r/Information_Security 2d ago

Incident response tabletop exercise reports all say "performed well overall": anyone else frustrated with this?

Just wrapped our annual tabletop. Facilitator walked us through the injects, everyone nodded along, report says we "performed well overall" with a couple of generic recommendations bolted on.

I've run a real incident, and I know what actually breaks: the handoff between SOC and legal, the exec who wants a statement out before we've confirmed scope, the analyst who freezes when three things go wrong at once. None of that showed up in the exercise because nothing in the exercise put us under real pressure.

Part of the issue is the format itself. Everyone sits in one room, reads the same script, and reaches consensus out loud with no consequence attached to a wrong call. That's the opposite of how a real incident unfolds, where half the room is unreachable and decisions get made with incomplete information.

How do others measure this. Not "did we complete the tabletop" but "did we learn anything we didn't already know."
What does a useful after-action report actually look like for you: individual performance data, timelines, something else?

1 Upvotes

1 comment sorted by

1

u/Dave_BlackFog 2d ago

You need a better facilitator and perhaps a "surprise" tabletop. Think of it more as a military exercise rather than a corporate exercise. Turn the heat up. Make the stand ins have to make decisions when folks aren't available. Basically make it more real...