Imagine: it is a Monday morning, and from all viewpoints it appears to be a normal day. But as you and your staff settle in, you notice some alerts from campus monitoring systems from Friday night that appear to be both abnormal and serious. Then, almost in concert with each other, more alerts begin to arrive, and the help desk manager calls to let you know that they are being overwhelmed by contacts from the campus about ransom pop-ups, unwanted SMS messages, and emails seeking personal information.
Any IT or security professional will know that you and your team must spring into action. But now you realize that you are not only stressed by the alerts and campus anxiety, but also the questions that quickly arise: Where is our incident response plan? Do we even have a plan? Is the plan up to date? Do the security and IT staff know of their responsibilities? What about other areas? Legal, communications, public safety?
This is not the time to be asking these questions. Panic may ensue, and feelings of regret may emerge in your mind that you were not prepared for a moment like this.
For cybersecurity teams there is consensus that an incident response plan is necessary. This is not simply just for the response itself – a plan is also part of several regulatory and compliance mandates. Having an up to date, well documented, well known, and well tested plan are key signs of a mature and responsible cybersecurity mission.
So yes, a plan is necessary, but—more importantly—it needs to be ready and actionable.
If you don’t have a plan, that’s an entirely different concern and content for a future article. Today, I’m focusing on the often forgotten “well tested” part of the equation via the valuable tool known as a tabletop exercise.
What is a tabletop exercise?
Tabletop exercises (or “TTX”) are activities that simulate an actual incident response. They are used in many disciplines beyond cybersecurity such as public safety and emergency management. A TTX is a discussion-based session, where the exercise leader presents a hypothetical scenario to an incident response team. Using periodic “injects” which add new information, threat vectors, outside concerns or downstream impacts, a response team will dialogue through their actions to respond to the incident described in the scenario, as documented in their incident response plans.
TTXs help you recognize both strong and weak points in your incident response plan. In addition to the technical aspects, intangible areas such as teamwork, cross-functional coordination, and communication needs come into play, and these are all areas that can be difficult to correct during an actual incident. Brainstorming, decision making, escalation, expansion to other areas, and executive actions may also be required while in incident response mode, and an up to date and well-practiced plan using regular tabletops will play a major role in response effectiveness.
For cybersecurity, the options that you could cover in a hypothetical tabletop are endless. You can consider scenarios that cover DNS and DDoS attacks, lost devices, shadow databases, network compromises, a breach at your third-party partners, insider threats, and many others too numerous to list. Good places to start are scenarios based on the most likely threats that your institution may face, such as phishing, ransomware, or compromised credentials.
How should you perform a tabletop exercise?
I recommend that you have an experienced higher education cybersecurity professional run your tabletop exercise if you can, but there are several alternatives if this is not an option.
They can be facilitated by a member of your campus community, though I highly recommend that it is not someone who is listed as a member of your cyber security incident response team (CSIRT). Good candidates for this would be someone from your project management office or a senior business analyst. I had a colleague in one of my roles from the PMO who could facilitate any situation on a moment’s notice because of her inquisitiveness and ability to ask hard questions. She led great tabletops for me. I’ve also seen success when you use your head of public safety or emergency management as long as they are not part of the CSIRT. The positive of this option is that there are no impacts on your budget, while the often-repeated negative is the facilitator not having the experience or expertise to make the results worthy of the effort. With an experienced facilitator, neither of those should come into play. And of course, continued practice will provide the experience along the way.
Another no-cost or low-cost option is to ask a trusted peer from another school. As a CISO, I was often asked to facilitate tabletops for peer schools. This can be a very insightful option, as your facilitator is already somewhat familiar with your campus culture and security operations and deeply understands higher education dynamics. I have found that this trusted outsider can watch with an experienced and nuanced view and ask the right questions to make your plan stronger.
And of course, there are outside experts such as Moran who can provide TTX services to test your plan. Local law enforcement, state emergency management personnel, and even the Department of Homeland Security often provide this service at no cost. Just be sure that they will be providing a scenario that is cyber focused, and takes into account the uniqueness of higher ed.
Who will benefit from a tabletop exercise?
