INVESTIGATE: Plan Before Panic
Incident Response Plan Development Workshop
Plan Before Panic Strikes
When a cyber incident strikes, panic is the enemy of good decisions. This practical, gamified planning workshop helps your team create a solid incident response plan from scratch – so you have a clear score to play from before crisis hits.
This session focuses on building your incident response plan, not running a full simulation. If you already have a plan and want to test it under pressure, our separate CSIRTxp: Cyber Security Incident Response Team eXPerience is our workshop is where you test it.
A gamified, live‑play incident response experience for cross‑functional teams that reveals gaps, strengthens communication and builds confidence before a real attacker does.
Every organisation, regardless of size, will face some form of cyber incident.
The question is not if, but when. The organisations that recover fastest are the ones that have rehearsed their response and know who plays which part.
This workshop helps you:
Reduce panic and confusion when an incident occurs.
Clarify who needs to do what, and when, across technical and non‑technical teams.
Build confidence across your incident response team and leadership.
Meet regulatory and insurance expectations for incident planning.
Demonstrate due diligence to funders, clients, boards, and the ICO.
Protect your reputation and minimise operational disruption.
Or put another way: panic is never a good business strategy – preparation is.
Who should attend?
This workshop is designed for leadership teams, operational staff, and anyone who’d be involved in responding to a cyber incident:
- CEO, trustees, and board members
- CIO, CTO, Head of IT and technical staff
- Organisation’s information assets
- Organisation's current cyber defences
- Potential consequences of a security incident
- Anyone with a role in your CSIRT or on‑call rota
- What to do if they spot a security risk, an issue, or an incident
Mixed groups work particularly well; we encourage a blend of strategic and operational voices in the room to provide different perspectives.
About the workshop
A hands‑on planning workshop that guides you step by step through creating a usable, business‑focused incident response plan – even if you’re starting from a blank page. We structure the experience using our 3Ps:
PREPARE – gather the right people and context so the plan reflects reality
PARTICIPATE – co‑create your incident response plan together, with light scenario prompts to check it works in practice
PROBE – refine, prioritise and agree concrete follow‑up actions so the plan doesn’t gather dust
We also help you Prove – by generating clear metrics that give you hard numbers to plan and prioritise your next incident response investments.
PREPARE – Before the workshop
We set the stage so your time in the room is spent solving problems, not trying to work out who does what.
- Context Lens session to understand your organisation’s risks, assets, and culture
- Pre-workshop questionnaire to tailor scenarios to your sector and critical services
- Access to curated incident response resources via our portal
- INVESTIGATE workbook (per person) provided digitally
PARTICIPATE – During the workshop
This is where the rehearsal happens: your team practises what they’ll do when the music suddenly stops.
- Participants anonymously respond to questions to establish what they already know (at the start) and what they've learned (at the end). This data can be used to measure both the efficiency and Return on Investment of the training sessions
- Gamified activities to actively explore, discuss, and consolidate the content
- Team-based scenario planning focused on business impact, not just tech
- Interactive card deck exercises using CyberDeck8D™ INVESTIGATE cards
- Defining or refining your CSIRT (Cyber Security Incident Response Team) roles and escalation paths
- Mapping detection, response, and recovery processes – including who speaks to whom, and when
- Consolidation of learning points with a quiz tournament
- Opportunity for Questions and Answers throughout
PROBE – After the workshop
Although one rehearsal is good; embedding the learning in daily practice is where the real value lies. Refine, prioritise and agree concrete follow‑up actions so the plan doesn’t gather dust.
- Certificate of attendance and digital badge for each participant (shareable on LinkedIn)
- Ongoing access to the INVESTIGATE resources portal
- Debrief session with a nominated organisational lead to review the draft plan, prioritise next steps and decide whether/when to schedule a CSIRTxp exercise
- ENHANCED ONLY: Full Planning Summary and Recommendations report with analysis, metrics and improvement roadmap you can share with your board or audit committee
Prove - Assessment & evaluation
- Pre‑ and post‑session knowledge checks
- Incident Response Maturity scoring to capture your starting point and initial progress
- Team readiness reflections to highlight where extra support or training is needed
- Anonymous feedback surveys to inform your next steps and whether CSIRTxp is the right follow‑on
Outcome: You leave with a structured, organisation‑specific incident response plan in draft, plus a clear list of gaps to close (not just good intentions.
Flexible Delivery
We’re flexible, and work with you to accommodate your preferred learning experience.
Both formats deliver the same practical preparation, with full interactivity, group work, and space for questions.
Live in-person Client site or alternative venue
Bring your staff together for maximum collaboration, energy, and informal side conversations that surface the real issues
Live online aka virtual instructor lead training (VILT)
Perfect for distributed or hybrid teams who still need full interaction and engagement
Plan Before Panic Options
We provide 3 options, each with different levels of customisation; so there is something to fit the needs of every organisation.
NOTE: If you’re starting entirely from scratch, you’re unlikely to finish a fully‑fledged plan during the session – but you will leave knowing what good looks like and how to get there.
Enhanced
Do it FOR you (DiFY)
6 Hour workshop
We turn your workshop outputs into a polished incident response plan your team can refine over time.
Standard
Do it WITH you (DiWY)
5 Hour workshop
Up to 4 × 30‑minute remote consultation calls to help you complete the plan.
Basic
Do it Yourself (DiY)
4 Hour workshop
You leave with a solid skeleton incident response plan to refine internally.
Once your plan is in place, our separate CSIRTxp: Cyber Security Incident Response Team eXPerience can then put it through its paces in a live, gamified drill – turning your static document into practical, rehearsed behaviour
Our workshops are:
- Engaging: Use humour and surprises to create a playful state of mind, making information easy to understand and remember.
- Created and delivered by experts: Benefit from over 30 years of combined experience in cybersecurity and adult learning.
- For all staff: Whether staff are technically savvy or not, the content is designed to help them learn new things and change their behaviours.
- Inclusive & diverse: Respectful of each person's preferences and needs. Our examples include people of different ages, ethnicities and abilities.
Already have a plan or just created one with us?
NVESTIGATE: Plan Before Panic workshop and give your team the clarity, capability, and confidence to handle incidents like professionals; not amateurs. Our CSIRTxp workshop is where you test it. A gamified, live‑play incident response experience for cross‑functional teams that reveals gaps, strengthens communication and builds confidence before a real attacker does.
Pricing is available on request. We offer discounts for charities, not‑for‑profits, and public sector organisations because reducing cyber risk should never be a privilege.