Incident Response Planning & Tabletop Exercises

When an incident hits, there is no time to figure out who calls whom. We build a practical incident response plan and playbooks, then put them to the test with realistic tabletop exercises for your leadership and technical teams.

Why it matters

Most organizations either have no incident response plan or have one that has never been opened. During a real incident — ransomware, a compromised email account, a data breach — that gap turns into confusion, delays, and expensive mistakes.

A good plan is short enough to use under pressure. It names who decides what, who needs to be notified, and what to do in the first hours. And the only way to know it works is to practice it. Tabletop exercises walk your team through realistic scenarios in a safe setting, so the first time they use the plan isn't during a crisis.

Is this right for you?

This service is a good fit if:

  • You don't have an incident response plan, or it hasn't been updated in years
  • Your cyber insurer, customers, or a framework require a tested plan
  • Your leadership has never practiced responding to a cyber incident
  • You've had an incident and want to be better prepared next time
  • You need an annual tabletop exercise for compliance

What's included

Incident response plan

A clear, right-sized plan aligned to NIST SP 800-61 Rev. 3: roles, severity levels, escalation paths, communication, and decision authority.

Scenario playbooks

Step-by-step playbooks for the incidents you're most likely to face — such as ransomware, business email compromise, data breach, lost devices, and insider threats.

Notification and communication planning

Contact lists, notification decision points, and message templates for leadership, staff, customers, insurers, and partners — prepared for review by your legal counsel.

Executive tabletop exercise

A facilitated, discussion-based scenario for leadership focused on decisions, communication, and business impact.

Technical tabletop exercise

A deeper scenario for IT and security staff focused on detection, containment, evidence, and recovery.

After-action report

What went well, what didn't, and specific improvements to your plan, people, and tools.

Frameworks we work with

  • NIST SP 800-61r3
  • NIST CSF 2.0
  • CISA tabletop exercise guidance
  • ISO/IEC 27035

What you receive

  • Incident response plan in editable format
  • Scenario-specific playbooks
  • Contact and escalation matrix
  • Communication templates
  • Tabletop exercise materials and after-action report with improvement plan

How it works

  1. 1

    Review

    Understand your environment, existing plans, insurance requirements, and the incidents you're most likely to face.

  2. 2

    Evaluate

    Identify gaps in roles, tools, contacts, and decision-making.

  3. 3

    Build

    Write the plan and playbooks with your team.

  4. 4

    Enhance

    Exercise the plan with tabletops and turn lessons learned into improvements.

Common questions

Can you run a tabletop exercise if we already have a plan?

Yes. Many clients start with a tabletop to test their existing plan. The after-action report shows exactly what to improve.

How long is a tabletop exercise?

Usually two to four hours, plus planning beforehand and an after-action report afterward. We tailor the scenario to your business and the threats you face.

Will you respond to incidents for us?

We help you prepare and can advise your leadership during an incident. Hands-on forensic investigation is best handled by a dedicated incident response firm — often provided through your cyber insurance — and we'll help you plan how to bring them in quickly.

Let's scope your project

Share a few details and we'll follow up within one business day to talk through your goals and put together a fixed-scope quote.

Request a scoped quote