Lab 39Friday, October 9, 20262 min read
Tabletop-Test an Incident Response Plan
cybersecurityincidentresponsetabletopexerciseplaybooksdocumentationsoclabslearningprocess
View original postLab Objective
Test whether an incident response plan helps a team make the next decision during a fictional ransomware scenario.
This lab is a tabletop exercise. It does not simulate a live attack and does not authorise interacting with real systems.
Setup
Prepare a small response pack containing:
- a fictional asset and network diagram;
- a synthetic contact list;
- an incident response procedure;
- an incident-handler journal template;
- a short asset inventory;
- a recovery checklist.
Procedure
- Read the scenario inject: several fictional endpoints display a ransom note and one shared file is unavailable.
- Start a timeline with the first observation and the person or role that recorded it.
- Ask the team to identify the affected assets, the first containment decision, and the evidence that must be preserved.
- Use the contact list and assign the security analyst, technical lead, incident coordinator, communications lead, and business owner roles.
- Walk through containment, eradication, recovery, and stakeholder communication without inventing facts that the inject did not provide.
- Record every point where the plan is unclear, a contact is missing, an owner is ambiguous, or a recovery dependency is unknown.
- Finish with a short after-action report: strengths, gaps, owners, and due dates.
Expected Evidence
A good result includes a completed timeline, decisions with reasons, a list of evidence to preserve, assigned roles, unresolved questions, and at least one improvement to the response plan.
Security Takeaway
The exercise tests the plan's usability, not its appearance. A document can be polished and still fail if people cannot find the right contact, identify the affected asset, or agree on who owns the next action.