Sherlocked Security – Crisis Management Tabletop Exercises
If You Can’t Practice the Crisis, You Can’t Manage It.
📄 1. Statement of Work (SOW)
Service Name: Crisis Management Tabletop Exercises
Client Type: Financial Institutions, Healthcare Providers, Critical Infrastructure, Cloud-native Enterprises
Service Model: Scenario-Based Simulation + Team Readiness Evaluation + Post-Exercise Review
Compliance Coverage: ISO 22361, NIST SP 800-84, FFIEC, PCI-DSS, HIPAA, SOC 2
Exercise Types:
- Cybersecurity Incident Tabletop (e.g., Ransomware, DDoS)
- Natural Disaster / Data Center Outage Response
- Insider Threat / Data Leakage Scenario
- Public Relations & Legal Risk Simulation
- Third-Party/Supply Chain Disruption Drill
- Multi-Department Coordination Testing
🧠 2. Our Approach (with Visual)
🧠 Simulate. Assess. Adapt. Improve.
[Scenario Design] → [Team Role Assignment] → [Live Tabletop Facilitation] → [Real-Time Decision Logging] → [Debrief & Gap Discovery] → [Improvement Plan] → [Re-test]
🧪 3. Methodology (with Visual)
[Select Crisis Scenarios] → [Design Injects & Timeline] → [Facilitate Live Tabletop] → [Observe & Record Decisions] → [Conduct After-Action Review] → [Recommend Enhancements]
Phases:
- 🎯 Scenario Creation
- 🧩 Simulation Execution
- 📈 Post-Exercise Evaluation
📦 4. Deliverables to the Client
- 📜 Custom Crisis Scenario Playbooks
- 🎥 Tabletop Facilitation Session (Live or Remote)
- 🧠 Real-Time Role Performance Observations
- 🔍 Decision Timeline Documentation
- ⚠️ Identified Gaps & Weaknesses Report
- 🛠️ Actionable Recommendations & Remediation Steps
- 📁 Compliance Mapping to ISO/NIST/FFIEC
- 🏆 Crisis Tabletop Participation Certificate (optional)
🤝 5. What We Need from You (Client Requirements)
- ✅ List of key stakeholders and participants
- ✅ Organizational chart and emergency roles
- ✅ Access to existing IR/BCP/DR documents
- ✅ Preferred communication tools (Zoom, MS Teams, etc.)
- ✅ Availability for 2–3 hour workshop
- ✅ Approval of tailored crisis scenarios
🧰 6. Tools & Technology Stack
- 🎯 Scenario Management: Lucidchart, Miro, PowerPoint
- 🎥 Facilitation: Zoom, MS Teams, OBS
- 📝 Logging & Review: JIRA, Notion, Excel
- 📁 Documentation: Confluence, Google Workspace
- 🧠 Learning Management: TalentLMS, Docebo (for follow-up)
- 🔄 Feedback Loop: SurveyMonkey, Typeform
🚀 7. Engagement Lifecycle (Lead → Closure)
1. Scope Review → 2. Scenario Design → 3. Tabletop Planning → 4. Exercise Facilitation → 5. Debrief Session → 6. Recommendations → 7. Final Report & Retest (Optional)
🌟 8. Why Sherlocked Security? (Our USP)
Feature | Sherlocked Advantage |
---|---|
🎭 Realistic Scenario Design | Custom-tailored to sector and threat model |
🕹️ Live Facilitation | Experienced moderators for in-depth engagement |
📈 Decision Tracking Tools | Logs team responses, decisions, and time-to-react |
📚 Post-Mortem Frameworks | ISO/NIST-aligned after-action reporting |
🔁 Optional Retest Rounds | Validate improvements in follow-up session |
📚 9. Real-World Case Studies
🔐 Ransomware Tabletop – Tech Enterprise
Scenario: HR server hit with ransomware, payroll halted
Exercise: Simulated ransom email, C-level escalation, PR fallout
Outcome: Improved comms flow and RTO decision-making
Fixes: Added legal/PR rep to IR team, revised comms templates
🏥 Healthcare – Data Breach & Regulator Notice
Scenario: PHI leak discovered with public exposure risk
Exercise: Legal, CISO, CMO involved in crisis resolution
Impact: Timelines optimized for breach notification
Fixes: Pre-drafted notice templates, updated breach escalation path
🛡️ 10. SOP – Standard Operating Procedure
- Identify key teams and crisis types
- Design customized tabletop scenarios
- Schedule and prepare logistics
- Facilitate tabletop session (in-person or virtual)
- Observe and document real-time responses
- Conduct after-action review
- Deliver improvement plan
- Schedule optional retest (if required)
📋 11. Sample Tabletop Exercise Checklist (Preview)
- Confirm critical crisis scenarios to simulate.
- Define roles and assign team responsibilities.
- Create timeline-based injects with decision points.
- Prepare tabletop facilitator and observers.
- Conduct session with real-time logging.
- Capture decision speed, clarity, and effectiveness.
- Record communications and escalation steps.
- Debrief with team and collect feedback.
- Recommend policy/process improvements.
- Deliver final report and track corrective actions.
📬 Contact Us or 📅 Book a Consultation