High School IntermediateModule I16Lesson 6 of 8

I16.6 Fake Incident Response Tabletop

Coordinate a fictional incident-response exercise through readiness, detection, triage, declaration, containment concepts, continuity, evidence preservation, communication, recovery, validation, closure, and lessons learned.

Lesson Progress

Fake Incident Response Tabletop

High School IntermediateI16: Intermediate Defensive Labs • Lesson 6 of 8

75% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

A Tabletop Tests the Decision System, Not Just the Technical Team

The fictional scenario combines expired supplier access, a broad storage policy, a monitoring gap, a suspicious message, leadership questions, and recovery decisions. The goal is not to invent the most dramatic incident. It is to test whether the organization can define scope, make authorized decisions, preserve evidence, protect service continuity, communicate accurately, validate outcomes, and improve.

Weak tabletop

Treat the scenario as fact, merge every signal, skip owners, assume actions happened, overstate impact, ignore continuity, and end without accountable improvements.

Professional tabletop

Define objectives, test decisions, preserve evidence limits, coordinate owners, communicate by audience, validate recovery, apply closure criteria, and assign improvements.

Objective 1

Define a fictional incident-response tabletop scope covering the scenario, systems, identities, services, suppliers, data, business impact, evidence sources, privacy limits, authority, participants, and exercise goals.

Objective 2

Evaluate fictional signals through readiness, detection, triage, declaration criteria, evidence quality, source health, service context, alternate explanations, potential impact, confirmed impact, and confidence.

Objective 3

Coordinate fictional containment, continuity, communication, evidence preservation, supplier actions, recovery, validation, closure, and lessons learned through the correct approved roles.

Objective 4

Distinguish fictional tabletop decisions, real operational actions, proposed actions, authorized actions, completed actions, validated outcomes, assumptions, limitations, and residual risk.

Objective 5

Create a portfolio-safe fictional incident-response tabletop package with an exercise charter, inject log, decision register, communication map, recovery plan, validation record, metrics, and improvement recommendations.

Why This Matters

Readiness Fails When Roles, Authority, Communication, or Validation Are Unclear

Fictional technical evidence may be strong while the response still fails because no one owns the decision, service continuity is ignored, communications overstate impact, suppliers are not verified, recovery criteria are vague, or improvements never gain owners. Tabletop exercises reveal these coordination gaps before a real event.

Core Concept

Use the Objective–Evidence–Authority–Action–Validation Model

Objective

What fictional security, service, evidence, communication, recovery, or continuity result matters in the current decision window?

Evidence

Which fictional facts, source health, timeline, context, alternatives, confidence, and limitations support the decision?

Authority

Which fictional incident, identity, service, cloud, supplier, communications, privacy, legal, or recovery owner may approve the action?

Action

Which fictional proposed, authorized, completed, failed, rolled-back, monitored, or escalated action follows?

Validation

Which fictional access, configuration, source, service, owner, communication, residual-risk, and closure evidence proves the result?

Key Vocabulary

Incident Response Tabletop Terms

Tabletop exercise

A fictional discussion-based defensive exercise in which participants review a scenario, make decisions, test roles, identify gaps, and record improvements without affecting real systems.

Exercise objective

A fictional statement describing which readiness, coordination, communication, evidence, continuity, recovery, or decision capability the tabletop is designed to evaluate.

Inject

A fictional new fact, event, request, constraint, or change introduced during the tabletop to test participant decisions.

Facilitator

The fictional role that presents the scenario, controls injects, keeps time, asks questions, and preserves safe exercise boundaries.

Controller

The fictional role that manages exercise flow, expected outcomes, rules, and realism while preventing confusion with real operations.

Participant

A fictional person or role expected to make decisions, explain responsibilities, communicate, or validate an outcome during the exercise.

Observer

A fictional role that records decisions, timing, strengths, gaps, assumptions, and lessons without directing the response.

Incident declaration

A fictional authorized decision that the available evidence and business impact meet defined criteria for formal incident handling.

Containment

A fictional approved action intended to limit additional harm, exposure, access, spread, or service impact while preserving evidence and business continuity.

Business continuity

A fictional plan for maintaining or restoring essential services while defensive work continues.

Evidence preservation

A fictional process for maintaining relevant records, timestamps, ownership, integrity, handling, scope, and limitations for later review.

Decision register

A fictional chronological record of decisions, rationale, evidence, authority, owner, deadline, status, rollback, and validation.

