CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

Incident response and tabletop exercises

Would your team know what to do in the first hour of a cyber incident?

A tabletop exercise tells you. We build or update your incident response plan against NIST SP 800-61, run tabletop exercises with leadership and technical staff, and fix what the exercise exposes, including the DFARS 252.204-7012 duty to report cyber incidents to DoD within 72 hours.

Incident response planning and tabletop exercises for defense contractors, including DFARS 252.204-7012 reporting readiness.

Book a 30 minute call

What does the engagement include?

  • An incident response plan and playbooks
  • DFARS 252.204-7012 reporting procedures
  • Tabletop exercise design and facilitation
  • An after action report with fixes
  • Forensic readiness and chain of custody guidance

Who is this for?

Contractors with an incident response plan that has never been tested, or no plan at all, and leadership teams that want to rehearse decisions before they have to make them.

What do you get?

An updated incident response planTested playbooksAn after action reportA DFARS 7012 reporting checklist

How does the engagement run?

  1. A 30 minute call about your contracts, your deadline and where your sensitive data lives.
  2. A written scope that names the deliverables, the schedule and who does what.
  3. A kickoff with your leadership and your IT provider, then regular progress briefings until the deliverables are accepted.

No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.

What else do buyers ask?

What does DFARS 252.204-7012 require after an incident?

Report the cyber incident to DoD through DIBNet within 72 hours of discovery, submit any malicious software found to DC3, preserve images of affected systems and relevant monitoring data for at least 90 days from the date you submit the report, and give DoD access for forensic analysis if it asks. Reporting requires a DoD approved medium assurance certificate, which is worth getting before you need it.

How often should we run a tabletop exercise?

NIST SP 800-171 requirement 3.6.3 calls for testing your incident response capability. Many organizations run a tabletop at least once a year and after major changes to their systems or team.

Who should attend a tabletop exercise?

The leaders who would make decisions, the IT and security staff, and anyone who would speak to customers, contracting officers or counsel. The exercise is most useful when the people in the room are the people who would be on the call.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.