The Incident Response Plan Was Perfect. Then There Was an Incident.
Room 1 | 8:00am – 8:45am
Most organizations have an incident response plan. It is organized. It is documented. It may even live in a very impressive binder.
Then something actually happens.
Suddenly the information is incomplete, leadership wants an update, someone is asking whether we should call legal, communications wants to know what they can say, and at least one person is quietly wondering whether turning everything off is an acceptable strategy.
This interactive session uses one to two realistic cyber incident scenarios to explore what happens when the plan meets people, pressure, and incomplete information. Participants will make decisions, compare approaches, and then work in small groups to identify what their organizations do well, where gaps may exist, and what they can learn from one another.
The scenarios create the pressure. The real value comes from the conversation afterward. Attendees will leave with practical ideas for improving communication, clarifying roles, strengthening incident response, and running short tabletop exercises of their own, all without requiring a six-hour meeting, seventeen observers, and a catered lunch.