Communication cadence

A fictional planned schedule for technical, service, leadership, user, supplier, legal, privacy, and recovery updates.

Recovery criterion

A fictional measurable condition that must be satisfied before a service, identity, control, or process returns to normal operation.

Closure criterion

A fictional requirement covering evidence, impact, recovery, validation, ownership, communication, residual risk, lessons learned, and follow-up before the case closes.

After-action review

A fictional structured review of what happened in the exercise, what worked, what failed, why, and which improvements require owners and deadlines.

Response Roles

Eight Fictional Tabletop Roles

Incident Commander

Responsibility

Maintains the fictional response objective, approves coordination priorities, resolves conflicts, confirms declaration status, and ensures decisions have owners and deadlines.

Authority boundary

Coordinates the response within the approved incident framework but does not automatically own every technical, legal, privacy, supplier, or business decision.

Handoff content

Provides current scope, facts, impact, decisions, actions, blockers, cadence, next milestone, and unresolved risks.

SOC Analyst

Responsibility

Validates fictional alerts, builds the timeline, compares sources, records findings, tracks evidence gaps, and recommends proportionate next actions.

Authority boundary

May perform approved analysis and case actions but escalates containment or service-impact decisions beyond assigned authority.

Handoff content

Provides evidence identifiers, source health, observations, conclusions, alternatives, confidence, and requested owner decisions.

Identity Owner

Responsibility

Reviews fictional account state, sessions, roles, authentication activity, recovery needs, access restrictions, and identity validation.

Authority boundary

Approves identity restrictions and recovery steps according to the fictional process.

Handoff content

Provides identity scope, actions completed, remaining sessions, recovery status, validation, and residual risk.

Service Owner

Responsibility

Explains fictional business function, criticality, dependencies, approved changes, service impact, continuity needs, rollback, and recovery acceptance.

Authority boundary

Approves service changes and business-impact tradeoffs within the fictional service model.

Handoff content

Provides service status, dependencies, continuity plan, owner decisions, validation criteria, and customer impact.

Cloud and Platform Owner

Responsibility

Reviews fictional cloud resources, configuration, network controls, logs, identity paths, rollback options, and platform health.

Authority boundary

Approves platform changes according to the fictional change and incident process.

Handoff content

Provides effective state, actions, rollback, logging health, validation, and unresolved platform risk.

Communications Lead

Responsibility

Creates fictional audience-specific updates that separate known facts, impact, actions, limitations, next steps, and next update time.

Authority boundary

Coordinates approved communications but does not independently determine legal, privacy, or regulatory conclusions.

Handoff content

Provides audience, message, approval, delivery time, response channel, and next cadence.

Supplier Owner

Responsibility

Coordinates fictional supplier verification, access decisions, service obligations, escalation, evidence requests, and support deadlines.

Authority boundary

Manages the supplier relationship but uses independent verification and approved internal ownership.

Handoff content

Provides supplier status, verified contacts, actions, evidence received, contract considerations, and next checkpoint.

Recovery Lead

Responsibility

Coordinates fictional restoration, validation, monitoring, service acceptance, rollback readiness, and transition to normal operations.

Authority boundary

Directs recovery tasks within the approved recovery plan and confirms technical readiness with service owners.

Handoff content

Provides recovery stage, completed tests, failed tests, monitoring state, service acceptance, and residual risk.

Tabletop Injects

Ten Fictional Scenario Injects

INJ-0109:00

Unusual supplier sign-in

New information

A fictional supplier administrator signed in to a confidential support service after its exception expired.

Decision question

Does this meet incident declaration criteria, or should the team open a focused access case while gathering more evidence?

Expected focus

Scope, identity status, approval expiration, activity evidence, impact limits, ownership, and proportionate access restriction.

Safety boundary

No real identity, credential, supplier, or service information is used.

INJ-0209:12

Cloud policy changed

New information

A fictional confidential storage policy changed outside the approved window and now includes a broad read condition.

Decision question

Should the team restrict the policy immediately, and what can be communicated about possible exposure?

Expected focus

Effective access, rollback authority, confirmed versus possible impact, access evidence, data ownership, and validation.

Safety boundary

No real cloud account, resource, key, secret, or data is involved.

INJ-0309:24

Audit source stops reporting

New information

A fictional administrative audit source stops delivering records thirty minutes after the storage-policy change.

Decision question

How does the source gap affect confidence, priority, containment, evidence preservation, and communication?

