Incident Response Series Round‑Up: IRP, PIR, Tabletop Exercises & NIST CSF 2.0

Circular NIST CSF 2.0 diagram with a dark‑navy “Govern” center and five equal outer segments labeled Identify, Protect, Detect, Respond, and Recover, each with its own color and icon on a cyber‑themed background.

My interest in incident response started years ago during my first university course on the subject. It was the first time I’d seen how structured, disciplined, and genuinely powerful a well‑designed Incident Response Plan could be. That early exposure stayed with me.

Later, when I began studying NIST CSF 2.0, I noticed something interesting: the new framework reorganised many of the familiar IRP elements, but there wasn’t much guidance on how the old structure translated into the new one. That gap became the starting point for this series.

The first article explores exactly that transition:

Once I mapped the old IRP into CSF 2.0, I realised I could go further. I had previously written a full IRP using the older NIST model, so I rebuilt it properly under the new framework. The result is a complete, modern example:

To support it, I wrote a companion guide that explains each section, how it works, and what belongs in it:

With the IRP foundation in place, the next logical step was documenting the post‑incident process. I created a full Post‑Incident Review based on a fictional scenario, showing how to structure the analysis and extract meaningful lessons:

From there, the series expanded into tabletop exercises using the same fictional scenario. One of the most valuable tools a team can run. I built a complete example scenario, facilitation guide, and all supporting documentation:

These exercises work best when the scenario is tailored to your own environment. Using your real systems, real processes, and real risks forces your team to think deeply about how an incident would unfold in your actual infrastructure.

One of the most challenging parts of NIST CSF 2.0 is navigating its functions, categories, and outcome tags. The official documentation is comprehensive, but not always practitioner‑friendly. To make the framework easier to use, I built a complete reference guide:

Finally, I included a real incident I responded to outside of work, fully anonymised covering a rapidly growing social‑engineering scam:

Writing this series taught me a lot, not just about the frameworks themselves, but about how these documents fit together as a complete, practical toolkit. IRP, PIR, tabletop exercises, AARs, and CSF 2.0 mappings aren’t isolated artefacts; they reinforce each other. Building them side‑by‑side made me appreciate how much clarity and confidence a well‑designed incident response ecosystem can give a team.

If any of these guides help you build your own IRP, PIR, or tabletop exercise, I’d genuinely love to hear how you used them. This series was a rewarding project to create, and I hope it becomes just as useful for you.


Continue Reading the IRP series

How to Write an After Action Report (AAR) for Cyber Tabletop Exercises

How to Run a Cybersecurity Tabletop Exercise: Facilitator Script with Discussion Prompts

How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guide

How to Write a Post-Incident Review (PIR) Report (With Real-World Example)

How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Example

How to Write a Modern Incident Response Plan (IRP) Using NIST CSF 2.0

The Evolution of Incident Response: Updating the Classic NIST IRP to the 2026 Framework

How to Build a Vulnerability Management Program

How to Build a Cyber Aware Workplace Culture

Further Reading: Cyber Security Awareness Series

If this incident taught me anything, it’s that cyber security isn’t about being perfect, it’s about being prepared.

Leave a Comment

Your email address will not be published. Required fields are marked *