Training Programme

Incident Response Exercises

A half-day tabletop exercise testing leadership and IT's actual incident response against a realistic, scenario-led simulation.

Incident Response Exercises

An incident response plan that has never been rehearsed is a document, not a capability.


An incident response plan that has never been rehearsed is a document, not a capability. Most organisations discover the actual gaps in their plan, unclear ownership, slow escalation, inconsistent external messaging, only during a genuine incident, at the worst possible time to discover them. This tabletop exercise walks leadership and IT through a realistic incident scenario in real time, testing who decides what, who is contacted when, and what gets said externally and when, surfacing the gaps in your actual plan before a real incident does.

What's Covered

What this programme covers.


A realistic, scenario-led simulation built around a plausible incident for your organisation

Who decides what, and how quickly, when the scenario develops in real time

Internal and external communication: what gets said, to whom, and when

The gap between your documented plan and what actually happens when it is tested

A structured debrief identifying specific, actionable gaps to close

Outcomes

What attendees leave able to do.


Delivery

How it's run.


Delivered as a half-day tabletop exercise, in person or remotely, facilitated by a named Greyline analyst who designs the scenario specifically for your organisation's sector, size and known risk profile. Leadership and IT are walked through the scenario in real time, with the facilitator introducing developments as the exercise progresses rather than presenting a fixed script.

Frequently Asked

Questions we're asked most.


Who should take part in this exercise?

Leadership and IT, at minimum, since the exercise is built specifically to test the decision-making handoff between the two. Legal, communications and HR are often included where their role in a real incident would be significant.

Is the scenario the same for every organisation?

No. The scenario is built specifically around a plausible incident for your sector, size and known risk profile, discussed and confirmed before the exercise runs.

What happens if the exercise reveals serious gaps in our plan?

That is the point of running it before a real incident does the same thing with real consequences. The debrief identifies gaps clearly and specifically, so they can be closed with your own team or with our support.

How is this different from a written incident response plan review?

A plan review checks what is written down. This exercise tests what actually happens when people have to make decisions in real time, which is where most plans genuinely fail.

Can this connect to Greyline's Incident Response Intelligence service?

Yes. Where the exercise reveals a need for stronger threat intelligence support during a live incident, that connects directly to our Cyber & Digital Risk Intelligence capability.

Bring This to Your Organisation

Enquire and scope this programme.

Every programme is scoped to the organisation, its sector, incident history and regulatory drivers, before delivery. Submit an inquiry and we'll arrange a scoping call.