Law & Forensics Editorial
Editorial team, Law & Forensics
The editorial team at Law & Forensics, the firm behind Tabletop.ai.
- Cyber, forensics, and incident-response practitioners
- Court-appointed neutrals and testifying experts
OT & plant floorOT and IT incident response are not the same discipline
OT incident response differs from IT because plant-floor containment steps like isolation and shutdown can create physical safety risk. Here is how exercises should reflect that.
GuidesWhat belongs in a cybersecurity after-action report
A cybersecurity after-action report template turns a tabletop exercise into a defensible record when it names objectives, findings, and owned corrective actions with dates.
Incident responseHow to test an incident response plan so it holds under pressure
A practical explanation of incident response plan testing methods, from plan read-throughs to tabletops to full functional exercises, and when each fits.
ScenariosHow to run a third-party vendor breach tabletop exercise
A practical guide to designing and running a discussion-based tabletop exercise around a compromised software supplier, focused on contractual notification, isolation, and evidence preservation.
GuidesHow to run an insider threat tabletop exercise for a departing employee
A practical guide to designing and running an insider threat tabletop exercise built around the departing employee, focusing on coordination among human resources, legal, and security.
RegulatoryThe SEC cybersecurity disclosure rules and what boards must be ready to say
An examination of how the SEC's four-business-day materiality clock and annual governance disclosures have reshaped board-level cyber readiness, including the personal liability exposure directors now face.
RegulatoryWhat NYDFS Section 500.16 requires for incident-response testing
A plain reading of the NYDFS Part 500.16 annual testing obligation for incident response plans, including the expectation that staff and management critical to the response take part.
RegulatoryHong Kong's first ransomware fine puts cybersecurity control failures on the regulatory ledger
The Securities and Futures Commission's first ransomware-related enforcement action against a licensed broker signals that weak cybersecurity controls now carry a priced regulatory liability for financial firms.
ScenariosRunning a business email compromise tabletop exercise that forces the wire-transfer decision
A practical walkthrough for building and running a business email compromise tabletop exercise that forces the wire-transfer decision and carries a leadership team through the recovery path.
OT & plant floorWhen hackers hit water: legal and response lessons from the Minnesota utility attacks
A coordinated cyberattack that disrupted operational technology at more than 30 Minnesota water utilities shows how nation-state targeting of control systems reshapes legal, regulatory, and incident-response obligations.
PrivilegeWhen is a cybersecurity assessment discoverable? Privilege and tabletop exercises
Whether a candid tabletop record can be subpoenaed later depends on how the exercise is structured. How privilege over security work actually functions, and where courts have said it breaks.
ScenariosHow to run a ransomware tabletop exercise
A practical walkthrough of a ransomware tabletop: the scenario, the injects that force real decisions, the roles in the room, and the payment and disclosure calls leaders most often get wrong.
GuidesThe complete guide to cybersecurity tabletop exercises
What a cybersecurity tabletop exercise is, why boards, regulators, and insurers now expect it, what separates an exercise that changes behavior from one that does not, and how to turn the result into a defensible record.
Make cyber readiness a board-visible program.
Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.