Incident Response Tabletop
Experience the thrill of an information security incident firsthand – welcome to the Incident Response exercise for everyone who has ever wanted to know what happens behind the scenes during a hacking incident in IT security.
Phönix Pen and Paper
Durlacher Allee 77
May 11, 2023 from 6:00 PM
The event is free, registration is below, refreshments are provided
The Setting
Imagine the following: You are part of an IT crisis team and a critical incident occurs. Data is stolen, systems are encrypted, and the consequences for the company could be devastating. How do you react?
In aramido’s Incident Response exercise, you are placed in such a situation and must make quick decisions to manage the incident. Every step you take can influence the situation, and it is up to you to find the right balance of risk-taking to get your company out of trouble.

The Story
During the exercise, you will gain a deeper understanding of the complex challenges of information security and learn how to react in an emergency. You will get to know the importance of precautions such as regular backups and access controls in a realistic scenario. At the same time, your assertiveness will be called upon – different roles represent different interests.
The Goal
The exercise is not only educational but also entertaining and exciting. It will challenge you, test your analytical skills, communication competencies, and your judgment as you work against the clock to resolve the incident.
The Roles
Management
The management is responsible for the overall picture of the company. In the game, they will have to answer decisive questions, such as how much money can be spent to resolve the incident, how customer communication should be designed, or how to minimize the impact on business processes.
SOC Analyst
The SOC Analyst (Security Operations Center Analyst) monitors the company’s IT infrastructure for potential security incidents. In the game, they will play a key role, as they will be the first to notice the incident and initiate the incident response process.
Data Protection Officer
The data protection officer is responsible for compliance with data protection guidelines and laws in the company. In the game, they will have to ensure whether personal data is affected and that the incident is properly reported.
HR Management
The HR (Human Resources) management is responsible for the company’s employees. In the game, they will have to take care of internal communication and employee training to ensure that all involved parties are informed about the incident and know how to behave.
Chief Information Security Officer
The chief information security officer is responsible for the security of the IT systems in the company. In the game, they will lead the incident response process and ensure that all measures to resolve the incident are taken.
Infrastructure Admin
The infrastructure admin (Infrastructure Administrator) is responsible for the administration of the company’s IT infrastructure. In the game, they will work closely with the SOC analyst and the chief information security officer to resolve the incident as quickly as possible.
Cloud Admin
The cloud admin is responsible for the administration of the company’s cloud infrastructure. In the game, they will have to ensure that no data is lost and that all measures to resolve the incident also take the cloud systems into account.
Program Overview
| Start | Title |
|---|---|
| 6:00 PM | Arrival at aramido premises |
| 6:15 PM | Kick-off and introduction |
| 6:30 PM | Start of the role-play |
| 8:30 PM | End of the role-play and beginning of the wind-down |
| open | Pinsa and Tschunk |
Application via email, preferably encrypted (Link to PGP key), with role request by May 9, 2023
