a live charge, pause live campaigns, unlink production partners, rotate shared objects, or create live damage. A separately approved safe-control test may use a known non-production target with rollback, read-back, and real-incident handoff authority. Synthesis/inference: Scenario wording below describes simulated decision artifacts and expected read-backs, not live mutations or provider submissions. [RS-S03][RS-S09]
Scenario cards (nine executable injects)
Inject the fact. Recorder captures UTC, label/error, IDs, region/entity, last-good export, changes, owner map, and cases. Take one reversible step; stop on unsafe requests, authority gaps, evidence loss, or failed read-back. [RS-S03][RS-S09][DRS-A01]
1. Compromised administrator or session
- Inject / scope-evidence: Unknown admin/session/extension/token or spend change; inspect person, portfolio, accounts, payments, apps, domains, datasets, logs, notices, and transactions from a known-clean endpoint.
- Roles / safe action: Asset owner authorizes simulated containment; security reviews persistence; finance reviews hypothetical transactions; recorder owns chronology. Draft, do not execute, one session/token revocation and reset plan.
- Stop / communications / acceptance: Stop if ownership is unclear or scope expands. Say “suspected unauthorized access,” use verified channels, and accept after admin/session/app/token, payment, campaign diff, test, monitoring, and sign-off.
- Observer / after-action: Did anyone request a password, cookie, code, or remote control? Assign owner-map, least-privilege, clean-device, and retention tests. [BC-S18]
2. Suspension, restriction, or verification hold
- Inject / scope-evidence: Restricted, suspended, read-only, Account Health, policy, or verification state; preserve detail ID, object, region/entity, notice, linked assets, authentic records, and route.
- Roles / safe action: Asset/legal owner approves simulated truthful remediation; incident lead controls edits; provider decides review; recorder owns the case. Prepare, do not submit, a mock review packet; never replace accounts or alter identity. [PR-P10][PR-P13]
- Stop / communications / acceptance: Stop on unknown route/entity, fabricated evidence, flooding, or evasion. State state, hypothesis, route, uncertainty; accept owner/entity, mock submission, related checks, residual dependency, and next owner.
- Observer / after-action: Did anyone treat the label as cause? Refresh route/label verification by market and test the no-evasion decline rule.
3. Payment lock or dispute
- Inject / scope-evidence: Failed payment, unpaid balance, suspicious payment, chargeback, or agency mismatch; collect balance, transaction ID, currency/date, bank/card, authorization, served delivery, invoice, entity, and payment profile.
- Roles / safe action: Finance owns simulated reconciliation/issuer decision; asset owner approves hypothetical spend changes; incident lead freezes simulated edits. Branch unauthorized activity, legitimate balance, and agency mismatch; do not dispute live. [BC-S07][BC-S08]
- Stop / communications / acceptance: Stop if authorization or billed-entity mapping is unresolved; no blanket chargeback. Separate platform, bank/card, agency records. Accept reconciliation or residuals, official route, clean payment state, and restart approval.
- Observer / after-action: Did ledgers remain separate? Test invoice export, transaction matching, dual approval, and dispute routing.
4. Delivery zero with no acknowledged incident
- Inject / scope-evidence: Login works but a critical campaign has no impressions/clicks; capture delivery export, IDs, payment/policy/verification, budget, changes, endpoint/feed, status, UI/API, and customer symptoms.
- Roles / safe action: Incident lead classifies; asset owner approves hypothetical delivery change; measurement checks events; provider owns provider incidents. Capture read-only/synthetic snapshot and compare signals; do not edit live settings. [PR-P09][PR-P21]
- Stop / communications / acceptance: Stop without rollback/read-back or when scope expands. Say “delivery-zero observed; cause unknown.” Accept account/campaign read-back, payment/policy/endpoint checks, test, monitoring, and sign-off.
- Observer / after-action: Did anyone rely on green status or app outage alone? Add independent delivery, endpoint, and customer-impact signals.
5. Measurement/reporting failure
- Inject / scope-evidence: Report stale or “misconfigured” while analytics, CRM, or orders disagree; preserve query/export version, event IDs, consent/deduplication, platform, analytics, CRM, backend, finance, timestamps, and cohort.
- Roles / safe action: Measurement leads; finance quarantines simulated conclusions; asset owner approves hypothetical edits; privacy/legal controls sharing. Freeze a synthetic cohort and compare ledgers; do not rewrite tracking. [PR-P18][RS-S07]
- Stop / communications / acceptance: Stop when definition, time zone, attribution window, or ownership is unknown. Report variance/freshness, not lost revenue or fraud. Accept residuals, observed event, monitoring, and restart decision.
- Observer / after-action: Did participants conflate spend, attribution, analytics, and settlement? Add schema/version and freshness checks.
6. Platform outage or control-plane incident
- Inject / scope-evidence: Login, creation, reporting, or API errors while status is green; capture surface, status/history, raw errors/request IDs, UI/API, second admin, symptoms, last-good export, and telemetry.
