Back to all posts
Lab 39Friday, October 9, 20262 min read

Tabletop-Test an Incident Response Plan

cybersecurityincidentresponsetabletopexerciseplaybooksdocumentationsoclabslearningprocess
View original post

Lab Objective

Test whether an incident response plan helps a team make the next decision during a fictional ransomware scenario.

This lab is a tabletop exercise. It does not simulate a live attack and does not authorise interacting with real systems.

Setup

Prepare a small response pack containing:

  • a fictional asset and network diagram;
  • a synthetic contact list;
  • an incident response procedure;
  • an incident-handler journal template;
  • a short asset inventory;
  • a recovery checklist.

Procedure

  1. Read the scenario inject: several fictional endpoints display a ransom note and one shared file is unavailable.
  2. Start a timeline with the first observation and the person or role that recorded it.
  3. Ask the team to identify the affected assets, the first containment decision, and the evidence that must be preserved.
  4. Use the contact list and assign the security analyst, technical lead, incident coordinator, communications lead, and business owner roles.
  5. Walk through containment, eradication, recovery, and stakeholder communication without inventing facts that the inject did not provide.
  6. Record every point where the plan is unclear, a contact is missing, an owner is ambiguous, or a recovery dependency is unknown.
  7. Finish with a short after-action report: strengths, gaps, owners, and due dates.

Expected Evidence

A good result includes a completed timeline, decisions with reasons, a list of evidence to preserve, assigned roles, unresolved questions, and at least one improvement to the response plan.

Security Takeaway

The exercise tests the plan's usability, not its appearance. A document can be polished and still fail if people cannot find the right contact, identify the affected asset, or agree on who owns the next action.