← all drills
Mitsubishi Electric · Practical Cyber × DACTA × Apexagen

Practice Tender — test AI safely

A fully fictional BMS tender, built to rehearse the whole Day-2 workflow — triage, postures, the CAGE prompt — without ever touching a real client's tender.

🟢 Safe to paste into ChatGPT, Claude or Gemini. Meridian One and every clause here are invented for practice — there's no real client, no live data. In real life the one rule still holds: never paste a client's live tender into a consumer AI.

How to practise

  1. Open a web AI chat. Copy the CAGE prompt and paste it in first.
  2. When it plays back its plan, reply “go”, then copy the tender and paste it.
  3. Ask it to triage every clause (Must-have / Nice-to-have / Risky red-herring) and set a posture (Comply / Not-comply + alternative / Clarify / N/A).
  4. Verify by hand. Find the clauses that are indefensible to “Comply” to, and the two that contradict themselves. The AI will confidently miss some — that’s the Eloquence Trap in action.

1 · The CAGE prompt

Paste this first.
CAGE prompt
You are helping a Mitsubishi Electric BMS salesperson respond to a building tender.

CONTEXT: We supply, install and maintain Building Management Systems — DDC/PLC
controllers, HVAC and chiller control, fire-system integration, and the head-end
software. We are the BMS vendor, not the building owner and not the network
integrator. This is a practice tender.

ALIGN: Before you answer, play back in 3-4 lines how you plan to work through the
clauses, and WAIT for me to say "go".

GOALS:
  1. Sort every cybersecurity clause into Must-have / Nice-to-have / Risky red-herring.
  2. For each clause set a posture: Comply / Not-comply (+ a better alternative) /
     Clarify / N/A — each with a one-line rationale.
  3. Flag any clause that is indefensible to "Comply" to, any that contradicts
     itself, and any drafting slip.
  You MUST NOT invent facts, standards or clause numbers. Mark anything uncertain
  as [UNVERIFIED].

EXAMPLE of the row format I want:
  9.x | Must-have | Comply | "Per-engineer MFA through a recorded jump host — we do
        this as standard." | Pillar: Applications

Reply with your ALIGN plan only. Then wait for the tender.

2 · The tender

Paste this after you reply “go”.
Tender BMS-2026-014 — Meridian One
TENDER Ref: BMS-2026-014
Project: Supply, Installation, Testing & Commissioning of an Integrated Building Management System (BMS)
For: Meridian One — a mixed-use commercial tower with a co-located hospital wing and a tenant data hall
Client: Meridian Estates Pte Ltd (the "Employer")

SECTION 9 — CYBERSECURITY, SEGMENTATION & RESILIENCE REQUIREMENTS
The Contractor shall comply with the following. Where it cannot comply, it shall say so and propose an alternative. Respond against each clause number.

9.1  The Contractor shall provide and maintain a complete inventory of every delivered device — controller, gateway, sensor and server — including firmware version and support status, updated on each change.
9.2  The BMS and building-control network shall be segmented from the corporate, guest and tenant networks. Communication out of the control network shall be restricted to the minimum necessary, and one-way where only one-way is required.
9.3  Any remote access to the delivered system shall be disabled unless required, require multi-factor authentication, pass through a secured intermediary (jump/bastion host), be session-logged, and be granted on a time-boxed, per-engineer basis.
9.4  All factory-default credentials shall be changed before handover. Any device running end-of-life or unsupported firmware shall be identified, with a containment plan.
9.5  Critical control sequences and setpoints (including the fire and smoke-control matrix) shall be baselined, backed up in restorable form, and monitored for unauthorised change.
9.6  The Contractor shall support the Employer's incident-reporting obligations, providing logs and asset data in a form the Employer's monitoring team can ingest.
9.7  Accounts on the delivered system shall follow least privilege, with no shared operator logins, and shall automatically log out after a period of inactivity.
9.8  The Contractor should provide a mobile dashboard application allowing the facilities team to view plant status remotely.
9.9  The Contractor should provide energy-analytics reporting suitable for the building's Green Mark submission.
9.10 The Contractor shall warrant that the delivered system is 100% secure against all cyber threats for the full duration of the maintenance contract.
9.11 All products supplied under this contract shall be CCoP-certified.
9.12 Anti-virus software shall be installed, running and kept updated on every field controller and DDC in the building.
9.13 All data in transit and at rest within the BMS shall be protected using quantum-proof encryption.
9.14 Remote vendor access to the control network shall be permanently disabled at all times. The Contractor shall also provide 24/7 remote support with a guaranteed 2-hour remote response to critical faults.
9.15 User passwords for the head-end software shall be a minimum of eight (12) characters, changed every 90 days.
9.16 The Contractor shall be responsible for the cybersecurity of the entire building network, including all tenant and corporate systems connected to it.
9.17 The Contractor shall align the delivered system to recognised standards such as IEC 62443 (zones and conduits) and the CSA Cybersecurity Code of Practice for CII, where applicable to the Contractor's scope.
— End of Section 9 —
Facilitator key — try the tender yourself first

The interesting rows are the traps (9.10–9.13, 9.16) and the Clarify slips (9.14, 9.15). An eager “Comply” on the traps loses the bid and creates liability; the wins are the honest Not-comply + alternative and the Clarify.

#TriagePostureWhy
9.1–9.7, 9.17Must-haveComplyGenuine controls we deliver: asset register, segmentation, MFA remote access, hardening, backups, least-privilege, standards alignment.
9.8–9.9Nice-to-haveComply if scopedReal but non-critical — price them, don't over-invest.
9.10Red-herringNot-comply“100% secure” is indefensible — no one can warrant it. Offer defence-in-depth + a defined risk posture.
9.11Red-herringNot-comply / ClarifyCCoP binds the operator, not a product — “CCoP-certified product” doesn't exist. We design to CCoP-grade controls.
9.12Red-herringNot-comply + altA DDC/field controller can't run AV. Offer segmentation + monitoring + application whitelisting as compensating controls.
9.13Red-herringNot-comply / Clarify“Quantum-proof” is a marketing red flag. Offer strong standards-based encryption + crypto-agility.
9.14TrapClarifySelf-contradiction — “permanently disabled” AND “24/7 remote support.” Ask which; if remote is permitted it comes with the 9.3 stack.
9.15TrapClarifyDrafting slip — “eight (12) characters.” Which is it? The expert notices; don't blindly Comply.
9.16TrapClarify / Not-complyScope over-reach — we secure the BMS segment, not tenant/corporate networks. Clarify the boundary before pricing.

Watch for the Eloquence Trap: the AI will often “Comply” straight through 9.10–9.13 with confident, wrong wording. Verify every posture by hand.

↓ Download the practice tender (PDF)