Your information technology group, of course, but the wider campus audience are also beneficiaries of the resulting improvements that will follow. Your entire institution will benefit from both the resiliency that is developed, as well as more efficient responses leading to less downtime. There can be financial implications in reducing the threat of ransom payments, and a lower probability of reputational harm from fines, long recovery or public embarrassment. Campus partners will get an active look at how practice leads to quicker responses and less mistakes, while also gaining insight and greater appreciation of what it takes to secure, respond, and recover from an event.
Practice Makes Perfect
I’m a firm believer that practice makes perfect or, at the very least, a high level of excellence. I strongly urge regular testing of your plan, which can be done at differing levels.
If you are short on time, you can begin by walking through a small portion at a monthly staff meeting. It doesn’t have to be long or prepared for—just a “what if” discussion on one aspect of your plan is a great place to start. A regular cadence of this will keep your plan fresh in mind and up to date.
The next level would be dedicated time with the IT staff who are part of the incident response team. I’m a believer in using an actual incident from the past few months to fully walk through the plan. As an option, this can be part of an after-action report of a real incident to positively identify deficiencies and make the necessary plan modifications.
Finally, an annual exercise by a trusted peer or an outside firm is not only good practice, but also now becoming necessary for several regulations, compliance mandates, and cyber insurance policies, including GLBA. This annual test would be with full membership of the incident response team and include several other areas from across your campus. Plans typically include public safety, communications, risk management, legal, and others. I fondly remember a tabletop I was holding for over 70 members of the campus community on the morning that the crisis in Ukraine began. During the exercise there were attendees who were dealing with concerned students on campus, faculty who were there, and putting out communications to the campus on the crisis. We were practicing while also doing actual response. Talk about impact!
Conclusion
Tabletops play a valuable role in the success of your security mission. Many boards request your statistics for the mean time to identify, respond, and/or mitigate an incident, and regularly testing your response can have a positive impact on your bottom-line statistics.
With increasing regularity, tabletops are becoming an essential element in sound security practices. Incident response teams are better prepared for potential emergency actions though the simulation of a real-life situation, via regularly scheduled exercises. Finding both your gaps and your strong points in a controlled, facilitated environment not only increases your organization’s resiliency, but also your confidence.
Finally, there can be intangibles that are gained through a tabletop exercise.
I have been doing numerous tabletop exercises over the last few months in my role as an executive consultant. For some campuses, this was the first time utilizing their plan with a TTX, while others may have been blowing off the dust of a plan that had not been visited in a while.
In every tabletop that I facilitate there is always an “aha” moment for the institution. Maybe it is the realization that the contact information for a key participant or vendor was missing, or perhaps the plan did not include a decision point for escalation to their cyber insurance broker. The biggest intangible that I witness during a tabletop, almost without fail, is the recognition by the non-IT participants of what is demanded of IT and security during an event response. The regard and increased respect that naturally arise from this exercise are almost always verbalized during the feedback session as to the knowledge, expertise, focus, and passion of the incident response team. This leads not only to deeper appreciation and partnerships but can also shape and enhance future needs for the team.
I encourage you not to overlook this key element in your overall security mission. Revisit your plan and schedule your tabletop today.
About Moran
For over two decades Moran has focused on the most pressing technology needs of the institutions of higher education and research that we’ve served. We partner with institutions to achieve improvements in student experience and success, digital transformation, administrative optimization, and risk management. For more information about Moran or to schedule a conversation please click here.
Our vCISO, Cybersecurity Advisory Services, and tabletop exercises are developed and conducted by experienced, higher education cybersecurity leaders who have been in your shoes. We understand the complexity of campus decentralization, culture, and decision making, and can advise you through your challenges, vision, strategy, culture, and upskilling your cyber practices using our deep experience. Our catalog of exercise options brings real-world scenario-based simulations, facilitated in a way to foster collaborative learning. These exercises are not about pass/fail or win/lose, but are developed as educational tools to increase your security posture and reduce risk on your campus. We can also assist in developing your initial plan or reviewing your current one. Backed by a team of consultants and analysts with over twenty years of experience and success as a firm, Moran can help elevate your security mission.
No results found.
Tell us about your challenge, and we’ll work with you to design the right next step.