- Roles / safe action: Incident lead controls simulated changes; liaison drafts official route; provider decides recovery; communications states facts. Simulate preservation/freeze; do not retry destructive edits. [PR-P09]
- Stop / communications / acceptance: Stop when status is treated as cause or workaround is untracked. Name product, region, time, symptoms, unknowns; accept signals, read-back, exports, staged restart, and closure.
- Observer / after-action: Did the team distinguish provider acknowledgment from advertiser impact? Archive product-scoped evidence and test outage communications.
7. Provider or agency interruption
- Inject / scope-evidence: Agency, API/feed vendor, manager link, billing intermediary, or support partner is unavailable; collect owner/full-control admin, partner/token/app map, contract/exit terms, direct path, exports, invoices, requests, and dependencies.
- Roles / safe action: Asset owner decides simulated custody/removal; finance owns invoices; operations drafts changes; counsel handles contracts. Map dependency and draft export/owner-access test; do not unlink or rotate production objects.
- Stop / communications / acceptance: Stop if only provider can act, ownership is disputed, or removal severs entities. Say “provider dependency unavailable.” Accept owner access, export/map, billing/handoff residuals, and lawful restart/referral.
- Observer / after-action: Did anyone equate partner access with ownership? Add offboarding and direct-platform fallback tests.
8. Regional or legal interruption
- Inject / scope-evidence: Country, entity, category, statutory, or document condition interrupts a market; preserve region/entity/category, notice, route, inventory, and lawful alternatives.
- Roles / safe action: Legal/business owner decides simulated jurisdiction; asset owner models containment; provider applies policy. Classify only with evidence; simulate pause/local advice, never alter live delivery. TikTok’s 2025 U.S. event was legal/DNS-bound, not Ads-delivery proof. [PR-P22][PR-P25]
- Stop / communications / acceptance: Stop if a U.S. route is generalized, records mismatch entity, or concealment is proposed. State scope/date/uncertainty; accept route review, lawful fallback, baseline, and residual owners.
- Observer / after-action: Did the team preserve jurisdiction and category? Maintain a regional matrix with refresh and legal-review triggers.
9. Off-hours escalation
- Inject / scope-evidence: Material symptom arrives outside verified coverage; approver is unreachable. Collect roster, contact attempts, time zone, record, status, second admin, transaction, official route, and unavailable-data note.
- Roles / safe action: Documented owner/incident lead authorizes hypothetical action; otherwise record unavailable authority. Draft preservation and pre-authorized containment; paper-route official contacts only. [BC-S17]
- Stop / communications / acceptance: Stop on authority ambiguity, secret request, or irreversible change. Send factual update with attempts, state, next owner; accept authority or gap, checks, finding, and closure.
- Observer / after-action: Did anyone page an unrostered person? Approve cadence and coverage from observed risk, then test the contact tree.
Blameless after-action and retest
Synthesis/inference: After each exercise, facilitator freezes the record; observer compares chronology, decisions, and read-backs. Record evidence, authority, and safety gaps without blame. Assign each action an owner/date, retest evidence, and scenario. Closure requires the artifact, observer confirmation, and signed retest; otherwise it remains open. [RS-S03][RS-S09]
Evidence to preserve
The recorder owns one evidence register with copies for owners: incident ID; UTC/local times; platform/product/region/entity; account/object IDs; exact label/error; exports/status URL; access/partner/app/token and budget changes; invoices/transactions; event/schema versions; chronology; communications; storage; unavailable evidence/owner; redaction/retention. Preserve before revoking, deleting, relinking, rotating, or rebuilding; screenshots are context only. [DRS-A01][RS-S03][PR-P18]
What not to do
Do not rotate identities/payment methods, create replacement accounts, cloak destinations, forge documents, spam appeals, share credentials/cookies/MFA/IDs/payment or browser data/scripts/remote access, or blanket-chargeback to evade restrictions. Use official domains, preserve evidence, and route legal, insurer, bank, forensic, platform decisions to owners. [PR-P07][PR-P10][BC-S07][BC-S18]
When to escalate
Synthesis/inference: Use self-service for small, reversible, documented scope with healthy owner access and no compromise, finance, regional, or cross-system ambiguity. Escalate for material exposure, uncertain authority, suspected compromise, multi-asset dependency, evidence/finance coordination, or an untested control. Refer to platform support, bank/issuer, counsel, broker/insurer, or security response as facts require. No route guarantees outcomes or staffed response.
FAQ
Is quarterly mandatory? No. Each advertiser approves and records a risk-based cadence.
Can a tabletop prove recovery time? No. It tests decisions, not provider timing or an SLA.
Should we simulate live damage? No. Use paper, synthetic, staging, or read-only injects.
What if no owner is available? Record the authority gap; use only pre-authorized reversible containment.
Does login or a script run close the exercise? No. Verify custody, dependencies, ledgers, measurement, testing, monitoring, and sign-off.
