Why it matters
Most organizations either have no incident response plan or have one that has never been opened. During a real incident — ransomware, a compromised email account, a data breach — that gap turns into confusion, delays, and expensive mistakes.
A good plan is short enough to use under pressure. It names who decides what, who needs to be notified, and what to do in the first hours. And the only way to know it works is to practice it. Tabletop exercises walk your team through realistic scenarios in a safe setting, so the first time they use the plan isn't during a crisis.
Is this right for you?
This service is a good fit if:
- You don't have an incident response plan, or it hasn't been updated in years
- Your cyber insurer, customers, or a framework require a tested plan
- Your leadership has never practiced responding to a cyber incident
- You've had an incident and want to be better prepared next time
- You need an annual tabletop exercise for compliance
What's included
Incident response plan
A clear, right-sized plan aligned to NIST SP 800-61 Rev. 3: roles, severity levels, escalation paths, communication, and decision authority.
Scenario playbooks
Step-by-step playbooks for the incidents you're most likely to face — such as ransomware, business email compromise, data breach, lost devices, and insider threats.
Notification and communication planning
Contact lists, notification decision points, and message templates for leadership, staff, customers, insurers, and partners — prepared for review by your legal counsel.
Executive tabletop exercise
A facilitated, discussion-based scenario for leadership focused on decisions, communication, and business impact.
Technical tabletop exercise
A deeper scenario for IT and security staff focused on detection, containment, evidence, and recovery.
After-action report
What went well, what didn't, and specific improvements to your plan, people, and tools.
Frameworks we work with
- NIST SP 800-61r3
- NIST CSF 2.0
- CISA tabletop exercise guidance
- ISO/IEC 27035
What you receive
- Incident response plan in editable format
- Scenario-specific playbooks
- Contact and escalation matrix
- Communication templates
- Tabletop exercise materials and after-action report with improvement plan
How it works
- 1
Review
Understand your environment, existing plans, insurance requirements, and the incidents you're most likely to face.
- 2
Evaluate
Identify gaps in roles, tools, contacts, and decision-making.
- 3
Build
Write the plan and playbooks with your team.
- 4
Enhance
Exercise the plan with tabletops and turn lessons learned into improvements.
Common questions
Can you run a tabletop exercise if we already have a plan?
Yes. Many clients start with a tabletop to test their existing plan. The after-action report shows exactly what to improve.
How long is a tabletop exercise?
Usually two to four hours, plus planning beforehand and an after-action report afterward. We tailor the scenario to your business and the threats you face.
Will you respond to incidents for us?
We help you prepare and can advise your leadership during an incident. Hands-on forensic investigation is best handled by a dedicated incident response firm — often provided through your cyber insurance — and we'll help you plan how to bring them in quickly.