ir-tabletop-exercise
SKILL.md
Tabletop Exercise Script for Incident Response Plan
Produces a ready-to-execute tabletop exercise that tests an organization's IR Plan against realistic cyber threats and regulatory notification deadlines.
Prerequisites
- IR Plan — current incident response plan, escalation hierarchy, severity classification framework
- Regulatory profile — applicable frameworks and notification deadlines
- Org context — industry sector, data holdings (PII, PHI, PCI, IP), crisis roles, prior after-action reports
- Participant list — attendees with titles and IR Plan roles
Quick Start
- Extract key elements from provided materials (deadlines, escalation paths, data types, prior gaps)
- Select threat scenario matched to org risk profile
- Assign participants to functional groups with role cards
- Design 4–5 progressive injects testing IR phases and notification triggers
- Draft facilitation guide with ground rules and timing
- Build debrief agenda and after-action report framework