Source appendix
Sources accessed 2026-07-19; mutable routes require re-check.
| Key | URL | Exact source title; author/publisher; date | Boundary |
|---|---|---|---|
| RS-S03 | https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf | Cybersecurity Incident & Vulnerability Response Playbooks; CISA; 2021. | Roles; thresholds excluded. |
| RS-S07 | https://sre.google/sre-book/monitoring-distributed-systems/ | Monitoring Distributed Systems, chapter 6; Rob Ewaschuk, edited by Betsy Beyer; Google SRE; 2017. | Signals; metrics proxies. |
| RS-S08 | https://sre.google/sre-book/service-level-objectives/ | Service Level Objectives, chapter 4; Chris Jones, John Wilkes, Niall Murphy, Cody Smith; Google SRE; 2017. | Internal objectives; no SLA. |
| RS-S09 | https://sre.google/sre-book/managing-incidents/ | Managing Incidents, chapter 14; Andrew Stribblehill; Google SRE; 2017. | Handoffs. |
| PR-P03 | https://www.facebook.com/business/help/530209463124901/ | Request a review if you are restricted from advertising on Meta platforms; Meta Business Help Center; undated/current. Accessed 2026-07-19. | Route/title/available OG metadata only; server metadata says “Learn how to request a review if your account is restricted from advertising on Meta platforms.” Body object types, eligibility, timing, and outcome remain unverified; current authenticated browser/session check required; no guarantee. |
| PR-P07 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ | Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26. | Anti-evasion. |
| PR-P09 | https://ads.google.com/status/publisher/summary | History | Google Ads Status Dashboard; Google; live/undated. | Product status. |
| PR-P10 | https://support.google.com/adspolicy/answer/9841640?hl=en | Google Ads account suspensions overview; Google Ads Help; current/undated. | Account/region-specific. |
| PR-P13 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 | About suspended ad accounts on TikTok; TikTok for Business; updated June 2026. | Mutable labels. |
| PR-P18 | https://www.searchenginejournal.com/google-ads-experiencing-outage-impacting-key-features/523624/ | Google Ads Experiencing Outage Impacting Key Features [Updated]; Matt G. Southern, Search Engine Journal; 2024-08-01, updated 2024-09-19. | Reported. |
| PR-P21 | https://searchengineland.com/google-ads-stop-running-for-some-advertisers-452864 | Google Ads stop running for some advertisers; Barry Schwartz, Search Engine Land; 2025-03-02, updated 2025-03-03. | Reported; cause unclear. |
| PR-P22 | https://blog.cloudflare.com/the-fall-and-rise-of-tiktok-traffic/ | The fall and rise of TikTok (traffic); João Tomé, Cloudflare Blog; 2025-01-21, modified 2026-07-15. | U.S. DNS. |
| PR-P25 | https://www.congress.gov/118/plaws/publ50/PLAW-118publ50.pdf | Public Law 118-50, Division H; U.S. Congress; 2024-04-24. | Legal. |
| BC-S06 | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors | Errors and Warnings; Google Ads Scripts team; updated 2026-06-24. | Best effort. |
| BC-S07 | https://support.google.com/google-ads/answer/13704200 | Billing and payment suspensions; Google Ads Help; current/undated. | Billing state. |
| BC-S08 | https://support.google.com/google-ads/answer/10560092 | How to dispute a Google Ads charge; Google Ads Help; current/undated. | Reconcile first. |
| BC-S10 | https://www.meta.com/help/policies/539039418231124/ | If your account was hacked or someone is using it without your permission; Meta Help Center; updated 32 weeks before access. Accessed 2026-07-19. | Candidate route/title only; body not quote-locked here. Current authenticated browser/session check required before recovery-step claims; not proof linked assets are clean. |
| BC-S17 | https://response.pagerduty.com/ | PagerDuty Incident Response Documentation; PagerDuty; current/undated. | Role framing. |
| BC-S18 | https://www.group-ib.com/blog/meta-phishing-campaign/ | Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25. | Impersonation caution. |
| DRS-A01 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf | Digital Evidence Preservation: Considerations for Evidence Handlers; Barbara Guttman, Douglas R. White, Tracy Walraven, NIST; 2022-09. | Preservation principles. |
Related resources
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- TikTok Ads Not Delivering? Diagnose Zero ImpressionsTikTok ads approved but not delivering or spending? Check delivery status, billing, schedule, audience, bid, budget, and creative before making changes.
- Meta Pixel Not Firing — Troubleshooting GuideYour Meta Pixel is not firing or firing inconsistently. Here's how to diagnose the issue, fix broken tracking, and restore your conversion data and retargeting audiences.
- Google Ads Suspension Recovery — The Full RoadmapA step-by-step roadmap for recovering from a Google Ads suspension: how to triage the suspension type, which appeal channel to use, realistic timelines, and what to do if the appeal fails.
Contact AdsInfra
Send a message about this resource before making a high-impact change.