A cyber incident rarely begins with a complete picture.
There may be an alert, a suspicious activity report, or an indication that something has gone wrong. But in those first moments, the organization often does not yet know the full scope of what has happened, how the attacker gained access, or what the eventual consequences will be.
And yet, decisions have to be made.
When should we escalate? Who needs to be involved? What resources should we commit? What obligations may already have been triggered?
These are not purely technical questions. They are executive decisions made under pressure and incomplete information.
This is the focus of Threat Detection and Initial Response, the first of three progressively escalating tabletop simulations in The Ceiba Protocol.
When the risk you identified becomes an incident
The simulation follows directly from the work participants have completed earlier in the day.
In Mapping Your Attack Surface, the group identifies a priority exposure within a realistic organizational scenario. The simulation then presents the incident as having entered through that exact vector.
The exercise moves participants from anticipating an attack to confronting one.
That shift is important.
It is one thing to identify a vulnerability when there is time to discuss it. It is another to recognize that vulnerability in the middle of a developing incident and decide what to do before the full picture is available.
The exercise is designed to create that moment.
The executive decision seat
Incident response is often associated with technical actions: investigation, containment, remediation, and recovery.
Those actions are essential, but they are not the focus of this exercise.
Participants remain in the executive decision seat throughout the simulation.
They must determine when the situation warrants escalation, who should be notified, and what resources should be committed. They have to make those decisions while information is still developing and uncertainty remains.
That is closer to the reality senior leaders face during a crisis.
The question is not simply whether the organization has an incident response plan. The question is whether its leaders can make sound decisions when the circumstances do not follow the plan neatly.
Acting before you know everything
One of the most difficult judgments during an emerging incident is knowing when to act.
There is a natural tendency to wait for confirmation. More information feels safer. But an incident does not necessarily pause while an organization finishes establishing certainty.
Senior leaders therefore need to be able to distinguish between:
- What is known
- What is unknown
- What requires immediate action
- What can safely wait for further information
That judgment is particularly important when escalation or notification decisions may have consequences beyond the technical response itself.
The simulation gives participants an opportunity to practice that judgment in real time rather than discussing it abstractly.
The legal and regulatory dimension
The early stages of an incident can also raise legal and regulatory considerations before the full scope of the event is known.
Participants are challenged to identify the specific legal and regulatory notification obligations already in effect at the point of initial detection.
This requires security, legal, privacy, and executive perspectives to intersect.
The person making the technical assessment may not be the person responsible for determining a notification obligation. The person responsible for legal risk may not have complete technical information. The executive responsible for allocating resources may have to make a decision before either does.
A strong initial response therefore depends on more than technical expertise. It depends on the organization’s ability to bring the right people into the decision at the right time.
When the plan meets pressure
An incident response plan is designed to provide structure during uncertainty.
A simulation can reveal whether that structure holds when people are actually required to use it.
Under pressure, documented roles may become less clear. Information may arrive in fragments. Priorities may compete. Decisions that appeared straightforward during planning may become much more difficult when the consequences are immediate.
This is one of the most useful outcomes of an executive tabletop exercise: identifying the gap between what an organization says it will do and what its leaders actually decide when an incident is underway.
That gap is not necessarily a failure.
It is something to understand, examine, and improve before the next incident makes the consequences real.
Who should be thinking about this?
This session is particularly relevant to senior leaders who may find themselves making decisions during the earliest stages of a cyber incident.
- CISOs and security leaders need to recognize when a developing incident matches a known priority exposure and determine when technical uncertainty should no longer prevent executive escalation.
- General Counsel, privacy leaders, and legal teams need to understand what information is available at initial detection and which notification obligations may already apply.
- CIOs and technology executives need to make resource and escalation decisions while the technical investigation is still unfolding.
- Risk, compliance, and audit leaders need to understand how the organization’s documented response framework performs when tested under pressure.
And for executives and board-level decision makers, the exercise provides a direct way to experience the uncertainty that surrounds early incident decisions, rather than receiving the situation later as a fully packaged security report.
Practicing the first decision
The purpose of a tabletop simulation is not to recreate an incident perfectly.
It is to create a controlled environment in which leaders can examine how they make decisions when the information is incomplete and the stakes are high.
At The Ceiba Protocol, this simulation forms the first stage of an escalating incident scenario. The exposure identified during the day’s earlier sessions becomes the entry point for the exercise, and participants begin making the decisions that will shape what happens next.
The exercise is facilitated by Shawn Ford, whose practice spans incident response, crisis communications, regulatory engagement, and strategic risk advisory.
The value is ultimately found in the decisions participants have to make in the moment: when to escalate, who to involve, what to communicate, and what to commit before they know everything.
That is the reality of initial response.
It is much easier to examine those decisions in a simulation than for the first time in a real crisis.
This is one session within The Ceiba Protocol.
