Blog
Write injects that force a decision, not a discussion
Most tabletops fail at the inject. How to write a timed prompt that names a system, a seat, and a choice, and what a vague prompt costs when someone later reads the packet.
The room is right. Legal is here. The technical lead is here. The incident commander has the plan open. Then the facilitator says, talk through how you would contain this. Forty minutes later someone writes "containment was discussed" in the notes, and the packet has nothing an outsider can check.
That failure started in the inject, not in the people.
A weak inject reads:
Discuss containment options for the affected systems.
The room lists EDR isolate, a VLAN cut, and disabling the VPN. Nobody chooses. Payroll is not mentioned. An assessor who later reads the packet cannot tell whether anyone had the access, the authority, or the willingness to take a system down. The sentence would also be true of a team that has never opened the EDR console. That is what it costs: the record looks complete and the gap stays invisible until 03:22 on a real night.
A strong inject reads:
T+18. EDR shows encryption on billing-db-02 and the finance file share. The overnight operator can isolate both from the network in about four minutes. Finance says payroll posts from billing-db-02 at 06:00. It is 03:22. Priya S is the technical lead the plan names. Isolate both, isolate only the file share, or keep both up and accept spread. Name the choice, the owner, and the clock. You have four minutes of exercise time.
Both produce a meeting. Only the second produces a decision that can be written down: who chose what, against which facts, at which time.
What a usable inject actually contains
Five parts. If one is missing, the room will fill the gap with discussion.
- A time on the exercise clock. Later is not a time. T+18 is.
- A fact that arrived. A host, an alert, a person, a message. Not a movie plot.
- A choice that cannot be deferred without that deferral being the decision. Isolate, keep up, or wait. Freeze the agent, or leave it running. File, or record that you will not file yet.
- A named seat that has to own it. If the plan cannot name the seat, that is a finding about the plan, and it is worth more than the inject. Run the free plan self-check before you book the room.
- The line you will write either way. Owner, choice, clock, and what was still unknown.
The filing-clock walk in who files at hour 72 is one inject family. Containment, customer wording, vendor cutoff, and freeze-the-feature are others. The craft is the same: a clock, a fact, a seat, a choice.
Split the trailer into a sequence
The other common failure is dumping the whole incident at T+0.
A ransomware group has encrypted 40% of servers, stolen two terabytes, and posted a leak site. Discuss your response.
That is a trailer. It produces shock, then open discussion, then a packet that says the team walked through a ransomware scenario. Split it so each inject forces a different call:
- T+0. EDR flags encryption on billing-db-02. The SOC analyst pages the incident commander. Decide: declare Sev-1 now, or wait for a second host.
- T+12. A ransom note appears on the finance file share. Backup status is unknown. Decide: isolate the share, or keep it up so finance can finish payroll.
- T+35. A sample of stolen files lands in the CEO's personal inbox. Decide: who calls counsel, and what has to be true before anyone drafts customer wording.
- T+50. A reporter asks whether customer data is involved. The facts on the table do not answer that. Decide: Sam O (comms) issues known, unknown, and under investigation, or the room stays silent.
Hang the sequence on a family you actually run. Ransomware with exfiltration is one of six on the scenario library. The injects have to name your hosts and your clocks, not a server and a vendor.
Do not put a restore in the inject. Asking the room whether last night's backup of billing-db-02 would come back is a DR test, and a conversation about backups is not a restore. A well-written inject still only produces evidence that named people practised a choice under a scenario. It does not prove the isolate button works, that the backup restores, or that any control is tested.
Time the room so the decision can be written
Five injects is plenty for ninety minutes. After each one, stop talking long enough for the owner to speak the choice out loud and for the scribe to write it: time, seat, decision, what was still unknown. If an inject does not produce a named decision in about eight minutes, the inject is the problem, not the room.
Silence from a required seat is itself evidence. Pull them in by name. If they still do not own the call, write that down and reassign the seat to keep the clock moving. The invite-list post covers how an empty or silent seat becomes a finding rather than a scheduling note.
Do not send a live customer email or a live regulator filing from the exercise. Practise the wording and the ownership. Leave the send for a real event. Do not quiz the plan ("what does section 4.2 say"). That tests memory, not decisions. Do not grade the room. The inject's job is to force a choice. The record's job is to capture plan-says versus room-did. Neither is a pass or fail, and neither is a compliance verdict.
The artifact that travels is the decision log, not the slide deck. That is the shape of our free evidence template, and it sits with three other formats in the template library. Hand the record to whoever owns assurance. They decide whether it meets their sampling for the period.
Bottom line: write injects that name a system, a clock, a seat, and a choice. Open discussion hides the gap. A timed inject writes it down.