Program overview
This program trains the people who run a security incident. That includes technical responders who contain and recover, and the managers, legal, and communications staff who make decisions alongside them. Sessions follow your incident response plan and show how well it holds up as an incident develops.
Technical teams work through hands-on exercises in an isolated lab. Leadership and communications groups take part in tabletop sessions based on the same scenario. DeployOpen engineers facilitate both and run a joint debrief.
Topics covered
Triage and scoping
Confirming an incident, setting severity, and identifying the affected systems, accounts, and data.
Containment and eradication
Choosing containment actions, weighing business impact, and removing attacker access while preserving evidence.
Evidence handling
Collecting logs, memory, and disk evidence in an order that preserves it, and recording who handled what.
Recovery
Restoring systems and services in a safe order, confirming they are clean, and deciding when to return to normal operations.
Decisions and communication
Escalating to leadership, briefing executives, working with legal, insurers, and regulators, and preparing staff and customer messages.
Lessons learned
Running a post-incident review and turning it into changes to the plan, runbooks, and tooling.
How the program runs
We review your incident response plan, runbooks, contact lists, and escalation thresholds, and talk to the people named in them. This shows which roles and decisions need the most practice. We agree objectives and participant groups with you.
We write a scenario that fits your environment and the incident types that matter to you. Technical injects are built in the isolated lab with your tools where possible. Tabletop injects are written for each audience, so leadership and communications staff receive the decisions they own.
Participants work through the scenario as it develops. A DeployOpen engineer releases injects, plays outside parties where needed, and logs decisions with timestamps. Technical and tabletop groups can run together or separately.
We review the timeline with all groups, compare decisions with the plan, and record where the plan helped, where it was unclear, and where people worked around it. Findings are grouped by owner.
Formats
| Format | Who it suits | What it covers |
|---|---|---|
| Executive tabletop | Executives, legal, communications, and HR | Decisions on disclosure, extortion demands, business continuity, and external communication, with the scenario briefed in business terms |
| Technical tabletop | Incident response and IT operations leads | Runbooks, escalation paths, and containment choices, discussed without hands-on systems |
| Hands-on lab exercise | Incident responders, SOC analysts, and system administrators | Investigation, containment, and recovery tasks in the isolated lab |
| Combined exercise | Organizations testing the full response chain | One scenario run across technical and leadership groups, with a joint debrief |
| Recurring drills | Teams keeping the plan and contacts current | New or updated scenarios run at an agreed interval, or after changes to staff, systems, or the plan |
Scenario options
Ransomware with data theft
File servers are encrypted and the attacker threatens to publish stolen data. Covers containment, recovery order, legal advice, and extortion decisions.
Deepfake executive or IT impersonation
A cloned voice call or video meeting appears to come from an executive or the IT help desk, asking for a payment, a password reset, or an MFA change. Covers verification steps, reporting, and response once the request is found to be fake.
AI-written phishing campaign
Targeted phishing messages written with AI tools reach many staff at once and several accounts are compromised. Covers scoping, password and session resets, and staff communication.
Compromised AI agent
An AI agent with access to internal tools or data is manipulated through prompt injection and takes actions it should not. Covers revoking its access, reviewing its activity logs, and deciding who owns the response.
Cloud account compromise
Stolen credentials are used to access cloud storage and create new identities. Covers identity response, cloud audit logs, and coordination with the cloud team.
Supplier or software supply chain incident
A supplier reports a breach that may affect your data or a software update you deployed. Covers supplier contact, impact assessment, and notification decisions.
What you receive
Each exercise ends with a debrief, followed by written material your team can act on.
Exercise report
- Scenario timeline with participant decisions
- Where the plan was followed, unclear, or bypassed
- Observations for each participant group
Detection and response findings
- Points where detection or escalation was delayed
- Evidence that was hard to collect or missing
- Tooling and access gaps found during containment
Recommended improvements
- Changes to the incident response plan and runbooks
- Updates to contact lists, roles, and decision authority
- Communication templates to draft or revise
Materials to rerun
- Scenario narrative and inject list
- Facilitator guide with expected decisions
- Lab scenario files for the technical exercises
Common questions
Who should attend?
Incident responders, SOC analysts, and IT operations staff for the technical sessions. Executives, legal counsel, communications, HR, and business owners for the tabletop sessions. We help you choose groups based on who is named in your plan.
Can non-technical staff take part?
Yes. Tabletop sessions are written for leadership and communications staff and focus on the decisions they own. No technical background is needed.
Do exercises use our plan and tools?
Yes. Scenarios are built around your incident response plan, escalation paths, and tools. Hands-on work runs in an isolated lab, so production systems are not affected.
Is it remote or on-site?
Remote or on-site delivery can be agreed, including a mix of on-site and remote groups for combined exercises.
How do you measure progress?
Each exercise has objectives agreed in advance. The debrief records which were met and lists open actions by owner. A later exercise can check whether those actions were completed and how the response changed.
Can it be repeated?
Yes. We hand over the scenario materials so your team can rerun them, and we can write new scenarios for later drills. We sign an NDA on request.
How to prepare
Send us your current incident response plan, escalation matrix, and any runbooks you want tested. Tell us which incident types concern you most and which past incidents or near misses you want to learn from.
Confirm the participant groups and a sponsor who can approve the scenario. Make sure the decision-makers named in the plan can attend, or name the deputies who would act for them.
Alignment with NIST guidance
The program follows the incident response recommendations in NIST SP 800-61 Rev. 3, which places incident response within the six functions of the NIST Cybersecurity Framework 2.0. Findings can be grouped under those functions for reporting to leadership.
Exercise planning, facilitation, and evaluation draw on NIST SP 800-84, which describes test, training, and exercise programs for IT plans.

