Practical incident response rehearsal resources

Facilitator learning path

An incident response drill is a time-boxed conversation in which a team receives incomplete information, makes specific decisions, and records what must improve before a real incident. It is not a quiz and it is not a test of who remembers the plan. The facilitator's job is to keep the room focused on ownership, evidence, tradeoffs, communications, and the next decision.

1. Choose the smallest useful rehearsal

Match the format to the decision you need to practice. A short exercise with one clear objective is more useful than a long meeting that tries to test every part of the response plan.

2. Define the decision outcome before writing injects

Write one sentence that describes what the room should be able to decide by the end. Examples include: who can isolate a critical system, when leadership receives its first update, who approves an external holding statement, or what evidence is required before recovery begins. This keeps the exercise anchored to a real operating question instead of a dramatic incident story.

Next, name the roles that must contribute. Use role titles rather than individual names so the exercise remains reusable. A small session may need only a facilitator, incident lead, IT lead, communications or operations representative, executive decision-maker, and scribe. Combine roles when that reflects the organization, but state who has each authority during the exercise.

3. Prepare the room without scripting the answer

Give participants the objective, time limit, ground rules, and their roles before the first inject. Tell them that assumptions must be spoken aloud and that the scenario will not provide every fact they want. Do not distribute facilitator notes, preferred choices, or consequences. Those are prompts for keeping the discussion moving, not an answer key.

  • Use fictional names and generic systems; do not enter credentials, personal information, regulated data, or active incident details.
  • Assign one scribe to capture facts, assumptions, decisions, open questions, owners, and due dates.
  • Decide who can call a pause if the discussion reveals a real security concern that belongs outside the exercise.
  • Reserve the final 10 minutes for the AAR rather than letting the scenario consume the entire meeting.

4. Run each inject as a decision loop

Read the inject, allow a brief fact-finding discussion, then ask for a decision. When the room starts describing everything it could investigate, bring it back to what it will do now, who owns that action, and when the decision must be revisited. A useful decision loop produces five things:

  1. Decision: the action, hold, escalation, or communication the team chooses.
  2. Owner: the role accountable for carrying it forward.
  3. Time: the deadline or next update point.
  4. Evidence: the facts needed to confirm, change, or reverse the decision.
  5. Tradeoff: the operational, legal, customer, safety, or recovery cost the team accepts.

If the room stalls, ask one bounded question: “What must happen in the next 15 minutes?”, “Who can authorize that?”, “What would make us change course?”, or “What can we safely tell staff right now?” Avoid rescuing the group with the facilitator notes too early. Productive uncertainty is where unclear authority and missing procedures become visible.

5. Add pressure that tests coordination, not technical trivia

A strong inject changes the decision environment. It can add an executive request, an unavailable system owner, a customer question, an uncertain data-scope finding, or a continuity deadline. It should not require participants to guess a product-specific command or forensic artifact. The goal is to test whether the team can coordinate responsibly when facts are incomplete.

For a ready example, run the Ransomware Communications Pressure Drill. It keeps technical certainty limited while the room must coordinate leadership updates, staff guidance, continuity decisions, and external messaging. For a different pressure pattern, run the BEC decision rehearsal and focus on payment holds, identity evidence, business verification, and executive communication.

To test delivery pressure without tying the room to one vendor, use the Source-Control Platform Outage Tabletop Facilitator Guide. It explains how to run release-freeze, evidence, credential-risk, communication, and staged-restoration decisions, then hands the room into the interactive source-control outage rehearsal.

6. Close with a usable after-action record

End the scenario while there is still time to agree on follow-up. Ask the scribe to read back the major decisions and unresolved questions. Separate observations from actions: “the escalation path was unclear” is an observation; “Operations will publish an after-hours escalation roster by September 15” is an action. Every action should have one accountable owner and a review date.

  • Record what the team decided and the evidence or assumption behind it.
  • Capture where authority, contact information, tooling, or documentation slowed the response.
  • Assign no more than a few high-value actions that can realistically be reviewed at the next meeting.
  • Schedule a short follow-up to verify completion rather than treating the AAR as the finish line.

Response Rehearsal's interactive path produces an AAR summary from the choices made during the session. The packet path provides a blank action tracker and facilitator worksheet for discussions that do not use branching choices. Both are planning aids; the facilitator remains responsible for adapting the exercise to the organization's plans, obligations, and professional advice.

Start with the BEC rehearsal