­
Strengthening Cyber Resilience: Best Practices for Crisis Drills and Tabletop Exercises By Dan Lohrmann and Bikash Barai - All Articles - CISO Platform

Strengthening%20Cyber%20Resilience%20Best%20Practices%20for%20Crisis%20Drills%20and%20Tabletop%20Exercises.png?profile=RESIZE_710x

 

In the ever-evolving landscape of cybersecurity, enterprises face the constant threat of cyberattacks. To fortify their defenses and enhance their preparedness, organizations must conduct regular tabletop exercises for cyber crisis management. Drawing from extensive experience in both government and private sectors, we'll outline a structured framework for conducting these exercises effectively.

 

.  

 

Here is the verbatim discussion:

How long should it be? What should be the structure? What are some best practices? What are some do's and don'ts? So building a kind of high level structured framework for conducting cyber crisis drill for enterprise, how would you approach that? Great question. Yeah. Solve been a part of many of those, both within government and nowin the private sector, working with us, with infragard, with federal agencies, with us state agencies and others. So, first of all, obviously,  there are different types of tabletops. i'm going to talk about one that really, for example, in Michigan, would be a whole of government approach, which really needs to involve the top executive.That's very interesting, Dan. So, Dan, let's consider a scenario like this that suppose we have to do a tabletop exercise for an enterprise. Can you give a kind of playbook for conducting tabletop crisis,cyber crisis drill? So you can start with, like, who are the folks who should be in the room? How long should it be? What should be the structure? What are some best practices? What are some do's and don'ts? So building a kind of high level structured framework for conducting cyber crisis drill for enterprise, how would you approach that?

 

Highlights:

Key Participants: Engage stakeholders from various departments, including IT, security, legal, communications, and senior management. This ensures a holistic approach and fosters collaboration across different functions.

Duration and Structure: Tailor the exercise duration to the organization's needs and the complexity of the scenario. Typically, tabletop exercises range from a few hours to a full day. Structure the exercise with a clear agenda, including scenario introduction, discussion, and debriefing.

Best Practices:

  • Realistic Scenarios: Craft scenarios that mimic potential real-world cyber threats faced by the organization.
  • Active Participation: Encourage active engagement from participants through role-playing and scenario-based discussions.
  • Learning and Improvement: Emphasize the learning aspect of the exercise, focusing on identifying strengths, weaknesses, and areas for improvement in the incident response process.

Do's and Don'ts:

  • Do: Foster a supportive environment that encourages open communication and collaboration.
  • Don't: Overwhelm participants with overly complex scenarios or unrealistic expectations.
  • Do: Conduct a thorough debriefing session post-exercise to capture lessons learned and actionable insights.
  • Don't: Neglect to update response plans based on feedback and lessons learned from tabletop exercises.

 

Tabletop exercises are invaluable tools for enhancing an organization's cyber resilience. By bringing together key stakeholders, simulating realistic scenarios, and emphasizing learning and improvement, enterprises can strengthen their preparedness to effectively respond to cyber crises. Adopting a structured framework that incorporates best practices ensures that tabletop exercises yield actionable insights and contribute to ongoing efforts to mitigate cyber risks.

 
 
 

 

Speakers:

Dan Lohrmann is an esteemed cybersecurity expert and Field Chief Information Security Officer (CISO) for Presidio, celebrated for his impactful career across both public and private sectors. With beginnings at the National Security Agency and roles at Lockheed Martin and ManTech, he has been recognized as CSO of the Year among other accolades. Dan is also a prolific author and speaker, sharing insights on cybersecurity and technology modernization through his award-winning blog and publications.


https://twitter.com/govcso

https://www.linkedin.com/in/danlohrmann/


Bikash Barai
is credited for several innovations in the domain of Network Security and Anti-Spam Technologies and has multiple patents in USPTO. Fortune recognized Bikash among India’s Top 40 Business Leaders under the age of 40 (Fortune 40-under-40).Bikash is also an active speaker and has spoken at various forums like TiE, RSA Conference USA, TEDx etc.

Earlier he founded iViZ an IDG Ventures-backed company that was later acquired by Cigital and now Synopsys. iViZ was the first company in the world to take Ethical Hacking (or Penetration Testing) to the cloud.

 

https://twitter.com/bikashbarai1

https://www.linkedin.com/in/bikashbarai/ 

 

 
 
 
 
 
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

City Round Table Meetup - Mumbai, Bangalore, Delhi, Chennai, Pune, Kolkata

  • Description:
    CISO Playbook Round Table Overview : 
    Our round tables are designed to bring together top CISOs and IT leaders in intimate, focused sessions. These closed-door discussions will provide a platform to explore key security challenges and solutions. These sessions aim to create a focused, closed-door environment where 08-10 CISOs will dive deeply into the practicalities of implementing specific technologies.
    • Technology Implementation: From…
  • Created by: Biswajit Banerjee
  • Tags: ciso, playbook, round table

Round Table Dubai 2025 | GISEC

  • Description:
    CISO Playbook Round Table Overview : 

    Our round tables are designed to bring together top CISOs and IT leaders in intimate, focused sessions. These closed-door discussions will provide a platform to explore key security challenges and solutions. These sessions aim to create a focused, closed-door environment where 08-10 CISOs will dive deeply into the practicalities of implementing specific technologies.
    • Technology…
  • Created by: Biswajit Banerjee

Fireside Chat With Dan Bowden (Global Business CISO, Marsh McLennan (Marsh, Guy Carpenter, Mercer, Oliver Wyman))

  • Description:

    We’re excited to bring you an insightful fireside chat on "Navigating the Cyber Insurance Landscape: Key Considerations for CISOs" with Dan Bowden (Global Business CISO, Marsh McLennan) and Erik Laird (Vice President - North America, FireCompass). In this fireside chat, we'll decode the complexities of cyber insurance from a CISO’s lens and uncover how to make smarter, security-aligned decisions when it comes to policy design, claims, and ROI.

    As cyberattacks grow in…

  • Created by: Biswajit Banerjee
  • Tags: ciso, cyber insurance, dan bowden

CISO Platform: CISO 100 Awards & Future CISO Awards @ Atlanta

  • Description:

    Nominate for the CISOPlatform CISO 100 Awards & Future CISO Awards - Recognizing Cybersecurity Leaders. Recommend someone you know deserving of this prestigious accolade....Nominate your colleague, mentor, someone you admire or yourself !

    CISO Platform is collaborating as a community partner with EC-Council’s Global CISO Forum, supporting initiatives such as the CISO Platform…

  • Created by: Biswajit Banerjee