Cyber incident tabletop exercises
We devise realistic scenarios and run them with your leadership and technical teams. You learn whether the plan, the people and the phone tree hold up before you need them.
Most plans have never been used
Most incident response plans have never been tested. They name people who have since left, rely on systems that will be down in a real incident, and leave the hardest decisions, such as whether to pay a ransom or when to tell customers, until the moment they are needed.
A tabletop exercise is a rehearsal. We present an unfolding incident based on attacks happening to organisations like yours, and the team works through it in real time. The gaps show up in a meeting room rather than in a crisis.
What we exercise
Decision making
Who decides, on what information, and how quickly.
Communication
Internal escalation, and what you tell customers, regulators, insurers, the press and law enforcement.
Technical response
Containment, evidence preservation and recovery, for technical teams.
Third parties
Suppliers, managed service providers and any incident response retainer you hold.
Reporting deadlines
Obligations such as the 72-hour personal data breach report to the ICO, and sector rules such as NIS2 and DORA.
Recovery
Backups, business continuity, and how the business keeps running while systems are down.
How the engagement runs
Discovery
We read your incident response plan and talk to key people to understand your organisation and its concerns.
Scenario design
We write a scenario specific to you, drawn from current attacks on your sector, with injects that build pressure.
The session
A facilitated session, usually half a day, for leadership, technical teams, or both.
Review
A report on what worked and the gaps found, with changes to the plan and an action list.
What you get
- A tailored scenario pack you can reuse.
- A facilitated session run by people who test real attacks.
- An after-action report with recommended changes to your plan and playbooks.
When to commission it
- When an incident response plan is new or has been rewritten.
- After a change of leadership, IT provider or major system.
- When a regulator, insurer or customer asks for evidence that the plan has been tested.
- At least yearly, using a different scenario each time.
Questions we get asked
Who should attend?
How long is a session?
Do you use our real plan?
Can it be run remotely?
Related
Threat modelling
Threat modelling for new systems and whole organisations: what could go wrong, who would do it, and which controls matter most, validated against real attacks.
Read more →Red teaming
Covert, objective-led red team engagements that test whether your people, processes and technology detect and stop a determined attacker.
Read more →NIS2 support
What the NIS2 Directive asks of you, and the testing and evidence that show your measures work.
Read more →SavountLessons From Recent Cyberattacks
M&S, Co-op and Harrods, Cartier and Coinbase: what recent attacks have in common, the techniques used, and what defenders should take from them.
Read the article →