My interest in incident response started years ago during my first university course on the subject. It was the first time I’d seen how structured, disciplined, and genuinely powerful a well‑designed Incident Response Plan could be. That early exposure stayed with me.
Later, when I began studying NIST CSF 2.0, I noticed something interesting: the new framework reorganised many of the familiar IRP elements, but there wasn’t much guidance on how the old structure translated into the new one. That gap became the starting point for this series.
The first article explores exactly that transition:
Once I mapped the old IRP into CSF 2.0, I realised I could go further. I had previously written a full IRP using the older NIST model, so I rebuilt it properly under the new framework. The result is a complete, modern example:
To support it, I wrote a companion guide that explains each section, how it works, and what belongs in it:
With the IRP foundation in place, the next logical step was documenting the post‑incident process. I created a full Post‑Incident Review based on a fictional scenario, showing how to structure the analysis and extract meaningful lessons:
From there, the series expanded into tabletop exercises using the same fictional scenario. One of the most valuable tools a team can run. I built a complete example scenario, facilitation guide, and all supporting documentation:
- How to Write an After Action Report (AAR) for Cyber Tabletop Exercises
- How to Run a Cybersecurity Tabletop Exercise: Facilitator Script with Discussion Prompts
- How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guide
These exercises work best when the scenario is tailored to your own environment. Using your real systems, real processes, and real risks forces your team to think deeply about how an incident would unfold in your actual infrastructure.
One of the most challenging parts of NIST CSF 2.0 is navigating its functions, categories, and outcome tags. The official documentation is comprehensive, but not always practitioner‑friendly. To make the framework easier to use, I built a complete reference guide:
Finally, I included a real incident I responded to outside of work, fully anonymised covering a rapidly growing social‑engineering scam:
Writing this series taught me a lot, not just about the frameworks themselves, but about how these documents fit together as a complete, practical toolkit. IRP, PIR, tabletop exercises, AARs, and CSF 2.0 mappings aren’t isolated artefacts; they reinforce each other. Building them side‑by‑side made me appreciate how much clarity and confidence a well‑designed incident response ecosystem can give a team.
If any of these guides help you build your own IRP, PIR, or tabletop exercise, I’d genuinely love to hear how you used them. This series was a rewarding project to create, and I hope it becomes just as useful for you.
Continue Reading the IRP series
How to Write an After Action Report (AAR) for Cyber Tabletop Exercises
How to Run a Cybersecurity Tabletop Exercise: Facilitator Script with Discussion Prompts
How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guide
How to Write a Post-Incident Review (PIR) Report (With Real-World Example)
How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Example
How to Write a Modern Incident Response Plan (IRP) Using NIST CSF 2.0
The Evolution of Incident Response: Updating the Classic NIST IRP to the 2026 Framework
How to Build a Vulnerability Management Program
How to Build a Cyber Aware Workplace Culture
Further Reading: Cyber Security Awareness Series
If this incident taught me anything, it’s that cyber security isn’t about being perfect, it’s about being prepared.
- ATO Tax Scams: How to Spot One and What to Look Out For– Tax season is when Australians are most vulnerable to scams, and scammers know it.
- “Hi Dad, I Dropped My Phone”: How a Simple Text Stole $3600 And Why This Scam Is Exploding – A complete breakdown of the “Hi Dad / Hi Mum” text message scams
- The Toll Scam Text Message That Hit Me Inside the Tunnel– A practical guide to recognising and avoiding toll‑text message scams.
- Social Media Privacy Reset – A step-by-step guide to tightening your social media privacy settings.
- Think Before You Click – How to recognise suspicious links, messages, and online traps before you fall for them.
- Strong Authentication Made Simple – A clear breakdown of MFA, why it matters, and how to set it up properly.
- Everyday Device Protection – Simple settings and habits that harden your phone and laptop against common threats.
- Travel Cyber Security Tips – How to stay secure on public Wi-Fi, in airports, hotels, and while exploring abroad.
- Introducing Everyday Cyber Security – The origin of the series and the philosophy behind making cyber security accessible.


