The first hour
decides how the whole
thing goes.
Nobody performs well the first time. Prior practice materially improves coordination between the people who would actually be called. Technical capability, architecture, backups and staffing still matter, but the coordination is the part a drill can fix in an afternoon.
So do it once. Pick a scenario, put the drill on a screen, and walk your team through it. It takes about forty-five minutes and the disagreements it surfaces are the entire point.
How to run it.
↳ read this bit out loud firstStages overlap. Urgent containment, a bank recall, anyone's safety, and a legal notice do not wait for their assigned minute; the clocks below are pacing for the exercise, not a sequence to obey during a real incident.
Book forty-five minutes; the drill is designed for about that long. Get the people who would actually be called in a real incident: whoever runs operations, whoever can authorize spending, whoever administers the systems, and whoever would have to talk to customers. If someone on that list cannot make it, that itself is a finding.
The rulesThree of them
1. Nobody is allowed to say “we would just call the IT company.” Name the person and find their number during the drill.
2. No blame, in either direction. The point is to find the gaps in the process, not the person.
3. Write down every answer nobody knows. That list is the real output of the session.
What you needAlmost nothing
A screen with this page on it, one person taking notes, and the printable roles sheet at the bottom. If you have an incident plan already, bring it, and notice whether anyone can actually open it during the drill.
What good looks likeNot a perfect score
A good drill produces an uncomfortable list of unknowns and two or three named owners with dates. A drill where everyone agrees smoothly on everything usually means the room is being polite rather than honest.
Pick one.
↳ the last two are things that happened hereFour scenarios, each with a different failure mode. Run the one closest to your actual exposure first; run a second one next quarter. The vendor letter and the video call are both patterned on incidents documented on our security page: reporting about a Puerto Rico IT vendor incident in which three government agencies were affected, and which one report attributed to compromised vendor credentials, and an engineering firm that lost roughly US$25 million to a video call full of synthetic colleagues.
Choose a scenario to begin
↳ nothing selected yetFill this in
before you leave the room.
↳ the only artifact that has to survive the session
A drill that produces insight and no names has failed. Print this, fill it in with real people, and put a copy somewhere reachable when your own systems are not: a wall, a wallet, a photo on a phone.
Incident roles
One name per line. An alternate for each, because incidents do not check calendars.
Page 8 of our security workbook is the incident-response one-pager this drill is built around: the first hour laid out to be filled in by hand, with the six steps, the do-nots, and space for the numbers you just looked up. Page 11 is the quarterly cadence that keeps it current.
Open the workbook →. Fourteen Letter-size pages, print what you need.
This is education, not legal advice. The notification stage summarizes Puerto Rico statutes as we understand them and does not account for your sector, your contracts, or your particular facts. We are a technology studio, not a law firm. Confirm your actual obligations with counsel, ideally before an incident, while it is still a cheap conversation.
