TRAINING & PLAYBOOKS

Practical training and playbooks for real incident response.

We start from real incidents and build practical exercises, playbooks, and coaching sessions that prepare teams for fast decisions, escalation, and recovery. We complement this with training focused on AI risks and the safe use of artificial intelligence tools in day-to-day work.

WHEN THIS HELPS

Use this when procedures exist, but people need practice.

01

Roles are unclear

Teams are not aligned on who decides, who acts, and who communicates during an incident.

02

Playbooks are outdated

Existing procedures no longer match tools, risks, escalation paths, or business expectations.

03

Teams need rehearsal

IT, SOC, leadership, legal, and communications need to practise the same scenario together.

04

AI is being used in the organisation without rules

Employees are already using ChatGPT, Copilot, or other AI tools and may disclose company data without understanding the risks or having a policy to guide them.

TRAINING TRACKS

Choose the format your team needs to practise.

Incident Response Playbook Pack

Best for: Teams that need repeatable steps, clear roles, and fast decisions for common incident scenarios.

We build or refine practical playbooks for incidents your team is likely to face, so response is documented, consistent, and easy to rehearse.

Includes
  • Ransomware, BEC, account compromise, or insider scenario playbooks
  • Escalation flow, clear roles, and decision points
  • Evidence checklist, documentation steps, and communication templates

Executive Tabletop Workshop

Best for: Leadership, legal, communications, and security teams that need coordinated decisions.

We facilitate realistic incident simulations focused on decisions, trade-offs, escalation, and messaging.

Includes
  • Scenario script and facilitator notes
  • Decision prompts for leadership and support teams
  • Debrief with improvement actions

Operational Coaching for SOC and IT

Best for: SOC and IT teams that need consistent triage, clear handoff between levels (L1→L2), and documented incident response.

We coach analysts and operational teams through practical detection, triage, escalation, and response workflows using scenarios close to their current alerts and tooling.

Includes
  • Review of alert triage, prioritisation, and escalation flow
  • Coaching on runbooks, dashboards, handoff, and investigation documentation
  • A practical list of improvements for detections, procedures, and operational indicators

Organisation-wide readiness programmes

Best for: Everyone in the organisation, from employees and management to IT teams and security owners.

We deliver structured programmes on cybersecurity and responsible use of artificial intelligence, adapted to the company's context, industry, and operating reality.

Includes
  • Complete written support (Knowledge Pack): 12-16 pages with concepts, real scenarios, protocols, and checklists
  • 60-90 minute live session: presentation, practical scenarios, and open Q&A
  • 30-day follow-up session for questions that come up in practice

OUTCOMES

What improves after the training sessions

01

Everyone knows what to do

All involved teams, from leadership and IT to legal and communications, work through an incident with the same understanding of roles, priorities, and next steps.

02

Procedures are tested, not just written

Teams practise detection, containment, escalation, and recovery together before a real crisis requires them to do it for the first time under pressure.

03

Outcomes become measurable

At the end of each session, the team receives clear actions, named owners, and criteria for tracking whether what was discussed is actually being applied.

04

Employees know what is allowed and what is not when using AI

Each person in the organisation understands where the usefulness of an AI tool stops and where risk begins. They also gain a usage protocol they can apply immediately, without waiting for approval.

Common questions