Expected focus

Source health, compensating evidence, uncertainty, failover, gap reconstruction, and avoidance of unsupported incident claims.

Safety boundary

The source and all logs are fictional training artifacts.

INJ-0409:36

Service owner reports no outage

New information

The fictional application remains available, but the service owner cannot confirm whether unauthorized access occurred.

Decision question

How should the team balance service continuity with targeted restrictions and evidence review?

Expected focus

Business impact, containment options, least disruption, approved changes, owner authority, and measurable recovery criteria.

Safety boundary

No live service action is requested.

INJ-0509:48

User report arrives

New information

A fictional employee reports a suspicious payroll-themed message and one link click without credential entry.

Decision question

Is the message related to the cloud and supplier records, or should it remain a separate case?

Expected focus

Case boundaries, evidence-based linkage, phishing triage, user guidance, identity review, and avoidance of scope inflation.

Safety boundary

No real message, link, recipient, or credential is included.

INJ-0610:00

Leadership requests an update

New information

Fictional leadership asks whether confidential data was exposed and whether the service must be taken offline.

Decision question

What can be stated confidently, what remains unknown, what actions are underway, and when is the next update?

Expected focus

Decision-ready communication, facts, impact limits, owners, actions, service status, confidence, and cadence.

Safety boundary

The update remains fictional and contains no private information.

INJ-0710:15

Access restriction completed

New information

The fictional supplier access is removed and the storage policy is restored to the approved identity group.

Decision question

What evidence is still needed before recovery or closure?

Expected focus

Effective access validation, session state, access review, source restoration, service function, owner signoff, and residual risk.

Safety boundary

No real change is performed.

INJ-0810:30

Audit source recovers

New information

The fictional audit source resumes and delayed records show no covered unauthorized storage read during the gap.

Decision question

Can the team conclude no unauthorized access occurred?

Expected focus

Coverage limits, delayed evidence, source completeness, alternate paths, confidence, and careful impact language.

Safety boundary

All recovered records are fictional.

INJ-0910:45

Supplier owner confirms outdated access

New information

The fictional supplier owner confirms the administrative access should have ended with the project.

Decision question

What governance and process improvements should follow?

Expected focus

Lifecycle control, exception expiration, owner accountability, automatic review, supplier process, metrics, and lessons learned.

Safety boundary

No real contract or supplier record is involved.

INJ-1011:00

Recovery review

New information

The fictional service is healthy, access is restricted, logging is current, and no confirmed disclosure appears in covered evidence.

Decision question

Should the case close, remain in monitoring, or transition to a lower-severity follow-up?

Expected focus

Closure criteria, residual risk, owner signoff, evidence limits, monitoring, communication, and tracked improvements.

Safety boundary

The exercise ends with documentation only.

Decision Framework

Eight Questions for Every Major Inject

What is directly observed?

Strong decision

Record only fictional facts supported by identified evidence, timestamps, source health, scope, and limitations.

Weak decision

Repeat the scenario narrative as though every statement were verified.

Reviewer question

Which exact source supports each fact?

What is the current response objective?

Strong decision

State the fictional priority such as protecting identity, restricting access, preserving service, restoring visibility, validating impact, or communicating clearly.

Weak decision

Allow each team to optimize its own task without one coordinated objective.

Reviewer question

What result matters most in the next decision window?

Do declaration criteria apply?

Strong decision

Compare fictional evidence, impact, criticality, persistence, uncertainty, authority, and defined thresholds.

Weak decision

Declare an incident because an alert is High or avoid declaration because no outage exists.

Reviewer question

Which criterion is met, not met, or still unknown?

Which actions are authorized?

Strong decision

Separate fictional proposed, approved, completed, failed, rolled back, and validated actions with owners and deadlines.

Weak decision

Treat recommendations as completed containment.

Reviewer question

Who approved the action and what evidence confirms completion?

What business impact is known?

Strong decision

Separate fictional service availability, access-control weakness, possible exposure, confirmed access, confirmed disclosure, user impact, supplier impact, and operational disruption.

Weak decision

Use a worst-case scenario as the current impact statement.

Reviewer question

What impact is directly supported now?

What evidence is missing or unhealthy?

Strong decision

Document fictional gaps, delays, incomplete coverage, conflicting records, stale sources, and compensating evidence.

Weak decision

Treat missing evidence as proof of harm or proof of safety.

Reviewer question

How does the gap change confidence and action?

Who must receive which update?

