What problem does it solve?
Security teams often have incident response plans that have never been tested, leaving gaps in escalation procedures, cross-functional communication, and recovery readiness undiscovered until a real breach occurs. This Skill guides the design, facilitation, and evaluation of discussion-based tabletop exercises that test IR playbooks and decision-making without touching production systems.
Core Features & Use Cases
- Scenario and Inject Design: Builds multi-phase scenarios (ransomware, data breach, insider threat, BEC, supply chain) with timed injects that escalate complexity and force real decision-making under pressure.
- Facilitation and Evaluation Framework: Provides facilitator protocols, role-based discussion questions, and scoring criteria across detection, containment, communication, and recovery dimensions.
- After-Action Reporting and Remediation Tracking: Generates structured AARs with scored objectives, gap findings, and assigned action items, plus a Splunk query for tracking remediation due dates.
- Use Case: A SOC manager needs to satisfy NIST and PCI DSS incident response testing requirements before an audit. Use this Skill to run a 3-hour ransomware tabletop exercise with SOC, Legal, PR, and executives, then produce a scored after-action report with owned remediation items.
Quick Start
Design a ransomware tabletop exercise for my SOC team with timed injects, evaluation scorecards, and an after-action report template.