60-Minute Incident Response Tabletop for Carolina Municipalities

A timed, discussion-based exercise for testing municipal authority, service continuity, evidence handling, communications, and scoped reporting decisions.

Updated

A municipal cyber tabletop should expose decisions that will be difficult on the worst day, not test whether participants can recite a policy. In one hour, a Carolina town or county can examine who declares an incident, who can isolate systems, how public-safety and public-facing services continue, what facts drive notification, and who owns the improvements afterward.

This playbook is for a discussion-based exercise. It does not direct participants to alter live systems, use malware, reveal credentials, or contact real external parties during the session. A facilitator presents simulated facts; participants describe actions and point to plans, contacts, authority, and evidence. Mark all exercise messages clearly so they cannot be mistaken for a real incident.

Prepare a scenario the jurisdiction actually understands

Use a fictional ransomware and account-compromise scenario affecting a shared municipal service, such as file access, permitting, finance, or utility billing. Do not include sensitive network details in participant materials. Choose two exercise objectives: for example, validate incident authority and containment coordination, then validate continuity and notification decision-making. CISA's Cybersecurity Tabletop Exercise Package documents include planner, facilitator, participant-feedback, and after-action templates designed to clarify roles and improve plans and information-sharing processes.

Invite the manager or administrator, IT lead or provider, department service owner, emergency management, public information, legal or records counsel, finance/risk, and law enforcement liaison as locally appropriate. Assign a facilitator who does not make decisions, an evaluator who records observations, and a scribe who captures actions without turning discussion into a transcript.

Set facts, boundaries, and decision rules

Before the clock starts, provide a one-page situation: Monday at 8:15 a.m.; several users cannot open shared files; one finance user approved repeated MFA prompts; the help desk sees a suspicious sign-in; a ransom note appears on one workstation; phone and radio services remain available; scope is unknown. State that no data theft is confirmed and no notification conclusion has been reached.

Participants must distinguish facts, assumptions, decisions, and open questions. A useful decision record names the time, decision authority, known facts, action, expected effect, and next review point. NIST SP 800-61 Rev. 3 integrates incident-response recommendations with cybersecurity risk management; use the exercise to test the jurisdiction's own plan, not to improvise a new plan during the meeting.

Run the 60-minute tabletop

TimeFacilitator actionRequired participant output
0-5 minutesState objectives, safety boundaries, scenario, and current facts.Name incident lead, business lead, scribe, and decision authority; confirm real-emergency override.
5-12 minutesInject 1: suspicious sign-in, MFA approval, inaccessible files, unknown scope.First six actions, evidence to preserve, systems not to disrupt, and internal escalation path.
12-22 minutesAsk how identity, endpoint, network, vendor, and operational containment decisions are coordinated.Containment owner, approval boundary, session/account actions, service impact, and next decision time.
22-32 minutesInject 2: permitting and payment processing stop; dispatch remains available; backup status is unverified.Critical-service priorities, downtime procedures, backup validation owner, and staff instructions.
32-42 minutesInject 3: a vendor reports possible outbound transfer but cannot identify records or people affected.Scoped notification decision tree, counsel and insurer contacts, facts needed, deadlines register, and documentation owner.
42-50 minutesAsk for employee, elected-official, partner, media, and resident communications.Message approver, audiences, confirmed facts, prohibited speculation, alternate channel, and update cadence.
50-57 minutesInject 4: a clean restore point exists, but the compromised identity path may remain active.Recovery gate, validation checks, reconnect authority, monitoring period, and rollback condition.
57-60 minutesClose discussion and read back observed gaps.Top actions, accountable owners, target dates, evidence expected, and leadership review date.

Test notification as a decision, not a reflex

Do not use the exercise to teach that every event goes to every agency, resident, regulator, or insurer. Reporting and notification depend on jurisdiction, entity type, affected systems and information, contracts, policy terms, facts discovered, and current law. Build a decision tree that asks: What happened? Which entity and systems are affected? Is regulated or personal information reasonably involved? Is a critical service impaired? What has been confirmed? Which state, federal, contractual, law-enforcement, insurance, records, and individual-notice paths might apply? Who is qualified to decide?

For North Carolina local governments, the current NCDIT cyber-incident reporting page describes incidents covered by state reporting, a 24-hour timing statement after confirmation, reporting channels, and the path for requesting operational support. It also says state reporting does not override other federal requirements. Confirm the live instructions during plan maintenance and apply them with counsel; do not extend North Carolina requirements to a South Carolina jurisdiction.

For either state, keep a contact and deadlines register maintained outside the exercise: organization, reason it might apply, trigger, decision owner, deadline source, approved contact method, alternate contact, last verified date, and evidence of submission. CISA's reporting page and the FBI Internet Crime Complaint Center are federal reporting resources, but the exercise team should determine applicability and coordinate outreach rather than assume one report satisfies every obligation.

Evaluate continuity and communications

Ask service owners to state the minimum safe service, manual workaround, required records, maximum locally acceptable interruption, and authority to resume. Test dependencies between identity, DNS, connectivity, vendors, backups, building access, payroll, public safety, utilities, and public information. A recovery is not ready merely because files restore; the compromised access path must be contained and data integrity must be checked before reconnecting.

For communications, require a message map: audience, owner, approving authority, delivery channel, alternate channel, known facts, actions requested, next update, and protected details that must not be disclosed. Practice saying "under investigation" without filling gaps with speculation. Preserve public-records and legal-review considerations according to the jurisdiction's established procedures.

Use an after-action and improvement tracker

FEMA's Homeland Security Exercise and Evaluation Program connects exercise objectives and evaluation to an After-Action Report/Improvement Plan. Capture strengths as well as gaps, then turn each gap into an observable corrective action.

Tracker fieldWhat to enter
Objective and observationThe tested objective, what occurred, and the specific evidence observed
Impact and causeService or decision at risk and the process, authority, resource, or knowledge gap behind it
Corrective actionOne testable change to a plan, contact, control, contract, training item, or recovery procedure
Accountable ownerOne person responsible, with supporting departments or providers named separately
Target and dependencyDue date, funding or approval needed, and prerequisite action
Completion evidenceUpdated plan, test record, approved contact list, configuration evidence, or signed decision
Status and validationOpen, blocked, complete, accepted risk; validator and retest date

Hold a short leadership review while observations are fresh. Remove exercise-only data from systems where it does not belong, protect sensitive notes, assign actions, and schedule a retest for material gaps. "Update the plan" is incomplete until the owner, changed section, approval, and validation evidence are recorded.

Connect the exercise to operating plans

Use the small-town incident response playbook for the underlying response sequence, the emergency communications continuity playbook for channel dependencies, and the municipal disaster recovery blueprint for restoration governance. The tabletop should reveal which parts of those plans cannot yet be executed.

Primary sources

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.