Back
#248
October 20, 2025

EP248 Cloud IR Tabletop Wins: How to Stop Playing Security Theater and Start Practicing

Guest:

Topics:

Cloud IR and Forensics
29:29

Subscribe at Spotify

Subscribe at Apple Podcasts

Subscribe at YouTube

Topics covered:

  • What is this tabletop thing, please tell us about running a good security incident tabletop? 
  • Why are tabletops for incident response preparedness so amazingly effective yet rarely done well?
  • This is cheap/easy/useful so why do so many fail to do it? Why are tabletops seen as kind of like elite pursuit?
  • What’s your favorite Cloud-centric scenario for tabletop exercises? Ransomware? But there is little ransomware in the cloud, no?
  • What are other good cloud tabletop scenarios?

Do you have something cool to share? Some questions? Let us know:

Transcript

The discussion, featuring Jibran Ilyas, underscored that Incident Response (IR) tabletops are not a luxury but a critical mechanism for building "muscle memory" for a high-stress scenario. Drawing on the classic military maxim, "The more you sweat in peace, the less you’ll bleed in war," the core value of a TTX is to preempt the panic, irritation, and poor decision-making that invariably accompany a real incident.

A successful tabletop essentially establishes a pre-agreed-upon rule set that aligns with the organization's risk profile and risk appetite. By determining critical decisions beforehand—such as the balance between preserving forensic evidence and prioritizing business recovery—teams can execute decisive actions during the chaos rather than debating core strategy. The worst outcome is being stagnant or fearful in the critical first 72 hours, which sets the tone for the entire recovery effort. Decisions must be made with imperfect facts.

The Pitfall of Executive-Only Tabletop Exercises (TTX)

A major theme addressed was the common failure of limiting TTXs to only executives and external counsel. These high-level, often two-hour sessions are frequently plagued by unrealistic assumptions, operating with a "magic wand" mentality. Executives often assume data, such as cloud logs, are instantly available.

In stark contrast, when a TTX is run with technical teams (the preferred approach), the reality hits:

Data Availability: Technical teams reveal they may not have the necessary logs, or that logs may be in cold storage, requiring a significant time delay (e.g., more than 10 minutes) to retrieve from a third-party backup.

Resource Constraints: Technical staff often shoulder IT, security, and data provision responsibilities simultaneously, creating cycle conflicts.

The "Hollywood Effect": Technical investigators must manage stakeholder expectations, particularly from executives, who have been "spoiled" by TV shows into believing an attacker can be found in a few hours.

The consensus conclusion is that the greatest value is unlocked by starting the TTX with the technical team and escalating to the executive level with realistic information and validated timeframes.

Operational Hurdles: Access and the Human Element

The conversation shifted to immediate, practical roadblocks encountered during a real IR:

Access is a Catastrophe: External IR teams (like Mandiant) frequently face significant access delays. The assumption that a VDI will suffice is deeply flawed; IR requires God-kind of access to the SIEM, EDR, data lakes, and raw data. A "48-hour delay" to provision access is unacceptable in a crisis. The single most important preparation tip is to pre-provision and test five to six corporate laptops with pre-configured, tested permissions for all core security and cloud platforms (AWS, Azure, Google Cloud).

The Human Element is Paramount: Incident response is a marathon, not a sprint. Analysts pushing themselves for 16-hour shifts for the first three days will have significantly degraded decision-making by day four, leading to finger-pointing and a toxic environment. Effective IR requires leadership to ensure teams (tech, execs, third parties) get rest, nutrition, and downtime to "charge their batteries." This focus on well-being ensures that when they are working, their eight hours are "all magic." As a humorous, yet critical, tactic, the guest noted that food and ice cream can actually serve as an effective incentive for onsite collaboration.

Favorite Cloud Tabletop Scenarios and the AD Connection

The most effective cloud TTXs focus on scenarios that expose common architectural flaws and the interconnected nature of hybrid environments:

Publicly Exposed Secrets: A favorite, and a scenario that has turned into a real incident, involves an attacker finding a Personal Access Token (PAT) on a public GitHub repository and then using tools like TruffleHog to discover further secrets. This shocks executives who mistakenly believe credentials are a prerequisite to a PAT being found.

