Filed under: the hour of preparation that saves you the worst day of your career.
Why a tabletop, and why now
How to run it well
- Commit before you reveal. At each decision, everyone picks their answer out loud, or writes it down, before anyone reads the recommended call. The value is in the commitment, not the hindsight.
- Argue the splits. When the room disagrees, stop and dig in. That disagreement is showing you an unwritten assumption or an unclear line of authority. Note it down. That’s an action item, not a distraction.
- No blame. The point is to find gaps in the plan and the decision rights, not to catch out the junior analyst. People have to feel safe saying the wrong thing in the room, so they make the right call in the incident.
- Capture the actions. Every “wait, who actually has the authority to do that?” and “do we even have that logged?” is a finding. The output of a good tabletop is a short list of things to fix before the real one.
Scenario one: The Inside Job
Scenario two: Secret Squirrel
They teach the same lesson, which is the point
Run both and you’ll notice something. One incident had no attacker and one had a frighteningly capable one, and the post-mortems land in exactly the same place. The insider mess was ungoverned permissions. The AI-enabled attack got in through open egress and standing credentials. Neither is a new, exotic, AI-shaped problem. They are the fundamentals we all know and quietly defer, exposed by a faster clock and a more patient adversary.
That’s the whole reason this is worth an hour of your week. The tools changed. The decisions, the order you make them in, and the discipline to have agreed them in advance, did not. AI didn’t rewrite the incident response playbook. It just raised the stakes on whether you actually have one, and whether anyone in the building has ever practised it.
So go and run the fire drill. Pull up the full exercise, with all sixteen injects and the calls, gather whoever would actually be on the bridge, and give them the first inject. If any of the answers surprise you, that’s not a bad day. That’s the cheapest lesson you’ll ever get.
Want a hand turning this into a proper facilitated session tuned to your environment, or a version built around your own systems and obligations? That’s a genuinely good use of an afternoon and I’m up for it. Say hello.
One caveat worth stating plainly: this is a rehearsal, not legal advice. The UK regulatory detail is accurate as far as it goes, but confirm your real obligations with your DPO.
Jay Ralph is a Technical Principal Consultant at Bridewell, with 20 years in IT and security and most of the last decade leading cloud transformation. He also serves as a Special Inspector with Avon and Somerset Police. He writes at modern-managed.com about the practical end of AI, security and Microsoft cloud, with the occasional bad joke.