Strong decision

Tailor fictional technical, service, leadership, user, supplier, legal, privacy, and recovery messages to audience need and authority.

Weak decision

Send one detailed message to everyone.

Reviewer question

What does this audience need to decide or do?

What proves recovery or closure?

Strong decision

Use fictional access, configuration, source, service, communication, owner, validation, residual-risk, and improvement criteria.

Weak decision

Close when alerts stop or when one change ticket is complete.

Reviewer question

Which measurable evidence proves the response objective was achieved?

Communication Matrix

Six Fictional Audience Plans

Technical response team

Needs

Detailed fictional scope, evidence, source health, timeline, decisions, owners, actions, blockers, and next validation.

Avoid

Unsupported impact claims, real credentials, private data, or unapproved operational instructions.

Cadence

At major injects and every thirty fictional minutes.

Service owner

Needs

Fictional service status, dependencies, containment options, business tradeoffs, validation, and recovery criteria.

Avoid

Raw technical detail that does not support a service decision.

Cadence

At each service-impact or recovery decision.

Leadership

Needs

Fictional facts, confirmed impact, possible impact, confidence, actions, service status, decisions required, and next update time.

Avoid

Long raw logs, speculation, blame, or certainty beyond evidence.

Cadence

At declaration, major impact change, recovery milestone, and closure transition.

Affected users

Needs

Fictional clear guidance about what not to do, what is known, what action is required, support path, and next update.

Avoid

Unnecessary technical detail, private case data, or unsupported claims.

Cadence

When user action or awareness is required.

Supplier owner

Needs

Fictional verified request, access status, service need, evidence required, deadline, and escalation path.

Avoid

Using contact details supplied by a suspicious message or unverified source.

Cadence

At access restriction, verification, evidence receipt, and resolution.

Recovery team

Needs

Fictional recovery stage, dependencies, tests, failures, rollback, monitoring, service acceptance, and residual risk.

Avoid

Declaring recovery before validation is complete.

Cadence

At each recovery gate.

Tabletop Workflow

Eight Steps from Exercise Preparation to Improvement

1

Prepare the exercise

Define fictional objectives, scope, safety boundaries, participants, roles, scenario, injects, evidence, timebox, communication rules, and success criteria.

Output: Exercise charter and participant brief.

2

Validate the initial signal

Review fictional alert, source health, identity, service, business context, change history, criticality, alternatives, and immediate risks.

Output: Initial triage statement.

3

Decide response status

Compare fictional facts with declaration criteria, impact, uncertainty, persistence, ownership, and authority.

Output: Declaration and priority decision.

4

Coordinate containment and continuity

Choose fictional access, configuration, network, identity, supplier, service, logging, monitoring, and continuity actions with rollback.

Output: Containment and continuity plan.

5

Preserve evidence and communicate

Maintain fictional timestamps, evidence references, source health, decision rationale, audience-specific updates, approvals, and next cadence.

Output: Evidence and communication register.

6

Recover and validate

Confirm fictional access, sessions, configuration, source delivery, service function, owner acceptance, monitoring, rollback readiness, and residual risk.

Output: Recovery validation record.

7

Close or transition

Apply fictional closure criteria, record unresolved risks, transfer follow-up actions, communicate status, and preserve case ownership.

Output: Closure or transition decision.

8

Learn and improve

Complete fictional after-action review, assign owners and deadlines, update runbooks, controls, training, suppliers, metrics, detection, and exercise plans.

Output: After-action and improvement package.

Fake Dashboard

Fake Northbridge Incident Response Tabletop Dashboard

Training dashboard for fictional exercise decisions only.

Scenario injects

10

Supplier access, cloud policy, source health, service continuity, phishing, leadership, recovery, and governance decisions are represented.

Separate cases

2

The fictional supplier and cloud records may share one response thread, while the phishing report remains separate without linkage evidence.

Confirmed disclosure

0

The fictional evidence supports control weaknesses and possible exposure but no confirmed data disclosure.

Fake SOC Alert

Expired Supplier Access, Broad Cloud Policy, and Audit Gap Require Coordinated Response

Source: Fake Northbridge Tabletop Console • Time: 10:22 AM

High Severity
A fictional supplier administrator used access after approval expiration, a confidential storage policy contains a broad read condition, and a critical cloud audit source stopped reporting. No confirmed disclosure appears in the supplied evidence.
Defensive recommendation: Restrict unsupported access and policy state, restore logging, preserve evidence and source limits, assign incident, identity, service, cloud, supplier, and communications owners, protect service continuity, validate outcomes, and communicate only supported impact.

