Insider threat cases
Insider Case Tabletop Intensive
This intensive uses a single evolving storyline so teams experience how decisions compound. IT, security, and business stakeholders each receive partial information, mirroring real operations. The goal is a calmer tempo, clearer activity logs, and fewer contradictory statements in status updates.
- Duration
- 2 days, hybrid
- Format
- Hybrid cohort
- Program fee (informational)
- ₩1,320,000
- Start window
- 2026-09-02
Outcomes
- A tabletop format your org can rerun quarterly with new injects
- Tighter alignment between help desk, IAM, and security leads
- More disciplined language in written updates during sensitive weeks
| Capability | What you practice |
|---|---|
| Module 1 | Role-based information packets updated between rounds |
| Module 2 | Structured decision log for leadership visibility |
| Module 3 | Breakouts for legal-adjacent phrasing without giving legal advice |
| Module 4 | Artifact request list templates aligned to internal ticketing |
| Module 5 | Quiet-room exercises for drafting cautious updates |
| Module 6 | Hotwash focused on communication failure modes |
| Module 7 | Follow-up reading on proportionality and scope creep |
Lead facilitator
Sora Kim
Incident response coach specializing in cross-org workflow alignment.
FAQ
No. We scale participant counts and inject complexity to match your org size while keeping the same narrative backbone.
We simulate reviewer-style questions as prompts only. Organizations should involve their own counsel for binding guidance.
The storyline is synthetic. Your internal context will still require customization of comms templates after the course.
Participant notes
“The decision log idea landed well with leadership. The second day felt dense; a slightly longer break would help.”
“Useful comms guardrails. We scheduled a private rerun for another business unit.”