Cyber Crisis Tabletop Exercises
Realistic incident scenarios run with technical and management teams to test plans, decisions and communication before a real crisis.
- NIST CSF 2.0 functions
- Respond Recover
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
The first hours of a cyber crisis decide how much damage it causes. Teams that have never practiced lose time deciding who is in charge, who to call and what to tell customers and regulators.
Tabletop exercises let you practice those decisions in a safe setting and fix the gaps before they matter.
What you get
- Incident plans tested against realistic scenarios
- Clear roles and decision rights during a crisis
- Gaps in plans, contacts and communication found early
- An improvement plan based on the exercise
What we cover
- Ransomware and extortion scenarios
- Data breach and regulatory notification
- Payment fraud and business email compromise
- Service outage and supplier compromise
- Separate or joint technical and executive exercises
How we work
-
Design
We agree objectives and participants, and write a scenario based on realistic threats to your sector.
-
Prepare
We review your plans and prepare injects that test key decisions.
-
Run
We facilitate the exercise and record decisions and issues.
-
Debrief
We hold a debrief while the exercise is fresh.
-
Report
We deliver findings and an improvement plan.
Deliverables
- Exercise design and scenario
- Facilitated exercise
- Debrief session
- After-action report
- Improvement plan
Questions buyers ask
Do we need an incident response plan first?
No. An exercise without a plan shows clearly why one is needed. With a plan, it shows whether the plan works.
Who should take part?
It depends on the objectives. Executive exercises include management, legal and communications; technical exercises include IT and security teams.
Related offerings
-
Business Continuity and Resilience
Business impact analysis, continuity plans and disaster recovery planning so critical services keep running through disruption.
NIST CSF function: Govern NIST CSF function: Recover -
Executive Cyber Briefings
Short, focused briefings for boards and senior management on cyber risk, regulation and their role in preparing for incidents.
NIST CSF function: Govern -
Compromise Assessment
A focused investigation to determine whether attackers are already inside your environment, what they accessed, and what to do next.
NIST CSF function: Detect NIST CSF function: Respond