Fake Log Panel

Fake Northbridge Tabletop Decision Timeline

training-log-viewer.log
09:00 INJECT supplier-signin='post-expiration'
09:08 DECISION access-case='opened'
09:12 INJECT storage-policy='broad-read'
09:18 ACTION policy-restriction='proposed'
09:24 INJECT audit-source='stopped'
09:30 ACTION source-failover='authorized'
09:36 SERVICE availability='healthy'
09:48 INJECT payroll-message='separate-case'
10:00 LEADERSHIP update='requested'
10:06 IMPACT disclosure='unconfirmed'
10:15 ACCESS supplier='removed'
10:17 POLICY approved-state='restored'
10:30 SOURCE audit='recovered'
10:34 EVIDENCE covered-read='none-observed'
10:45 OWNER supplier-access='outdated'
11:00 TRANSITION monitored-followup='proposed'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Six Fictional Tabletop Findings with Confidence and Limits

NBR-IR-F01High

The fictional supplier access should be handled as an urgent access-control case and may support incident declaration if additional impact evidence appears.

Evidence support

Expired approval, confidential service scope, active sign-in, supplier-owner confirmation, and no current renewal.

Alternate explanation

A legitimate emergency support need may have existed but was not documented.

Impact statement

Unsupported administrative capability is confirmed; misuse and disclosure are unconfirmed.

Next action

Remove access, review activity, validate sessions, notify owners, and preserve declaration criteria for reassessment.

NBR-IR-F02High

The fictional broad storage policy requires immediate restriction without claiming confirmed data disclosure.

Evidence support

Outside-window change, confidential classification, broad read condition, no approved exception, and healthy configuration evidence.

Alternate explanation

A legitimate temporary sharing need may exist but is not documented.

Impact statement

Possible exposure is supported; unauthorized access and disclosure are unconfirmed.

Next action

Restore approved access, review covered access evidence, validate effective state, and communicate impact limits.

NBR-IR-F03High

The fictional audit-source outage increases uncertainty and response priority but does not prove malicious activity.

Evidence support

Current thirty-eight-minute administrative logging gap, critical cloud coverage, healthy source monitor, and partial compensating evidence.

Alternate explanation

A nonsecurity delivery failure may explain the outage.

Impact statement

Monitoring assurance is reduced; harmful activity during the gap is unconfirmed.

Next action

Restore or fail over, preserve the gap, reconstruct events, and state confidence limits.

NBR-IR-F04High

The fictional payroll message should remain a separate phishing case unless evidence establishes a relationship.

Evidence support

Different identity, message source, recipients, evidence, requested action, owners, and timeline from the supplier and cloud records.

Alternate explanation

A coordinated scenario is possible but not currently supported.

Impact statement

One click is confirmed; credential compromise and relationship to the cloud case are unconfirmed.

Next action

Triage separately, review the clicked identity, and link cases only through evidence.

NBR-IR-F05Medium-High

The fictional recovered audit records increase confidence but cannot prove that no unauthorized access occurred through every path.

Evidence support

Source recovery, delayed covered records, no observed covered storage read, and documented source scope.

Alternate explanation

An uncovered or delayed access path may exist.

Impact statement

No covered unauthorized read is observed; universal absence of access is not proven.

Next action

Document source scope, review compensating evidence, monitor, and preserve residual uncertainty.

NBR-IR-F06Medium-High

The fictional response can transition to monitored follow-up after access, policy, logging, service, owner, communication, and improvement criteria are validated.

Evidence support

Supplier access removed, policy restored, logging current, service healthy, owner signoff available, and no confirmed disclosure in covered evidence.

Alternate explanation

Unresolved source coverage or related activity may require the case to remain open.

Impact statement

Immediate control conditions are corrected; residual uncertainty and improvement work remain.

Next action

Document closure limits, continue targeted monitoring, assign improvements, and schedule review.

Analyze the Evidence

Do Recovered Audit Records Prove No Unauthorized Access Occurred?

