Do any folks here use table top exercises to refine their incident response runbooks? Why, or why not? Is this idea new to you, or something you're familiar with?
I'm trying to get back in to technical writing, so I've written a bit about my experiences with table top exercises, and ideas that I think are worth sharing.
https://infosec.press/security-through-the-looking-glass/table-top-security-exercises
Feedback is welcome, especially editing. I'm still working on refining my process.

