🎲 An incident response plan that's never been exercised is a hypothesis. This kit runs a 60-minute tabletop with zero consultants: pick a scenario deck, follow the agenda, log three gaps with owners and dates. The after-action page becomes your "IR plan tested" evidence. Supports IR-readiness and audit-prep workflows β€” not legal advice and not a substitute for professional incident response services. During a REAL incident, follow your IR plan and engage counsel/insurer per its terms.

How to use this (5 steps)

  1. Duplicate this page into your workspace (top-right).
  2. Schedule 60 minutes + a facilitator + the people who'd actually get the 2 AM call.
  3. Pick ONE scenario deck below (ransomware for your first run).
  4. Run the agenda, then fill the After-Action Register β€” exactly 3 gaps, 3 owners, 3 dates.
  5. Calendar the re-run in 6 months. The rhythm is the control.

The facilitator's 60-minute agenda

Clock Step
0:00 Ground rules: no blame Β· no heroics Β· every answer names a PERSON and a PLACE
0:05 Inject 1 (read from the deck) β€” the alert lands
0:20 Inject 2 β€” escalation + the PTO test
0:35 Inject 3 β€” it goes external
0:50 Debrief β†’ exactly 3 gaps, 3 owners, 3 dates β†’ After-Action Register

βœ… Scoring: 🟒 = named person + named location ("Bob, IR folder, runbook Β§2") Β· 🟑 = role known, details fuzzy Β· πŸ”΄ = "someone would probably…" The facilitator's only job is refusing vague answers. Vague survives meetings; it does not survive incidents.


🐊 The tabletop finds gaps once. The rhythm keeps them closed. AxiomLens systemizes the rhythm β€” 106 controls, computed coverage, evidence tied to controls, and the board report written locally. Nothing phones home after activation. It supports compliance documentation and audit-prep workflows (it's a tool, not a certification). See it run (2 min): youtu.be/namYnNbox4k Β· Store: thesecuritygator.gumroad.com Β· Free Tuesday issue: thesecuritygator.com

Siblings: Gatorbyte #001 β€” the 10-missed-controls field guide Β· #002 β€” the CSF Govern tracker Β· #003 β€” the Evidence Register Β· #004 β€” the Shadow AI Starter Kit Β· #005 β€” the CaaS Pricing & Scoping Worksheet Β· #006 β€” the Vendor Risk 3-Question Tracker.

Scenario decks, role cards, and the After-Action Register are below ⬇

Scenario Deck A β€” Ransomware (machine-speed)

Scenario Deck B β€” Vendor breach

Scenario Deck C β€” Business email compromise

Role cards

After-Action Register