Blog
Who to invite to an IR tabletop (roles beat titles)
Build the invite list from the roles your IR plan names, not the org chart. How an empty seat becomes a finding, and how to record it without grading anyone.
Most weak tabletops are decided before the first inject, by the invite list. The people who own the decisions the scenario will force are marked optional, and ninety minutes later the packet has to explain why customer notification was debated by four engineers and nobody from legal.
Here is the difference in one line. A weak roster reads:
Security team, Engineering, plus Legal and Comms as optional.
A strong one reads:
Incident commander: Marcus T. Technical lead: Priya S. Communications: Sam O. Legal and privacy: Dana K. Executive sponsor: unfilled, plan does not name one.
Both lists produce a meeting. Only the second produces evidence, because only the second can be checked against the plan afterwards by somebody who was not in the room.
Start from the roles your plan names
Open the IR plan and list the roles it names at declaration: who declares, who runs the technical response, who owns customer and regulator communications, who can authorise spend or accept customer-facing risk. Then put a named person in each seat for this run.
Titles are a poor proxy. A Director of Security may or may not be the incident commander the plan describes, and a head of marketing may own external wording in a crisis while never touching production. The plan is the authority, not the org chart.
If the plan cannot tell you who fills a seat, stop and write that down. That is a finding about the plan, and it is worth more than the exercise you were about to run. Our free plan self-check asks this directly, because it is the question most plans fail.
The seats a serious scenario stresses
Rosters vary, but decision coverage usually has to span these lanes:
- Incident command. Can set severity, run the bridge, and decide the next step against a clock.
- Technical lead. Can speak to detection, containment options and recovery paths without turning the room into a debugging session.
- Communications. Accountable for internal status and for external wording when the plan requires it.
- Legal, privacy or compliance. Can name the notification clocks and where they come from, and say what has to be true before anyone contacts a customer.
- Executive. Can authorise spend, freeze a release, or accept customer-facing risk when the scenario escalates past the working team.
Add the owner of any lane the injects will actually touch: a payment provider, a regulated data path, a vendor you would have to call. Observers are useful for training, but an observer does not fill an empty decision seat.
An empty seat is a finding, not a scheduling problem
When a required role declines, no-shows, or was never invited, that fact is the most valuable line in the record. Reassign the seat to keep the clock moving if you must, and write down that you did.
The shape that carries weight compares your own plan against what the room did:
Plan names Legal as data-exposure owner within 1h. Room reached 6h33 with the seat unfilled, and notification wording could not be approved.
Against the version most write-ups contain:
Communication could be improved.
The first is checkable by a reader who was not there, and it points at a specific fix with an owner. The second is a feeling, and an assessor who reads two of them stops trusting the rest of the document. Our free evidence template records attendance in exactly that shape, absences included, and it is one of four record formats in the template library.
Patterns worth capturing verbatim when they happen:
- Legal was invited and silent while the room debated notification.
- Communications was covered by an engineer because the owner declined.
- The named incident commander sent a delegate who had not read the plan.
- An executive joined late and overturned the severity without owning the tradeoff on the record.
None of those is a grade on anyone. They are facts about which decisions got practised and by whom.
How big the room should be
Enough people to cover the roles the scenario stresses, and no more. A tight cross-functional set with named ownership beats a twenty-person call where nobody owns the next step and the injects dissolve into open discussion. If a stakeholder only needs awareness, send them the record afterwards instead of diluting the decision circle.
Remote sessions cut both ways. Join links prove who arrived, and a muted camera hides that a required role never spoke once. Facilitation has to pull silent seats in by name, and silence from a required seat is itself evidence. It is also the thing you cannot reconstruct afterwards: nobody remembers who did not speak.
What the roster supports
A complete invite and attendance record supports a narrow, useful claim: these roles were asked to practise, these people came, these seats were empty or reassigned, and the decisions are attributed accordingly. It says nothing about whether your detection rules fire or your backups restore, which are things you have to actually go and do. Keep the packet factual and someone who was not in the room can still trust what it shows.
Bottom line: build the roster from the roles your plan names, put named people in those seats, and treat an empty or silent required seat as a finding rather than an embarrassment. The invite list is the first piece of evidence the exercise produces.