Blog
The goal is not to pass or fail: what recent IR workshops get right
Microsoft DART and a bank tabletop both stressed practicing IR decisions under pressure without grading the room. How to take that stance into your own evidence packet.
On 1 September 2026, Microsoft's Detection and Response Team (DART) published a write-up of its Cybersecurity Incident Response Readiness Workshop: a multi-day, scenario-driven engagement where participants walk realistic incidents, present investigation findings, and take feedback from responders who have handled live cases. Four days later, Egypt's Housing and Development Bank publicly described a tabletop exercise run with Unit 42 to exercise cyber incident response plans and measure how teams handle scenarios under institutional pressure. Different formats, different sponsors, same useful signal: serious programs are treating response practice as something you run with people, not something you leave on paper.
The line that matters most in the DART post is short. The goal is not to pass or fail. It is to see how the organisation makes and executes critical response decisions under pressure, and where preparation today can prevent delay later. That framing matches how credible IR tabletops should be recorded: as evidence of an exercise, never as a compliance verdict or a certification outcome.
What these public exercises are actually stressing
DART's workshop is built around simulated incidents, cross-team discussion, and feedback grounded in real cases. Participants practice detection, containment, and communication decisions while researchers look at whether tools, logs, and telemetry support timely calls across identity, endpoint, cloud, and communications. The bank tabletop is described in plainer institutional language: assess plan efficiency, measure team readiness against complex scenarios, and improve decision-making and response times. Neither write-up claims the exercise proved the organisation "ready" in some absolute sense. Both treat the run as practice that surfaces gaps.
That is the transferable part for teams that will never book a Microsoft workshop or a Unit 42 facilitation. You do not need their brand on the calendar. You do need a scenario that forces decisions, the roles your plan names in the room, a clock, and a record that someone who was not present can still trust.
How to copy the stance without copying the format
Open discussion theater ("we would coordinate with legal") hides the same gaps DART and the bank are trying to expose. Timed injects do not. Write injects that force a named owner to choose: freeze or keep running, notify or wait for more facts, escalate to the executive or keep it on the bridge. Capture plan-says versus room-did without grading the room as a pass or fail. An empty seat is a finding about the roster, not a scheduling inconvenience. The invite-list post covers how to write that down so the packet stays checkable.
Keep the boundary honest. A tabletop or IR workshop proves that named people practised decisions under a concrete scenario and that you kept a durable record of attendance, decisions, and plan gaps. It does not prove that restore works, that EDR quarantines malware, that a red team would be caught, or that any control is "tested" for an auditor. Those need technical tests, DR drills, or adversary simulations. Mixing those categories in the packet is how programs lose credibility the first time someone samples the evidence. Our older post on why a tabletop is not a DR test is still the right boundary language.
What belongs in the packet after a workshop-style run
Whether you run ninety minutes remotely or three days with an external facilitator, the artifact that travels is the same shape:
- Scenario and scope. What was exercised, and what was explicitly out of scope (no live systems touched, no customer spam, no restore attempt).
- Attendance by role. Named people against the roles the IR plan lists, including empty seats.
- Decisions with owners and times. Who chose what under which inject clock.
- Gaps as facts. Plan step missing, tool access assumed but unavailable, notification clock unclear. No score, no green check.
- Follow-ups with owners. What will change before the next run, and who owns each change.
That is the shape of our free evidence template, and it sits with three other formats in the template library. Hand the record to whoever owns assurance. They decide whether it meets their sampling for the period. That separation (evidence versus verdict) is how you stay aligned with the DART line that the goal is not to pass or fail.
Bottom line: recent public IR workshops and bank tabletops are useful because they treat practice as discovery under pressure, not as a grade. Steal that stance. Run a scenario that forces real decisions, record plan-says versus room-did, keep technical proof for technical tests, and never let an exercise packet read like a compliance verdict.