Incident response training

Incident response training for technical responders, leadership, and communications staff. It combines tabletop sessions and hands-on lab exercises built around your plan and tools.

On this page

Program overview

This program trains the people who run a security incident. That includes technical responders who contain and recover, and the managers, legal, and communications staff who make decisions alongside them. Sessions follow your incident response plan and show how well it holds up as an incident develops.

Technical teams work through hands-on exercises in an isolated lab. Leadership and communications groups take part in tabletop sessions based on the same scenario. DeployOpen engineers facilitate both and run a joint debrief.

Topics covered

Triage and scoping

Confirming an incident, setting severity, and identifying the affected systems, accounts, and data.

Containment and eradication

Choosing containment actions, weighing business impact, and removing attacker access while preserving evidence.

Evidence handling

Collecting logs, memory, and disk evidence in an order that preserves it, and recording who handled what.

Recovery

Restoring systems and services in a safe order, confirming they are clean, and deciding when to return to normal operations.

Decisions and communication

Escalating to leadership, briefing executives, working with legal, insurers, and regulators, and preparing staff and customer messages.

Lessons learned

Running a post-incident review and turning it into changes to the plan, runbooks, and tooling.

How the program runs

We review your incident response plan, runbooks, contact lists, and escalation thresholds, and talk to the people named in them. This shows which roles and decisions need the most practice. We agree objectives and participant groups with you.

Formats

FormatWho it suitsWhat it covers
Executive tabletopExecutives, legal, communications, and HRDecisions on disclosure, extortion demands, business continuity, and external communication, with the scenario briefed in business terms
Technical tabletopIncident response and IT operations leadsRunbooks, escalation paths, and containment choices, discussed without hands-on systems
Hands-on lab exerciseIncident responders, SOC analysts, and system administratorsInvestigation, containment, and recovery tasks in the isolated lab
Combined exerciseOrganizations testing the full response chainOne scenario run across technical and leadership groups, with a joint debrief
Recurring drillsTeams keeping the plan and contacts currentNew or updated scenarios run at an agreed interval, or after changes to staff, systems, or the plan

Scenario options

Ransomware with data theft

File servers are encrypted and the attacker threatens to publish stolen data. Covers containment, recovery order, legal advice, and extortion decisions.

Deepfake executive or IT impersonation

A cloned voice call or video meeting appears to come from an executive or the IT help desk, asking for a payment, a password reset, or an MFA change. Covers verification steps, reporting, and response once the request is found to be fake.

AI-written phishing campaign

Targeted phishing messages written with AI tools reach many staff at once and several accounts are compromised. Covers scoping, password and session resets, and staff communication.

Compromised AI agent

An AI agent with access to internal tools or data is manipulated through prompt injection and takes actions it should not. Covers revoking its access, reviewing its activity logs, and deciding who owns the response.

Cloud account compromise

Stolen credentials are used to access cloud storage and create new identities. Covers identity response, cloud audit logs, and coordination with the cloud team.

Supplier or software supply chain incident

A supplier reports a breach that may affect your data or a software update you deployed. Covers supplier contact, impact assessment, and notification decisions.

What you receive

Each exercise ends with a debrief, followed by written material your team can act on.

Exercise report

  • Scenario timeline with participant decisions
  • Where the plan was followed, unclear, or bypassed
  • Observations for each participant group

Detection and response findings

  • Points where detection or escalation was delayed
  • Evidence that was hard to collect or missing
  • Tooling and access gaps found during containment

Recommended improvements

  • Changes to the incident response plan and runbooks
  • Updates to contact lists, roles, and decision authority
  • Communication templates to draft or revise

Materials to rerun

  • Scenario narrative and inject list
  • Facilitator guide with expected decisions
  • Lab scenario files for the technical exercises

Common questions

Who should attend?

Incident responders, SOC analysts, and IT operations staff for the technical sessions. Executives, legal counsel, communications, HR, and business owners for the tabletop sessions. We help you choose groups based on who is named in your plan.

Can non-technical staff take part?

Yes. Tabletop sessions are written for leadership and communications staff and focus on the decisions they own. No technical background is needed.

Do exercises use our plan and tools?

Yes. Scenarios are built around your incident response plan, escalation paths, and tools. Hands-on work runs in an isolated lab, so production systems are not affected.

Is it remote or on-site?

Remote or on-site delivery can be agreed, including a mix of on-site and remote groups for combined exercises.

How do you measure progress?

Each exercise has objectives agreed in advance. The debrief records which were met and lists open actions by owner. A later exercise can check whether those actions were completed and how the response changed.

Can it be repeated?

Yes. We hand over the scenario materials so your team can rerun them, and we can write new scenarios for later drills. We sign an NDA on request.

How to prepare

Send us your current incident response plan, escalation matrix, and any runbooks you want tested. Tell us which incident types concern you most and which past incidents or near misses you want to learn from.

Confirm the participant groups and a sponsor who can approve the scenario. Make sure the decision-makers named in the plan can attend, or name the deputies who would act for them.

Alignment with NIST guidance

The program follows the incident response recommendations in NIST SP 800-61 Rev. 3, which places incident response within the six functions of the NIST Cybersecurity Framework 2.0. Findings can be grouped under those functions for reporting to leadership.

Exercise planning, facilitation, and evaluation draw on NIST SP 800-84, which describes test, training, and exercise programs for IT plans.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.