Breach Response Tabletop

Breach Response Tabletop

Ransomware, a claimed data theft nobody can confirm, and a clock that started before anyone convened. From the privacy seat on the incident bridge, make four decisions every other function on the call wants you to make differently.

What Is Breach Response Tabletop?

Most breach training explains the rules. This exercise makes a learner apply them at hour four with a third of the facts, which is where breach response actually goes wrong. Sitting in the privacy seat on a crisis simulation, they face four decisions, and in every one the correct answer is the one another function on the bridge is arguing against. Security wants the notification clock to start at forensic confirmation rather than at the moment an on-call engineer found the encrypted systems. Infrastructure wants to wipe and rebuild tonight to restore trading, which would also destroy the only evidence of what left the network. The Chief Financial Officer wants to know whether paying the ransom means there is nothing to notify. Legal wants to wait for the completed forensic report so the filing is accurate, without noticing that waiting is not an option the regulation offers. The learner then files the notification, including what is not yet established and when it will follow, decides whether hashed passwords let the organisation avoid telling 2.1 million people, and rejects a public statement that understates a figure already filed privately. The debrief sets the timeline against the road not taken, where the same incident ends late, unknowable in scope, and reported twice.

What You'll Learn in Breach Response Tabletop

Breach Response Tabletop — Training Steps

  1. Introduction

    Today you take the privacy seat on an incident bridge during a full crisis simulation. The hard part of a major breach is not knowing the rules. It is applying them at hour four with a third of the facts, while every other function on the bridge wants a decision that suits their own problem.

  2. The Simulation Opens

    Alice has a message from Nils Ostrand, who runs crisis exercises for Torvell Retail Group. The annual simulation starts in a few minutes, and she is in the privacy seat.

  3. Joining the Bridge

    The simulation opens on the incident bridge, the shared console every function works from during a major incident.

  4. Taking the Seat

    The bridge tracks the elapsed clock, the status of every workstream, and each decision recorded against the person who made it.

  5. Hour Zero

    The first inject lands. Ransomware has encrypted the customer platform overnight, and the attackers have left a note claiming they took a copy of the customer database before encrypting it. Nobody can yet confirm whether anything actually left the network.

  6. When the Clock Started

    The bridge's first decision is procedural and everything else hangs off it. Security argues the clock should start when forensics confirms what was taken, because notifying on a claim in a ransom note is not evidence.

  7. Recording the Start Time

    Alice records the position so the rest of the bridge is working from one clock rather than four.

  8. Hour Three: Rebuild or Preserve

    Infrastructure wants to wipe the affected servers and rebuild from images tonight. Trading is down, the estate is losing revenue by the hour, and rebuilding is the fastest route back. Wiping the servers also destroys the only evidence of what the attacker did and whether anything left the network.

  9. What Preservation Bought

    Imaging adds five hours before restoration can start. The bridge accepts it.

  10. Hour Nineteen: The Demand

    The attackers make contact. They want payment, and in exchange they undertake to delete their copy of the data and provide a decryption key. The Chief Financial Officer points out that paying is cheaper than the alternative, and asks whether deletion by the attacker means there is nothing to notify.