Incident Response Tabletop – Is Your Company Prepared for an Emergency?

4. February 2021

Cyber attacks are an everyday reality for companies – therefore it is important to close any entry gates. However, as this alone is not enough in many cases, you should check whether your company is prepared for a cyber attack. A timely response by your employees as a well-coordinated team is crucial for successful protection and for limiting potential damage. Therefore, responsibilities and each individual step must be clearly defined – only then can you act swiftly and correctly.

In order to prepare your company for an emergency, the development of an incident response plan on the best possible reaction and crisis management in the event of a cyber attack is a decisive step. Different standards, such as

  • PCI DSS
  • ISO/IEC 27001:2013
  • NIST (NIST 800-53 and NIST Cybersecurity Framework)
  • IT-Grundschutz of BSI

require a regular review of these measures.

One method that you can use to check the Incident Response Plan in your company in a playful way is the Incident Response Tabletop.

How does an Incident Response Tabletop work?

The Incident Response Tabletop is a theoretical exercise of real-life scenarios where the response plan is tested. It identifies areas your team has effective decision-making processes or where improvements are needed. With this technique, different attack situations are played out theoretically, effectively preventing panic-driven reactions.

An information security expert guides your team through the discussion of each scenario, allowing them to assess readiness to respond or identify potential security gaps in the response process. The question of the correct behaviour of your employees or the filing location of relevant documents are points that need clarification in advance.

The result of this exercise is the understanding of all participants for the identification, analysis and possible solutions of incidents or how they can be prevented in advance in the future. It is thus ensured that each team member knows her or his responsibilities and takes the appropriate action through a hands-on experience in case of an emergency. It also clearly defines your company’s cyber response position and clarifies the collective decision-making processes of the teams involved – thus providing the optimal proof of concept for your emergency management.

Individual scenario

For a target-oriented incident response tabletop exercise, our experts prepare an individual emergency scenario. This is based on their many years of experience in IT security consulting and can be adapted to the guidelines and processes that apply to you. Through a combination of practical planning and customised training, our experts prepare your company that you take the right steps in an emergency.

If you would like to prepare your employees efficiently for an emergency too, our experts will be happy to assist. Contact us.

Also interesting:

usd PCI Best Practice Workshop 2021

usd PCI Best Practice Workshop 2021

For many years, the usd PCI Best Practice Workshop has brought together responsible PCI personnel from companies of all sizes and from all industries to discuss current topics from the world of payment card industry together with PCI experts from usd. The interactive...

3 Reasons for a Cloud Security Audit

3 Reasons for a Cloud Security Audit

Outsourcing applications and data to the cloud brings significant benefits for companies, but at the same time also new challenges for the corresponding IT departments. The technologies and processes of a cloud environment differ from those of local data centers....

usd HeroLab Top 5 Vulnerabilities 2020: SMB 1.0 & SMB Signing

usd HeroLab Top 5 Vulnerabilities 2020: SMB 1.0 & SMB Signing

During penetration tests our security analysts repeatedly uncover gateways in IT systems and applications that pose significant risks to corporate security. They increasingly identify the same vulnerabilities in different IT assets, some of which have been known for...

Categories

Categories