The fictional audit source recovered after a thirty-eight-minute gap.
Delayed covered records show no unauthorized storage read.
The source has documented coverage limits.
Compensating configuration records remained available.
No confirmed disclosure appears in the supplied evidence.
Not every possible access path is represented.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Fictional Tabletop Exercises

Using real incidents, identities, credentials, messages, cloud resources, logs, employee data, school records, or private organizational details in a tabletop artifact.
Confusing a fictional tabletop decision with an action completed in a real environment.
Declaring an incident solely because an alert is High.
Avoiding incident declaration solely because the service is still available.
Treating recommendations as authorized or completed actions.
Combining unrelated phishing, supplier, cloud, identity, and telemetry records without evidence.
Treating missing evidence as proof of harm or proof of safety.
Reporting possible exposure as confirmed disclosure.
Taking broad service-disrupting action without the correct owner and authority.
Failing to preserve rollback and continuity options.
Sending one identical update to technical staff, leadership, users, and suppliers.
Closing after access removal without validating sessions, effective policy, logging, service function, owner signoff, and residual risk.
Completing an after-action review without named owners, deadlines, success measures, and follow-up.
Turning the exercise into offensive planning, real-system testing, credential collection, or unsafe experimentation.

Safe Practice Lab

Run the Northbridge Fake Incident Response Tabletop

Your fictional assignment

Decisions, Authority, Continuity, Communication, Recovery, and Improvement

Use only the supplied fictional Northbridge scenario and injects to conduct a discussion-based defensive exercise.

Required deliverables

  1. Exercise charter with objectives, scope, safety boundaries, participants, roles, timeline, evidence, communication rules, and success criteria.
  2. Inject log with decisions, assumptions, evidence, authority, owners, deadlines, status, rollback, and validation.
  3. Incident declaration and priority decision with criteria and confidence.
  4. Containment, continuity, evidence preservation, supplier, identity, cloud, service, and communication plans.
  5. Audience-specific technical, service, leadership, user, supplier, and recovery messages.
  6. Recovery and closure criteria with access, policy, source, service, owner, residual-risk, and monitoring evidence.
  7. After-action review with strengths, gaps, root causes, improvements, owners, deadlines, dependencies, and success measures.
  8. Leadership summary, technical summary, reflection, and portfolio-safety statement.
This is a fictional discussion exercise only. Do not perform any real containment, account change, cloud action, system test, message interaction, credential request, or operational response.

Scenario Decision Lab

Leadership Asks Whether Confidential Data Was Exposed

The fictional policy was broad, the audit source had a gap, and no covered unauthorized read is observed after source recovery.

Scenario Decision Lab

The Team Wants to Close after Access and Policy Restoration

The fictional supplier access is removed and the storage policy is restored, but source recovery, session validation, owner signoff, communication, and improvement actions are not complete.

Defender Habits

Fake Incident Response Tabletop Checklist

Check Your Understanding

I16.6 Mini Quiz: Fake Incident Response Tabletop

Choose your answers first. Explanations appear only after submission.

1. What is the purpose of a fictional incident-response tabletop?

2. What does the fictional broad storage policy prove?

3. How should the fictional phishing message relate to the cloud case?

4. What does the fictional audit-source gap prove?

5. What should a leadership update include?

6. When can the fictional response transition toward closure?

7. What makes an after-action item useful?

Portfolio Prompt

Portfolio Prompt

Create a fictional Fake Incident Response Tabletop Package for Northbridge. Include the exercise charter, participant and authority map, inject log, evidence register, normalized timeline, declaration decision, containment and continuity plan, case-boundary decisions, supplier and identity actions, cloud and logging actions, audience communication matrix, recovery and closure criteria, decision register, findings, validation, residual risk, after-action review, metrics, improvements, leadership summary, technical summary, reflection, and a portfolio-safety statement.

Use only fictional systems, identities, services, suppliers, cloud resources, messages, logs, decisions, dates, actions, and outcomes.
Make clear that tabletop decisions do not authorize or represent completed actions on real systems.
Do not treat High severity, source gaps, policy state, user clicks, access expiration, or recovered records as automatic proof.
Show how accurate communication and validated recovery are as important as technical containment.

Key Takeaways

What You Should Remember

1.A tabletop tests the whole decision and coordination system.
2.Scenario injects are prompts for analysis, not automatically verified facts.
3.Incident declaration should follow criteria, evidence, impact, uncertainty, and authority.
4.Containment should preserve continuity, evidence, rollback, and correct ownership.
5.Technical, leadership, user, supplier, and recovery audiences need different updates.
6.Recovery and closure require validated outcomes, not only completed change tickets.
7.Portfolio artifacts should use fully fictional evidence and never expose or affect real systems.

Navigation

Continue Module I16