Incident response simulations

Find out now, not at 2am on a long weekend

Exercises built from your architecture and run by someone who has worked real incidents. You leave with findings that have owners and dates.

Why rehearse

Real incidents are messy. Your exercise should be too.

When it actually happens, two systems report conflicting statuses. Your incident commander is on a plane. Someone asks whether legal has to notify, and whether the clock started an hour ago or yesterday.

That ambiguity is exactly what we rehearse. You walk out knowing your team can make good calls with incomplete information, because they've already done it once.

What makes an exercise worth running

Built to test real decisions

It's built from your world

I start with your architecture, your risk register, your past incidents, and the threats genuinely landing in your sector. Everyone in the room recognises the scenario immediately, so everyone engages with it properly.

The right people are in the room

IT and security, and also legal, comms, finance, executive leadership, and where it matters, your insurer and key third parties. Real incidents test the handoffs: cloud team to SOC, a vendor as the entry point, the acquisition still being integrated.

Your decisions shape what happens next

No predetermined path. The scenario responds to the calls your team actually makes, so you're testing real decision-making under pressure, not recall of a document.

It gets uncomfortable

A good exercise leaves people mildly arguing about who owned what. If everyone walks out feeling reassured, you paid for reassurance, not readiness.

What you get afterwards

A report with specific findings tied to specific moments: the escalation path to tighten when your incident commander is unreachable, the notification clock to get crisp on, the runbook that still references a system you decommissioned last year. Every finding comes with an owner and a date, so improvement starts the same week.

Formats

Choose the right exercise

Security and engineering

Technical tabletop

Detection through to recovery, with your responders.

Your security and engineering teams work a realistic incident from first alert to restoration: detection, triage, containment decisions, forensic preservation, and the recovery sequencing that determines whether you're down for a day or a fortnight.

Scenarios are built from your architecture, your logging, and the threats genuinely landing in your sector. If someone in the room can say "that couldn't happen here," the exercise has already failed.

You get

  • A custom scenario
  • A facilitated session with live injects that respond to your team's decisions
  • An after-action report with named owners and dates
Board and leadership

Executive tabletop

The decisions only your leadership can make.

Disclosure. Regulator notification. Whether to pay. When to tell customers. Who speaks to media. These calls get made under pressure, with incomplete information, usually within hours, and they're almost never rehearsed.

Your board and executive team work through a scenario built from your actual business and obligations. You'll find out whether decision rights are clear, whether anyone knows the notification clock, and whether your insurer's requirements are understood by the people who'll need to meet them.

You get

  • A custom scenario tied to your environment
  • A facilitated session
  • An after-action report with specific findings, named owners and dates
Technical and executive

Combined multi-stage

The handover that makes or breaks a response.

Most organisations rehearse their technical team and their leadership separately, then discover during a real incident that the two don't connect. Information arrives late, garbled or with the wrong emphasis, and executives make decisions on a picture that's already hours old.

This format runs the incident across both groups in sequence. Your responders work the technical problem, then brief leadership under pressure, and leadership makes calls on what they're actually given.

You get

  • A multi-stage scenario spanning both audiences
  • Facilitation across both sessions
  • A combined after-action report examining the escalation itself
Across a year

Annual program

Three exercises across a year. Proof that you're getting better.

A single exercise tells you where you stood on one Tuesday. A program tells you whether you're improving, and that improvement is what your board, insurer and regulator actually want evidence of.

Three exercises across twelve months, increasing in difficulty and varying the threat, with decision timing measured consistently. Each exercise builds on the last, so you're testing the fixes, not repeating the same discoveries.

You get

  • Three custom exercises in formats to suit your audiences
  • Metrics tracked from exercise to exercise
  • A year-end report suitable for your board and insurer
  • Retests built into the program

Roughly 15% less than booking the same three exercises individually.

FAQ

Incident response simulation questions

What is an incident response tabletop exercise?

A tabletop exercise is a facilitated simulation of a cyber incident. Your team works through a realistic scenario and makes the decisions they would make in a real attack, so gaps in plans, roles and communication show up before an actual incident.

What's the difference between a technical and an executive tabletop?

A technical tabletop runs your security and engineering team from first alert through containment, forensics and recovery. An executive tabletop focuses on the decisions only leadership can make: disclosure, regulator notification, whether to pay, customer communication and media.

Who should take part?

IT and security, plus legal, communications, finance and executive leadership, and where it matters your insurer and key third parties. Real incidents test the handoffs between these groups.

Are the scenarios generic?

No. Each scenario is built from your architecture, risk register, past incidents and the threats active in your sector, and it responds to the decisions your team makes.

What do we get afterwards?

An after-action report with specific findings tied to specific moments in the exercise. Every finding has a named owner and a date, so improvement starts the same week.

How often should we run an exercise?

One exercise shows where you stand on the day. The annual program runs three exercises across twelve months, increasing in difficulty and tracking decision times, and costs roughly 15% less than booking the same three individually.

Plan your next exercise

Tell me about your environment and who needs to be in the room, and I'll suggest the right format.