《Modern Management Summit 2026 Improve your resilience with cybersecuri... - MEMSummit - Improve your resilience with cybersecurity table-top exercises.pdf》由会员分享,可在线阅读,更多相关《Modern Management Summit 2026 Improve your resilience with cybersecuri... - MEMSummit - Improve your resilience with cybersecurity table-top exercises.pdf(51页珍藏版)》请在三个皮匠报告上搜索。
1、Improve your resilience with cyber security table-top excercisesStefan Schrling,Mattias BorgSponsors Michael ScottMicrosoft MVP Endpoint&SecurityRoleManagerFocusIntune Windows 365 SecurityBlog,Hobbies and moreBeing awesomeStefan SchrlingMicrosoft MVP Security SIEM&XDRRoleManagerFocusSecurityBlog,Hob
2、bies and moreBeing awesomeMichael ScottMicrosoft MVP Endpoint&SecurityRoleManagerFocusIntune Windows 365 SecurityBlog,Hobbies and moreBeing awesomeMattias BorgMicrosoft MVP Security SIEM&XDRRoleMagicianFocusCyber Security&ResearchBlog,Hobbies and moreWrite stuff,Build stuff,Break stuff,Paint stuffAg
3、enda Whats is a table-top exercise Incident management fundamentals How to conduct a table-top Table-top scenario examples SummaryHey ChatGPT“A tabletop exercise in cybersecurity is a simulation-based training activity where participants discuss and work through various scenarios related to a cyber
4、incident.”A tabletop exercise is also referred to as goldteamingIncident Management FundamentalsApproaches and methodologies7Crisis Deviates from the normal Sudden and unexpected Threatens survival and fundamental values Requires quick decisions Loss of ability to operate Economic impactHello from A
5、kiraOverwhelming reaction to a threatening situationHumans and the stress of a crisisReflexesPessimismPrejudiceNormalLimitedCompetitionCo-operationsHostilityRuthlessP a n i cIncidents and crisis Management=Increased stress levels OODA Loops Observe:Collect data from relevant sources before any decis
6、ions are made.Orient:Identify useful and relevant data and organize according to rules and filters Decide:Define an action plan based on the data available Act:Follow through on decision;observe responses and re-orient if needed.If your OODA loops are faster than your adversarys,YOU WIN.Incident Res