Author

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

  • Cyber, forensics, and incident-response practitioners
  • Court-appointed neutrals and testifying experts
Editorial illustration for the article "OT and IT incident response are not the same discipline".OT & plant floor

OT and IT incident response are not the same discipline

OT incident response differs from IT because plant-floor containment steps like isolation and shutdown can create physical safety risk. Here is how exercises should reflect that.

September 9, 2026Read more
Editorial illustration for the article "What belongs in a cybersecurity after-action report".Guides

What belongs in a cybersecurity after-action report

A cybersecurity after-action report template turns a tabletop exercise into a defensible record when it names objectives, findings, and owned corrective actions with dates.

September 7, 2026Read more
Editorial illustration for the article "How to test an incident response plan so it holds under pressure".Incident response

How to test an incident response plan so it holds under pressure

A practical explanation of incident response plan testing methods, from plan read-throughs to tabletops to full functional exercises, and when each fits.

August 31, 2026Read more
Editorial illustration for the article "How to run a third-party vendor breach tabletop exercise".Scenarios

How to run a third-party vendor breach tabletop exercise

A practical guide to designing and running a discussion-based tabletop exercise around a compromised software supplier, focused on contractual notification, isolation, and evidence preservation.

August 19, 2026Read more
Editorial illustration for the article "How to run an insider threat tabletop exercise for a departing employee".Guides

How to run an insider threat tabletop exercise for a departing employee

A practical guide to designing and running an insider threat tabletop exercise built around the departing employee, focusing on coordination among human resources, legal, and security.

August 19, 2026Read more
Editorial illustration for the article "The SEC cybersecurity disclosure rules and what boards must be ready to say".Regulatory

The SEC cybersecurity disclosure rules and what boards must be ready to say

An examination of how the SEC's four-business-day materiality clock and annual governance disclosures have reshaped board-level cyber readiness, including the personal liability exposure directors now face.

August 19, 2026Read more
Editorial illustration for the article "What NYDFS Section 500.16 requires for incident-response testing".Regulatory

What NYDFS Section 500.16 requires for incident-response testing

A plain reading of the NYDFS Part 500.16 annual testing obligation for incident response plans, including the expectation that staff and management critical to the response take part.

August 11, 2026Read more
Editorial illustration for the article "Hong Kong's first ransomware fine puts cybersecurity control failures on the regulatory ledger".Regulatory

Hong Kong's first ransomware fine puts cybersecurity control failures on the regulatory ledger

The Securities and Futures Commission's first ransomware-related enforcement action against a licensed broker signals that weak cybersecurity controls now carry a priced regulatory liability for financial firms.

August 7, 2026Read more
Editorial illustration for the article "Running a business email compromise tabletop exercise that forces the wire-transfer decision".Scenarios

Running a business email compromise tabletop exercise that forces the wire-transfer decision

A practical walkthrough for building and running a business email compromise tabletop exercise that forces the wire-transfer decision and carries a leadership team through the recovery path.

August 4, 2026Read more
Editorial illustration for the article "When hackers hit water: legal and response lessons from the Minnesota utility attacks".OT & plant floor

When hackers hit water: legal and response lessons from the Minnesota utility attacks

A coordinated cyberattack that disrupted operational technology at more than 30 Minnesota water utilities shows how nation-state targeting of control systems reshapes legal, regulatory, and incident-response obligations.

July 31, 2026Read more
Illustration of scales of justice and a shield over a legal document.Privilege

When is a cybersecurity assessment discoverable? Privilege and tabletop exercises

Whether a candid tabletop record can be subpoenaed later depends on how the exercise is structured. How privilege over security work actually functions, and where courts have said it breaks.

July 28, 2026Read more
Illustration of a padlocked server rack with a countdown, a ransomware readiness drill.Scenarios

How to run a ransomware tabletop exercise

A practical walkthrough of a ransomware tabletop: the scenario, the injects that force real decisions, the roles in the room, and the payment and disclosure calls leaders most often get wrong.

July 27, 2026Read more
Illustration of a conference table and a rising framework scorecard grid.Guides

The complete guide to cybersecurity tabletop exercises

What a cybersecurity tabletop exercise is, why boards, regulators, and insurers now expect it, what separates an exercise that changes behavior from one that does not, and how to turn the result into a defensible record.

July 26, 2026Read more
Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.