1、Improve your resilience with cyber security table-top excercisesStefan Schrling,Mattias BorgSponsors Michael ScottMicrosoft MVP Endpoint&SecurityRoleManagerFocusIntune Windows 365 SecurityBlog,Hobbies and moreBeing awesomeStefan SchrlingMicrosoft MVP Security SIEM&XDRRoleManagerFocusSecurityBlog,Hob
2、bies and moreBeing awesomeMichael ScottMicrosoft MVP Endpoint&SecurityRoleManagerFocusIntune Windows 365 SecurityBlog,Hobbies and moreBeing awesomeMattias BorgMicrosoft MVP Security SIEM&XDRRoleMagicianFocusCyber Security&ResearchBlog,Hobbies and moreWrite stuff,Build stuff,Break stuff,Paint stuffAg
3、enda Whats is a table-top exercise Incident management fundamentals How to conduct a table-top Table-top scenario examples SummaryHey ChatGPT“A tabletop exercise in cybersecurity is a simulation-based training activity where participants discuss and work through various scenarios related to a cyber
4、incident.”A tabletop exercise is also referred to as goldteamingIncident Management FundamentalsApproaches and methodologies7Crisis Deviates from the normal Sudden and unexpected Threatens survival and fundamental values Requires quick decisions Loss of ability to operate Economic impactHello from A
5、kiraOverwhelming reaction to a threatening situationHumans and the stress of a crisisReflexesPessimismPrejudiceNormalLimitedCompetitionCo-operationsHostilityRuthlessP a n i cIncidents and crisis Management=Increased stress levels OODA Loops Observe:Collect data from relevant sources before any decis
6、ions are made.Orient:Identify useful and relevant data and organize according to rules and filters Decide:Define an action plan based on the data available Act:Follow through on decision;observe responses and re-orient if needed.If your OODA loops are faster than your adversarys,YOU WIN.Incident Res