Facilitated incident-response tabletop exercises
A tabletop exercise puts your team through a realistic incident without the real damage. People work in the roles they actually hold. The decisions they make change what happens next, the same way they would on a bad day. It’s your organisation working an incident it hasn’t had yet.
It’s for security leads, CISOs, and compliance and risk owners who need to know whether their incident-response plan holds, sometimes with an auditor in mind. The people at the table are the ones who would carry the plan out, from the security and IT staff to the managers who make the business calls. Groups of up to about eight work best with me facilitating alone, and larger groups get a second person. I’m based in Copenhagen and run these on site across Europe, or remotely, in English or Danish.
The exercise closes with a debrief, and that’s where most of the value sits. We walk back through what happened and tie it to your real plans, your real controls, and the gaps between them. Nobody is scored in the room. The point is to test the plan and the instinct behind it. A plan nobody has run is a hypothesis, and the fastest way to find out whether it holds is to run it before an incident does.
If part of the reason you’re running one is to show a regulator, an exercise like this evidences that you exercised your incident-response plan, which is a record NIS2, ISO/IEC 27001 and ISO/IEC 27035 expect you to be able to produce. Which regulation expects what is a topic in its own right, and it has its own page.
Where to go next.