| name | ir-tabletop-exercise |
| title | Tabletop Exercise Script for Incident Response Plan |
| description | Drafts a tabletop exercise script to stress-test an organization's Incident Response Plan against cybersecurity threats and breach notification obligations (GDPR, CCPA, HIPAA, GLBA, PCI DSS, NERC CIP, DFARS, SEC). Produces scenario injects, participant role assignments, facilitation guides, and after-action report frameworks. Use when creating IR tabletop exercises, cybersecurity drills, breach response simulations, or incident preparedness assessments. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/ir-tabletop-exercise |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | cybersecurity |
| language | en |
| tags | ["checklist","drafting","regulatory"] |
Tabletop Exercise Script for Incident Response Plan
Produces a ready-to-execute tabletop exercise that tests an organization's IR Plan against realistic cyber threats and regulatory notification deadlines.
Prerequisites
- IR Plan — current incident response plan, escalation hierarchy, severity classification framework
- Regulatory profile — applicable frameworks and notification deadlines
- Org context — industry sector, data holdings (PII, PHI, PCI, IP), crisis roles, prior after-action reports
- Participant list — attendees with titles and IR Plan roles
Quick Start
- Extract key elements from provided materials (deadlines, escalation paths, data types, prior gaps)
- Select threat scenario matched to org risk profile
- Assign participants to functional groups with role cards
- Design 4–5 progressive injects testing IR phases and notification triggers
- Draft facilitation guide with ground rules and timing
- Build debrief agenda and after-action report framework
Workflow
Step 1 — Document Research
Extract from provided materials before drafting:
| Element | Source |
|---|
| Notification deadlines | Regulatory docs, state-specific windows |
| Escalation hierarchy | IR Plan org chart, decision authority matrix |
| Regulated data types | Data inventory (PII, PHI, PCI, classified/CUI) |
| Prior gaps | After-action reports, audit findings |
| Contractual obligations | Vendor agreements, cyber insurance, customer DPAs |
Step 2 — Scenario Design
Select a threat scenario matched to org risk profile:
| Scenario | Regulatory Triggers | Key Complexity |
|---|
| Ransomware + exfiltration | Breach notification + OFAC screening | Dual operational/legal pressure |
| Business email compromise | Wire fraud + credential harvesting | Financial + data exposure |
| Supply chain compromise | Multi-party notification, vendor coordination | Shared liability, scope ambiguity |
| Insider threat |