Use when performing incident response tabletop — plans and facilitates a tabletop exercise to test incident response procedures without impacting production systems. Covers scenario design, participant preparation, exercise facilitation, response evaluation, and after-action review to identify gaps in incident readiness.
| Element | Details |
|---|---|
| Scenario | |
| Date/Time | |
| Duration | hours |
| Facilitator | |
| Observer/Scribe | |
| Participants | |
| Objectives |
| Time (min) | Inject | Information Provided | Expected Response | Evaluation Criteria |
|---|---|---|---|---|
| 0 | Initial alert | Detection & triage | ||
| 15 | Escalation | Severity assessment | ||
| 30 | Scope expansion | Communication | ||
| 45 | Customer impact | External comms | ||
| 60 | Root cause clue | Investigation | ||
| 75 | Resolution option | Decision-making | ||
| 90 | Recovery | Recovery procedures |
| Role | Participant | Responsibilities During Exercise |
|---|---|---|
| Incident Commander | Overall coordination, decision-making | |
| Technical Lead | Investigation, mitigation | |
| Communications Lead | Internal/external communications | |
| Security Lead | Security assessment (if applicable) | |
| Executive Sponsor | Business decisions, customer escalation | |
| Observer/Scribe | Document responses, timing, gaps |
| Category | Finding | Severity | Root Cause | Remediation |
|---|---|---|---|---|
| Detection | High/Med/Low | |||
| Escalation | ||||
| Communication | ||||
| Technical response | ||||
| Documentation | ||||
| Decision-making |
| Priority | Action | Owner | Deadline | Status |
|---|---|---|---|---|
| 1 |
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |