Orange warning icon on a transparent, grey‑and‑white chequered background. A stylised laptop shape supports a triangle containing an exclamation mark, suggesting a computer alert, security warning, or system error message. The icon used by Cybility to represent 'Investigate'

INVESTIGATE: Plan Before Panic

Incident Response Plan Development Workshop

Plan Before Panic Strikes

When a cyber incident strikes, panic is the enemy of good decisions. This practical, gamified planning workshop helps your team create a solid incident response plan from scratch – so you have a clear score to play from before crisis hits.

 

This session focuses on building your incident response plan, not running a full simulation. If you already have a plan and want to test it under pressure, our separate CSIRTxp: Cyber Security Incident Response Team eXPerience is our workshop is where you test it. 

 

A gamified, live‑play incident response experience for cross‑functional teams that reveals gaps, strengthens communication and builds confidence before a real attacker does.

Every organisation, regardless of size, will face some form of cyber incident.

The question is not if, but when. The organisations that recover fastest are the ones that have rehearsed their response and know who plays which part.

This workshop helps you:

  • Reduce panic and confusion when an incident occurs.

  • Clarify who needs to do what, and when, across technical and non‑technical teams.

  • Build confidence across your incident response team and leadership.

  • Meet regulatory and insurance expectations for incident planning.

  • Demonstrate due diligence to funders, clients, boards, and the ICO.

  • Protect your reputation and minimise operational disruption.

Or put another way: panic is never a good business strategy – preparation is.

Group selfie taken in a hotel conference room during a workshop. Two smiling facilitators fill the foreground, while participants seated at round tables behind them look towards the camera and smile or wave. The room has mirrored ceiling panels, neutral walls, and scattered papers, bottles, and notebooks on the tables, conveying a friendly, engaged training atmosphere.
Screenshot 2026 07 29 115556

Who should attend?

This workshop is designed for leadership teams, operational staff, and anyone who’d be involved in responding to a cyber incident:

Mixed groups work particularly well; we encourage a blend of strategic and operational voices in the room to provide different perspectives.

Graphic headed “Testimonial” with the Cybility logo and large orange quotation marks framing a purple box. The testimonial text reads: “Well delivered, great subject knowledge, informative, nuanced answers given to queries raised. Kept the session lively and entertaining whilst maintaining the importance of what we were covering.” A small line beneath states: “Service: Cybersecurity Incident Response Team Experience (CSIRTxp).” At the bottom, purple text says: “Members of the Cyber Security Incident Response Team (CSIRT) members, Turnover £20+ million, UK.”

About the workshop

A hands‑on planning workshop that guides you step by step through creating a usable, business‑focused incident response plan – even if you’re starting from a blank page.  We structure the experience using our 3Ps:

PREPARE – gather the right people and context so the plan reflects reality

PARTICIPATE – co‑create your incident response plan together, with light scenario prompts to check it works in practice

PROBE – refine, prioritise and agree concrete follow‑up actions so the plan doesn’t gather dust

We also help you Prove – by generating clear metrics that give you hard numbers to plan and prioritise your next incident response investments.

PREPARE – Before the workshop

We set the stage so your time in the room is spent solving problems, not trying to work out who does what.

PARTICIPATE – During the workshop

This is where the rehearsal happens: your team practises what they’ll do when the music suddenly stops.

PROBE – After the workshop

Although one rehearsal is good;  embedding the learning in daily practice is where the real value lies. Refine, prioritise and agree concrete follow‑up actions so the plan doesn’t gather dust.

Prove - Assessment & evaluation

Outcome: You leave with a structured, organisation‑specific incident response plan in draft, plus a clear list of gaps to close (not just good intentions.

Flexible Delivery

We’re flexible, and work with you to accommodate your preferred learning experience.

Both formats deliver the same practical preparation, with full interactivity, group work, and space for questions.

Live in-person Client site or alternative venue

Bring your staff together for maximum collaboration, energy, and informal side conversations that surface the real issues

Live online aka virtual instructor lead training (VILT)

Perfect for distributed or hybrid teams who still need full interaction and engagement

Plan Before Panic Options

We provide 3 options, each with different levels of customisation; so there is something to fit the needs of every organisation.

NOTE: If you’re starting entirely from scratch, you’re unlikely to finish a fully‑fledged plan during the session – but you will leave knowing what good looks like and how to get there.

Enhanced

Do it FOR you (DiFY)

6 Hour workshop

We turn your workshop outputs into a polished incident response plan your team can refine over time.

Standard

Do it WITH you (DiWY)

5 Hour workshop

Up to 4 × 30‑minute remote consultation calls to help you complete the plan.

Basic

Do it Yourself (DiY)

4 Hour workshop You leave with a solid skeleton incident response plan to refine internally.

Once your plan is in place, our separate CSIRTxp: Cyber Security Incident Response Team eXPerience can then put it through its paces in a live, gamified drill – turning your static document into practical, rehearsed behaviour

Our workshops are:

Already have a plan or just created one with us?

NVESTIGATE: Plan Before Panic workshop and give your team the clarity, capability, and confidence to handle incidents like professionals; not amateurs.  Our CSIRTxp workshop is where you test it. A gamified, live‑play incident response experience for cross‑functional teams that reveals gaps, strengthens communication and builds confidence before a real attacker does.

Pricing is available on request. We offer discounts for charities, not‑for‑profits, and public sector organisations because reducing cyber risk should never be a privilege.