Appearance
IR Tabletop Findings — Template
Purpose: Capture the outcomes of each IR tabletop exercise in a consistent format so findings drive runbook improvements, training, and future tabletops.
How to use: Copy this file to a dated filename (for example ir-tabletop-findings-2026-q2.md), replace the , and commit as part of the post-tabletop PR.
Review cadence: One findings document per tabletop, minimum twice per year. Each finding tracked in SecOps until closed.
Header
- Tabletop date: {{YYYY-MM-DD}}
- Scenario: {{Scenario title — e.g. "Ransomware via credential spray"}}
- Scenario document: {{Link to scenario file — e.g.
compliance/ir-tabletop-scenario-2026.md}} - Facilitator: {{Name — typically Rory}}
- Scribe: {{Name — can be same as facilitator}}
- Duration: {{Actual minutes — if the exercise ran long or short, note why}}
Participants
| Name | Role | Role during exercise | Attended |
|---|---|---|---|
| Rory | Security Officer | Facilitator / Incident Commander | Yes |
| Kevin | T1 DR Admin | DR escalation responder | {{Yes/No}} |
| Greg | T1 DR Admin | DR escalation responder | {{Yes/No}} |
| Adriana | BAA / vendor / risk docs | Breach notification / comms observer | {{Yes/No}} |
| {{additional}} | {{role}} | {{exercise role}} | {{Yes/No}} |
Scenario summary
{{Brief 3-5 sentence summary of what was simulated. Include the attack profile, environment scoped, and key inflection points.}}
Timeline walkthrough
For each inject in the scenario, record what was discussed and decided.
| Inject | Time (exercise) | Stimulus | Response discussed | Decision / owner |
|---|---|---|---|---|
| I1 | {{T+5m}} | {{Stimulus text}} | {{What the team talked through}} | {{Who owns the response in a real event}} |
| I2 | {{T+45m}} | {{...}} | {{...}} | {{...}} |
| I3 | {{T+...}} | {{...}} | {{...}} | {{...}} |
Add rows as needed; keep this aligned to the scenario inject list.
Gaps identified
Every gap becomes a SecOps story. Include priority.
| # | Gap | Impact | Priority | SecOps story | Owner | Target date |
|---|---|---|---|---|---|---|
| 1 | {{Gap description}} | {{What breaks if unaddressed}} | CRITICAL / HIGH / MEDIUM | {{Story ID}} | {{Name}} | {{YYYY-MM-DD}} |
| 2 | {{...}} | {{...}} | {{...}} | {{...}} | {{...}} | {{...}} |
Action items
| # | Action | Owner | Due | Status |
|---|---|---|---|---|
| A1 | {{e.g. Update runbook Ransomware section step 3 to name Kevin as backup IC}} | {{Rory}} | {{YYYY-MM-DD}} | Open / In Progress / Done |
| A2 | {{e.g. Add CA policy audit to weekly Maester run to catch service accounts excluded from MFA}} | {{Rory}} | {{YYYY-MM-DD}} | Open / In Progress / Done |
Runbook updates required
runbooks/incident-response.md— {{section and specific change}}compliance/hipaa-administrative-procedures.md— {{if applicable}}security/threat-model/threat-model-2026.md— {{if the tabletop surfaced a new attack path}}- {{Other documents}}
All updates must be merged within 30 days of this tabletop. Late items escalate to Security Officer.
Control effectiveness evaluation
For each key control referenced during the scenario, rate observed effectiveness.
| Control | Framework reference | Evaluated effectiveness | Notes |
|---|---|---|---|
| Conditional Access MFA enforcement | HIPAA §164.312(d) | {{EFFECTIVE / PARTIAL / GAP}} | {{Observation from exercise}} |
| Cortex XDR behavioral detection | SOC2 CC7.2 | {{...}} | {{...}} |
| Kill-chain execution agent | SOC2 CC7.2 | {{...}} | {{...}} |
| Arctic Wolf MDR | SOC2 CC7.3 | {{...}} | {{...}} |
| Palo Alto DNS Security | HITRUST 09.m | {{...}} | {{...}} |
| RSV restore path | HIPAA §164.308(a)(7) | {{...}} | {{...}} |
| Keeper PAM session review | SOC2 CC6.1 | {{...}} | {{...}} |
Participant sentiment
A short qualitative note from each participant — one sentence is fine. These surface human factors the timeline walkthrough misses.
- {{Rory}}: {{one sentence}}
- {{Kevin}}: {{one sentence}}
- {{Greg}}: {{one sentence}}
- {{Adriana}}: {{one sentence}}
Evidence preserved
- Facilitator notes:
SharePoint → Compliance → Tabletops → NaN → facilitator-notes.md - Participant notes:
SharePoint → Compliance → Tabletops → NaN → participant-notes/ - Any whiteboard photos:
SharePoint → Compliance → Tabletops → NaN → photos/
Next tabletop
- Target quarter: {{Q#}}
- Suggested scenario (draft): {{Brief — informed by gaps above}}
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Template created | Kobe |
| {{YYYY-MM-DD}} | Copied for {{tabletop name}} | {{name}} |