Appearance
Incident Response Tabletop — Coordination with Q3 DR Test (July 2026)
Purpose
SOC2 CC7.4 and HIPAA 164.308(a)(6) both expect an exercised incident response plan. An IR tabletop run in the same week as the Q3 disaster recovery test gives us one block of calendar time that produces evidence for both controls, and lets the team work through the realistic case where a DR event is triggered by a security incident (ransomware, prolonged outage from a cyber cause, data integrity compromise).
Q2 tabletop and DR test were not executed (June 2026 window missed). This is now rescheduled to Q3 — must complete before September SOC2 audit fieldwork.
Related story: COMP-032. Related: runbooks/incident-response.md, compliance/q2-dr-test-plan-2026.md (Q3 execution target), and compliance/ir-retainer-evaluation.md.
Timing
- Target window: Week of July 14, 2026 (proposed), remote — tabletop Monday July 14, DR test Saturday July 19. Rory to confirm with Kevin and Greg.
- Preferred sequence: Tabletop first (Monday), DR test later in the same week (Saturday). Running the tabletop first gives the team fresh context; the DR test becomes a live validation of decisions made in the tabletop
- Must complete by: August 31, 2026 — evidence needs to be filed before September audit
- Duration: 2 hours for the tabletop; 4–6 hours for the DR test (per the DR test plan)
- Format: Remote via Teams. Optional in-person for Rory and Adriana if both are in the same office that week
Invitees
Required:
- Rory — facilitator and primary responder
- Kevin — T1 Domain Admin, recovery operations
- Greg — T1 Domain Admin, recovery operations
Recommended:
- Adriana — compliance, BAA / vendor / breach notification decisions. Strongly encourage her to attend given the HIPAA breach-notification scenario in the agenda below; her decisions on 60-day notification timing are material
Optional:
- Arctic Wolf concierge / TAM — as observer. Tabletop is a good opportunity to confirm the escalation path and response SLA in action
- External counsel (if retained by June) — observer for the breach-notification decision segment
Keep the invitee count tight. Fewer attendees = more honest conversation.
Scenario
Pick one scenario that exercises the decisions we care about. Do not try to exercise everything in one session.
Primary scenario: Ransomware via compromised MSP credentials
Arctic Wolf raises a HIGH alert at 04:12 local time on a Monday. A domain administrator account has successfully authenticated from a country that is not in our expected geography. Minutes later, Cortex XDR flags suspicious encryption activity on two file servers. The SecOps platform shows the account is not cirius-breakglass — but it is an MSP-owned account we had delegated temporary rights to for a project last month. Veeam replication to AWS Backup is still running. Attackers have not yet touched the offsite immutable copy.
This scenario exercises:
- Detection (MDR + EDR + SecOps correlation)
- Containment decisions (lock accounts, isolate hosts, stop replication)
- DR decisions (fail over which workloads, when)
- Communication (who calls whom on the break-glass Signal channel)
- HIPAA breach notification decision path (is there PHI exposure? 60-day clock?)
- External support engagement (Arctic Wolf IR, retainer firm, counsel)
Alternate scenarios (pick only if team has done the primary one before)
- Business email compromise — CEO/CFO-targeted wire fraud attempt with compromised M365 account
- Insider threat — a departing privileged user downloads patient data bulk
- Third-party SaaS breach — a BAA vendor notifies us that their systems were compromised and our patient data may be involved
Agenda (2 hours)
| Time | Segment | Lead |
|---|---|---|
| 0:00–0:05 | Framing and ground rules | Rory |
| 0:05–0:15 | Scenario injection — initial alerts from Arctic Wolf | Rory |
| 0:15–0:35 | Detection and triage — what do we do in the first 15 minutes? | Kevin / Greg |
| 0:35–0:55 | Containment decisions — account lock, host isolation, replication | Rory + team |
| 0:55–1:15 | DR decision point — do we fail over? Which workloads? When? | Kevin / Greg |
| 1:15–1:35 | HIPAA breach notification decision path | Adriana / Rory |
| 1:35–1:50 | External engagement — MDR, retainer, counsel | Rory |
| 1:50–2:00 | Lessons learned, remediation list, evidence capture | Rory |
Injections: Have 2–3 pre-scripted injections ready — e.g. "the primary Veeam server is unreachable", "a second privileged account is flagged", "Adriana is on PTO that day — what changes?". Inject them at 0:30, 0:55, and 1:20.
Roles
- Facilitator (Rory): Runs the scenario, injects curveballs, keeps time
- Scribe (appointed at start): Captures decisions, gaps, and action items in the running document — this is the primary evidence artifact
- Observer(s): Arctic Wolf concierge, counsel — do not participate in decisions; comment only when invited at the end
Evidence and Documentation for SOC2 / HIPAA
Capture and file each of the following in SharePoint → Compliance → IR Tabletops → 2026-Q3:
- Attendance log — names, roles, sign-in times
- Scenario document — the scenario injected, verbatim, including inject timings
- Decision log — every decision made, by whom, with the reasoning
- Gap list — everywhere the team said "we don't have that" or "we don't know what we'd do" — this is the most valuable output
- Action items — each gap becomes a SecOps story (likely in the DR, COMP, or IRRET projects)
- Evidence photos / screenshots — at minimum a screenshot of the Teams attendance roster and the shared decision log
- Signed summary memo — one page, signed by Rory, stating date, scope, participants, PASS/FAIL, and where full evidence lives
The summary memo is what auditors look at first. Keep it short.
Mapping to DR Test Week
Same-week execution gives us:
| Day | Activity | Evidence Produced |
|---|---|---|
| Monday | IR tabletop (this doc) | Decision log + gap list |
| Tuesday/Wednesday | DR test (per DR test checklist) | RTO table + restore evidence |
| Thursday | Gap-list triage meeting (30 min) | SecOps stories filed |
| Friday | Summary memo sign-off | SOC2 evidence binder updated |
This sequence covers SOC2 CC7.4 (IR plan tested) and CC7.5 (recovery tested) plus HIPAA 164.308(a)(6), 164.308(a)(7)(ii)(D) in a single week with a single evidence package.
Preparation Checklist
Run this checklist 4 weeks before the target date.
- [ ] Confirm DR test week — proposed Saturday July 19; tabletop the Monday before (July 14)
- [ ] Hold calendar for Rory, Kevin, Greg, Adriana
- [ ] Invite Arctic Wolf TAM as observer
- [ ] Choose primary scenario and draft injections (use the primary scenario above unless the team has done ransomware before)
- [ ] Create the SharePoint folder for this quarter's tabletop
- [ ] Pre-populate the decision-log document with headers ready for the scribe
- [ ] File a SecOps story for the tabletop itself under COMP project, so the tabletop shows up in the quarterly review as completed evidence
SOC2 / HIPAA Mapping
- SOC2 CC7.4 — incident response plan tested
- SOC2 CC7.5 — recovery plan tested (covered by paired DR test)
- HIPAA 164.308(a)(6) — security incident procedures exercised
- HIPAA 164.308(a)(7)(ii)(D) — testing and revision of contingency plan
- HIPAA 164.308(a)(1)(ii)(D) — information system activity review