Incident Response Drill

Run the tabletop drill your incident-response plan is supposed to survive. Joy facilitates a realistic security incident, injects new developments as your team decides, and then coaches against the plan — what you handled well, the step you missed, and the playbook section to tighten.

For Security & Incident Response Teams IT & Infrastructure Managers CISOs & Security Leaders New Responders
Sample prompt to Joy's Assistant

/roleplay an incident-response tabletop drill from our incident-response plan: [a ransomware note found on a shared file server Monday morning]. Facilitate the scenario, inject new developments as we decide, then coach us against the plan.

What it can look like

/roleplayan incident-response tabletop drill from our incident-response plan: a ransomware note found on a shared file server Monday morning. Facilitate the scenario, inject new developments as we decide, then coach us against the plan.

I'll facilitate; your team runs the response, and I'll inject a new development each time you commit to a move, then step out to coach against your incident-response plan. Here's the scene: it's Monday 7:52am. A helpdesk tech reports that FS-03, the shared engineering file server, is showing a README_RESTORE.txt in every folder and staff can't open their files. Nobody has touched the incident-response plan yet.

Facilitator
Backups ran overnight, and users are still logging in against FS-03. What's your team's first move?
Declare a security incident and page the on-call IR lead so we're working the plan, not improvising. Isolate FS-03 from the network right away — pull it off the switch rather than shutting it down, so we keep memory and disk for forensics. Tell the helpdesk to stop staff from mapping or touching that share.
Facilitator
FS-03 is isolated at 8:04am. Two minutes later monitoring flags the same README file appearing on FS-05 in a different building, and a manager emails asking why her team is locked out and whether it's safe to keep working. Where do you go?
This is spreading, so it's no longer one server. Widen containment: have the network team segment the file-server VLAN and block the service account we think is doing the writes, then check whether FS-05 shares that account. Route the manager to the comms lead — one holding message that we're aware and investigating, and yes, stop working off the affected shares. Start the incident log with timestamps now so we're not reconstructing it later.

Coaching

  • You declared before you did anything else. Section 3 of the plan makes declaration the trigger that unlocks the on-call rota and the authority to isolate, so opening with it — instead of quietly poking at the server first — is exactly right.
  • Pulling FS-03 off the network without powering it down preserved volatile evidence. The plan's containment step calls that out specifically; a well-meaning shutdown here would have destroyed memory the forensics section depends on. Good instinct.
  • When it jumped to FS-05 you re-scoped instead of staying anchored to the first host, and you went after the shared service account rather than chasing servers one by one. That's the containment-over-eradication sequencing the plan asks for.
  • One thing to tighten: you started the incident log late. The plan wants a timestamped log opened at declaration — the 8:04 isolation and the FS-05 spread should already be in it. And you didn't name who decides on notification; Section 6 puts the reportable-breach clock on the incident commander, and nobody has picked that role up yet.

Want a harder inject: the attacker emails your CEO a sample of exfiltrated files and a 48-hour deadline, so it's now extortion and not just encryption?

Want to raise the stakes? Point it at your breach-notification policy and drill the who-do-we-tell-and-when decisions once customer data is confirmed exposed.

An illustrative example. Your output will reflect your own sources, data, and prompts. This is an abridged sample. A live /roleplay runs one turn at a time and keeps going for as long as you practice.

Build response readiness through practice

Incident Response Drill drops your team into a live security incident — a ransomware note on a file server, leaked credentials from a phishing hit, an exposed storage bucket — and makes them run it. Joy facilitates, injects a new development each time the team commits to a move, and then steps out to coach every decision against the specific section of your incident-response plan.

  1. Point Joy at your incident-response plan

    Add your incident-response plan, escalation matrix, and communication templates to the Knowledge Center, or connect the source. Joy grounds every scenario and every coaching note in your actual playbook, roles, and thresholds.

  2. Ask for a drill

    Tell Joy the incident you want to rehearse — a ransomware note, leaked credentials, a data-exfiltration alert — and that you want it facilitated as a tabletop. Joy sets the scene and takes the facilitator's chair.

  3. Run it live

    Joy presents the situation, and as your team commits to each decision it injects the next development — the attacker moves, a customer notices, legal asks a question. You make the calls in real time, by text or voice, and a wrong turn here costs nothing.

  4. Get coaching and run it again

    After the exchange Joy steps out to debrief: what the team handled well, the step it missed, and the section of the plan behind each call. Change the incident or raise the stakes and go again.

  5. Make it one click for your team

    Save this ask as a custom command on the assistant your team already uses, so anyone can run it in one step.

Make it yours

Realistic Incidents

Drawn from the incidents teams actually face: ransomware, credential theft, an exposed bucket, an insider mistake. No tidy textbook breach, just plausible pressure and incomplete information.

Live Injects

Joy adds a new development every time the team commits to a move, so the drill keeps moving the way a real incident does instead of pausing for the perfect answer.

Grounded in Your Plan

Every scenario and every coaching note ties back to the exact section of your incident-response plan and escalation matrix that governs it. No generic breach checklist.

Adaptive Difficulty

Start with a clean, well-scoped incident, then move to the messy ones — ambiguous indicators, a paged responder who's unreachable, conflicting priorities. Joy meets the team where it is.

Ransomware & Extortion

Rehearse isolation, the pay-or-not decision path, backup validation, and the notification clock when files are encrypted and a note is on the screen.

Credential Compromise

Work through a phishing hit that leaked a login — session revocation, blast-radius scoping, and forced resets before the attacker pivots.

Data Exposure

Practice the response to an exposed storage bucket or misrouted export: containment, what counts as reportable, and who gets told and when.

Insider & Third-Party

Drill the harder-to-scope cases — a departing employee's access, a compromised vendor account — where the threat sits inside a trusted boundary.

Frequently Asked Questions

How does an AI-facilitated tabletop drill improve incident response?

A written incident-response plan tells people what to do but never tests whether they can do it under pressure. JoySuite facilitates a live tabletop where your team makes real decisions, faces new developments injected as the incident unfolds, and gets immediate coaching tied to the exact section of your plan — so the first real run-through isn't the day of an actual breach.

What incident scenarios can the team practice?

Drills cover ransomware and extortion, credential compromise from phishing, data exposure from a misconfigured bucket or export, and harder-to-scope insider and third-party cases. Joy builds each scenario from your own incident-response plan, escalation matrix, and communication templates, so the practice matches the incidents and roles your team actually has.

How do I make this available to my whole team?

Save the ask as a custom command on the assistant your team already uses, so anyone can start the same drill in one step. The practice is self-directed: run a tabletop before an audit, after onboarding a new responder, or whenever the team needs the reps.

Can the drill adapt to different roles and experience levels?

Yes. Joy starts with a clean, well-scoped incident and progresses to messy, ambiguous ones based on how the team responds, and it can focus on the decisions a specific role owns — the responder isolating a host, the incident commander declaring, or the comms lead drafting the holding message.

Is voice mode available for incident response drills?

Yes. The team can run the drill out loud, the way a real bridge call sounds, with people talking over each other and decisions made verbally. Voice mode makes the rehearsal closer to the pressure of a real incident than typing does.

Ready to make your incident-response plan something your team has actually run?

Join the waitlist and be first to try this workflow when JoySuite launches.