On-Prem to Cloud Lateral Movement: The most potent and common cloud breach vector is the attacker compromising an on-premise NTDS.dit file (Active Directory database) to obtain password hashes, decrypting them, and then moving into the cloud via Entra ID (formerly Azure AD) to the cloud console. This highlights a critical lack of education and communication between long-time on-prem staff and newer cloud teams, who often believe their environments are separate. This vulnerability is not exclusive to the cloud; it also applies to virtualization platforms like vCenter and ESXi, where attackers can use compromised credentials to encrypt VMDK files directly on the NAS.

Stakeholder Management and the Role of the Project Manager

IR is no longer a purely technical exercise; it involves a complex ecosystem of stakeholders:

The Ecosystem: Investigators, containment/remediation teams, threat intelligence, crisis communications (crucial for managing internal, partner, media, and government messaging), legal, and data review teams (for extortion scenarios).

The Attestation Requirement: Business partners will often only reconnect to the victim's network upon receiving an attestation letter from a trusted third party (e.g., Mandiant) confirming the root cause is found, containment is complete, and the environment is "green."

Empowered Project Managers (PMs): Delays in task completion are the death of an IR effort. The guest strongly advocates for assigning the organization's best, most respected project managers to the IR effort. An empowered PM is essential to ensure critical prerequisites are met and, crucially, to make high-stakes, real-time decisions (like quarantining a server) at 1 AM without having to wait for executive response, thus preventing the attacker from creating new beachheads.

Final Recommendations for Tabletop Success

For successful TTXs, customization and inclusion are key:

Deep Customization: Do not use generic scenarios. Work with the IR team to understand the organization's adversaries (e.g., PLA targeting the energy sector) and its environment. The scenario should include real server names, IP addresses, and data center locations to make the exercise "hit home" and get the technical team's attention.

Inclusion of Legal and Law Enforcement: Legal counsel is necessary to define the line between "watching the attacker" for defensible intel and allowing the exfiltration of consumer data that could result in regulator penalties. Law enforcement (like the FBI) has evolved and can be an asset, potentially securing decryption keys, seizing data from cloud providers, or providing forensic images of the attacker's server—a reward most investigators would happily investigate.

The Need for a Friend: The ultimate value of a TTX is the human connection and trust. Meeting people before the crisis means that in the heat of the moment, the external expert is seen as a friend and an asset rather than an outsider who might put them "under the bus." This comfort is necessary to overcome the chaos and prevent the lingering cost of employee turnover due to mistreatment during a crisis.

📅 Timeline of Key Topics

Introduction and Analogy: Welcome, housekeeping, and the initial discussion framing tabletop exercises (TTX) as essential training before battle and noting the danger of training generals but not troops.

Defining Tabletop Value: Introduction of the military "sweat in peace" quote; establishing TTX as a method for building muscle memory and agreeing on rules before an incident to prevent panic and poor, legally risky decisions.

The Executive TTX Problem: Discussing why tabletops are seen as "elite" and the inherent flaw in high-level executive exercises that rely on unrealistic "magic wand" assumptions about log access and recovery simplicity.

The Technical Reality Check: Highlighting how technical teams reveal the truth about data access (logs may be in cold storage), timeframes, and the need to manage executive expectations, noting that TTX value peaks when the tech team is involved.

First 72 Hours and Business Decisions: Emphasizing the critical nature of the first three days and the difficult decision trade-off between forensic evidence preservation and business recovery (and getting money streams back online).

Access as a Bottleneck: Deep dive into the practical failures of external access, detailing why VDI is insufficient and the best practice of pre-provisioning dedicated IR laptops with tested, full-access permissions.

The Human Element: Focus on IR as a marathon, not a sprint, stressing the importance of rest, nutrition, and managing the human side of the crisis to ensure positive morale and effective decision-making.

Cloud Tabletop Scenarios: Discussion of effective cloud-specific scenarios, including the discovery of Personal Access Tokens on GitHub and, critically, the on-prem to cloud lateral movement via compromised Active Directory credentials.

Stakeholder Complexity and Attestation: Enumerating the growing number of non-technical stakeholders (Legal, Crisis Communications, Data Review, Threat Intel) and the importance of third-party attestation for business recovery.

The Empowered Project Manager: Explaining why the organization's best PMs must be assigned to the IR effort to prevent critical delays, manage task prerequisites, and authorize quarantine actions at any hour.

Closing Tips: Summarizing key recommendations: customization of scenarios (with real server names), mandatory inclusion of Legal and Law Enforcement, and fostering trust and friendship with IR partners to minimize the human cost of an incident.

View more episodes