π² An incident response plan that's never been exercised is a hypothesis. This kit runs a 60-minute tabletop with zero consultants: pick a scenario deck, follow the agenda, log three gaps with owners and dates. The after-action page becomes your "IR plan tested" evidence. Supports IR-readiness and audit-prep workflows β not legal advice and not a substitute for professional incident response services. During a REAL incident, follow your IR plan and engage counsel/insurer per its terms.
| Clock | Step |
|---|---|
| 0:00 | Ground rules: no blame Β· no heroics Β· every answer names a PERSON and a PLACE |
| 0:05 | Inject 1 (read from the deck) β the alert lands |
| 0:20 | Inject 2 β escalation + the PTO test |
| 0:35 | Inject 3 β it goes external |
| 0:50 | Debrief β exactly 3 gaps, 3 owners, 3 dates β After-Action Register |
β Scoring: π’ = named person + named location ("Bob, IR folder, runbook Β§2") Β· π‘ = role known, details fuzzy Β· π΄ = "someone would probablyβ¦" The facilitator's only job is refusing vague answers. Vague survives meetings; it does not survive incidents.
π The tabletop finds gaps once. The rhythm keeps them closed. AxiomLens systemizes the rhythm β 106 controls, computed coverage, evidence tied to controls, and the board report written locally. Nothing phones home after activation. It supports compliance documentation and audit-prep workflows (it's a tool, not a certification). See it run (2 min): youtu.be/namYnNbox4k Β· Store: thesecuritygator.gumroad.com Β· Free Tuesday issue: thesecuritygator.com
Siblings: Gatorbyte #001 β the 10-missed-controls field guide Β· #002 β the CSF Govern tracker Β· #003 β the Evidence Register Β· #004 β the Shadow AI Starter Kit Β· #005 β the CaaS Pricing & Scoping Worksheet Β· #006 β the Vendor Risk 3-Question Tracker.
Scenario decks, role cards, and the After-Action Register are below β¬
Scenario Deck A β Ransomware (machine-speed)
Scenario Deck B β Vendor breach