Skip to content
FioSec Consulting

Incident Readiness · Case study

The tabletop exercise that rewrote the incident response plan

An organization’s incident response plan looked complete until the first tabletop exercise asked who could actually make decisions. The walkthrough exposed the gaps, and the plan was rewritten around named people and real authority.

The situation

The organization

An organization with an incident response plan on paper that had never been exercised. The plan read well; nobody had ever pressure-tested it against a realistic scenario.

What prompted it

On paper, the plan was done. Then FioSec walked the team through a realistic incident scenario and the questions started: who has the authority to take production systems offline in the middle of the night? Who calls the insurer, and when? Who talks to customers, and who decides what to say? The plan named documents and systems; it did not name people. The exercise everyone expected to be a formality became the moment the organization learned the plan would not survive a real incident.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. A realistic scenario, not a checkbox

    We walked the team through an unfolding incident stage by stage: first signs, escalation, containment choices, and the outside world arriving in the form of insurers, lawyers, and customers.

  2. Finding the gaps in a meeting room

    Every stall in the room became a finding: decisions with no named owner, contacts nobody had, steps that assumed systems would be available when they would not be. Finding these in an afternoon exercise is cheap; finding them mid-breach is not.

  3. Rewriting the plan

    The plan was rebuilt around named roles and decision authority: who declares an incident, who can authorize containment, who speaks for the organization, and who the backups are when someone is unreachable.

  4. Testing it again

    The rewritten plan went back through the exercise, so the fixes were proven rather than assumed, and the plan stays current as people and systems change.

The outcome

The incident response plan now names people and decision authority, not just documents and systems.

Gaps that would have surfaced mid-incident were found and closed in a meeting room instead.

Leadership got a realistic feel for the first hours of an incident before ever having to live them.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.