Facilitated incident-response tabletop exercises

A tabletop exercise puts your team through a realistic incident without the real damage. People work in the roles they actually hold. The decisions they make change what happens next, the same way they would on a bad day. It’s your organisation working an incident it hasn’t had yet.

It’s for security leads, CISOs, and compliance and risk owners who need to know whether their incident-response plan holds, sometimes with an auditor in mind. The people at the table are the ones who would carry the plan out, from the security and IT staff to the managers who make the business calls. Groups of up to about eight work best with me facilitating alone, and larger groups get a second person. I’m based in Copenhagen and run these on site across Europe, or remotely, in English or Danish.

The exercise closes with a debrief, and that’s where most of the value sits. We walk back through what happened and tie it to your real plans, your real controls, and the gaps between them. Nobody is scored in the room. The point is to test the plan and the instinct behind it. A plan nobody has run is a hypothesis, and the fastest way to find out whether it holds is to run it before an incident does.

If part of the reason you’re running one is to show a regulator, an exercise like this evidences that you exercised your incident-response plan, which is a record NIS2, ISO/IEC 27001 and ISO/IEC 27035 expect you to be able to produce. Which regulation expects what is a topic in its own right, and it has its own page.

Where to go next.

How it works

The method, step by step. The scenario, the team working it in role, and the debrief that ties it back to your plans.

See the exercises

The full catalogue of facilitated games and exercises. Pick the problem you need your team to practice.

Compliance and standards

How an exercise maps to NIS2, DORA, and the ISO standards, and what it can and can’t evidence.

What you walk away with

The session, a live debrief, a written summary, and an evidence pack for when the exercise is for the auditor.

Who runs these

I facilitate these myself. About twenty years in infosec, practitioner to practitioner.

Talk to me

Tell me where your team is and what you want them to practice, and we’ll shape the exercise and find a date.

No cookies here

Notice there’s no cookie banner here.
That’s intentional and the site is still GDPR-compliant. I chose to avoid cookies and stick to basic, privacy-friendly stats.
My analytics are cookieless: self-hosted Plausible (EU) and PostHog in cookieless mode, with your IP anonymized. No cross-site tracking, nothing that identifies you.
The one cookie I can set does the opposite of every other cookie: it tells my stats to ignore you completely, and you only get it if you ask.

Everybody wins.