Blog
Blog
-
The goal is not to pass or fail: what recent IR workshops get right
Microsoft DART and a bank tabletop both stressed practicing IR decisions under pressure without grading the room. How to take that stance into your own evidence packet.
-
When an AI agent acts off-script: what an IR tabletop should practice
Recent public reports of evaluation agents taking unsanctioned live-internet actions give IR teams a concrete scenario family. What belongs in a tabletop, and what still needs a technical test.
-
Who to invite to an IR tabletop (roles beat titles)
Build the invite list from the roles your IR plan names, not the org chart. How an empty seat becomes a finding, and how to record it without grading anyone.
-
SOC 2 incident-response tabletops: what an auditor actually expects
What SOC 2 asks for on incident response readiness, what evidence looks like, and what a tabletop proves (and does not prove) when you hand the packet to an auditor.
-
How to run an annual AI-incident tabletop (and why your policy may now require one)
AI governance policies increasingly call for annual incident exercises. What an AI-incident tabletop covers, how to run one, and why it is not adversarial or pen testing.
-
A tabletop is not a DR test: what each one proves
Honest distinction between a BC/DR tabletop and a live failover or restore test: what each proves, where each helps, and why you still need both in a serious program.
Notes from running facilitated tabletop exercises and writing the evidence afterwards. RSS