Incident preparedness and tabletop exercise
An incident plan that works when it matters, and an exercise that shows it does. We define roles, decision paths and reporting routines, then test them in a tabletop exercise with your management team and your IT function.
Who it is for and when
Suits organisations that face requirements on incident handling and reporting, or that have realised the plan exists in a document but not in the heads of the people who would use it.
- You are affected by the Swedish Cybersecurity Act, DORA or the GDPR and have reporting deadlines to meet.
- You have an incident plan but it has never been tested with the people who would actually be called.
- It is unclear who decides to shut down a system, contact a customer or notify an authority.
- A customer or auditor has asked how you exercise your incident preparedness.
What we do
- Current state and requirements. We review existing routines, which reporting requirements apply to you and which systems and services are the most critical.
- Plan, roles and decision paths. We write or update the incident plan: classification, escalation, roles, mandates, communication and reporting with the deadlines that apply.
- A scenario for the exercise. We build a realistic scenario from your actual risks, for example ransomware in a business-critical service or a breach at a supplier.
- The tabletop exercise. Half a day to a day where management, IT and communications work through the scenario step by step and make the decisions for real, without touching a single system.
- Action list and report. We document what worked, where it stalled and which measures are needed, with an owner and a date.
You get
- An incident plan with classification, roles, mandates and escalation paths
- A reporting routine with the deadlines that apply to you
- An exercise scenario tailored to your risks
- A completed tabletop exercise with documented attendance
- An exercise report with a prioritised action list
Scope and price
A defined engagement over a few days: current state, plan and one exercise. If you want to exercise regularly we set it up as an annual session with a new scenario each time.
The price varies from engagement to engagement and depends on how many people take part, how much of the plan already exists and how complex the environment is. You get a clear proposal after the first conversation.
How it works
- A first conversation. We listen to your situation and explain how we usually set the work up. You get our assessment straight away, at no cost.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work alongside your organisation, report as we go and hand over so that you can manage the result yourselves.
Frequently asked questions
What is a tabletop exercise?
A structured walk-through of a scenario around a table, where the participants make the decisions they would make for real. No systems are affected, but the gaps in the plan show up immediately.
Which reporting deadlines apply to us?
That depends on the regulation. The Swedish Cybersecurity Act and NIS2 require an early warning within 24 hours and an incident notification within 72 hours. The GDPR gives 72 hours for personal data breaches. We map which ones apply to you and build them into the routine.
Can you take over the incident handling itself?
We lead the work during an active incident as part of our engagements, and support the investigation and remediation afterwards. This service is about the preparedness beforehand.
How often should we exercise?
At least once a year, and after significant changes to the environment or the organisation. Many choose an annual session with a new scenario.
Would you like to know whether your incident plan holds when it matters?
Contact us