An incident response plan you've never tested is not a plan — it's a document. Our tabletop exercise service stress-tests your people, processes, and decisions against realistic breach scenarios, before a real attacker does it for you.
Most organisations discover the gaps in their incident response capability during an actual breach — when the cost of those gaps is at its highest. Our tabletop exercise service surfaces those gaps in a controlled, low-stakes environment so you can close them before they matter.
We design and facilitate scenario-based exercises tailored to your sector and threat profile — ransomware, business email compromise, data exfiltration, supply chain compromise. Your leadership, IT, legal, and communications teams work through the scenario together, making the decisions they would face under real conditions. We observe, facilitate, and then deliver a detailed findings report with prioritised recommendations.
For organisations without a tested IR plan, we can develop one from the ground up — or review and strengthen an existing plan — as a standalone engagement or as part of a broader vCISO retainer.
Custom scenarios built around your industry's most relevant threat actors and attack types.
Expert-led sessions that challenge assumptions and surface decision gaps across technical and leadership teams.
Detailed after-action report identifying capability gaps, decision failures, and prioritised remediation actions.
Creation or review of a tested, practical incident response plan built for your organisation's actual environment.
Scenarios are selected and customised based on your sector, size, and the threat actors most likely to target you.
Tests your containment speed, backup recovery, regulatory notification decisions, and internal and external communications under the pressure of encrypted systems and a ransom demand.
Simulates a finance or executive impersonation attack — testing your verification processes, approval controls, and response when funds have already been transferred.
Explores your response to confirmed data theft — including customer data — with a focus on regulatory notification obligations, legal exposure, and public communications decisions.
Executives and board members who need to understand their role in a breach response and experience the pressure of real-time decisions before they have to make them for real.
Technical teams that want to validate their runbooks, identify gaps in tooling coverage, and stress-test their coordination and escalation processes.
Organisations that must demonstrate a tested incident response capability to satisfy regulatory obligations or cyber insurance underwriting requirements.
Get in touch to scope a tabletop exercise or IR plan engagement tailored to your organisation's threat profile.
Get in Touch