Tabletop Exercises
Practice your incident response plan before you have to use it
What this engagement covers
The service
Facilitated scenario-based tabletop exercises that stress-test your IR plan, expose communication gaps, and train executives and technical responders on the decisions they'll actually need to make.
What we test
Ransomware, BEC, insider threat, third-party compromise, cloud tenant takeover, and regulator-focused data-breach scenarios - tailored to your industry and threat model.
How we run it
Pre-exercise interviews to calibrate the scenario, facilitated roleplay with injects, debrief with observations, and written report with prioritized improvements to your IR plan.
Pre-exercise interviews and scenario design
Facilitated roleplay with injects
Decision point capture
Hot wash debrief
After-action report production
Improvement tracking
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Custom scenario tailored to your threat model
- Facilitated 2-4 hour exercise
- Participant debrief session
- Written after-action report
- Prioritized plan improvement backlog
- Annual or semi-annual cadence available
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Findings are mapped to SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF, NIS2, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.