Ash Carter (Mandiant)
Stacey Ross (Mandiant)
Jason Pang (Retrospect Labs)


This is a tabletop/discussion based exercises for members interested in incident response and management as CISO (or similar role) or who wish to fill that role in future. Over the course of the workshop (approx. 3 hrs) the group will be walked through a range of situation (otherwise referred to as injects) and provided time to respond to prompting questions. These injects will cover some situations faced by CISO’s before, during and after a breach. After each inject the delivery team will facilitate discussion based on participants responses to prompting questions as well as provide a range of considerations and appropriate responses based on our experience working with organisations and their cyber security leadership across the globe. This will allow members to considers a small range of the different issues, situations and problems that a CISO or similar role faces, building on their experience.
CISO: A senior position who oversees an organisation’s information, cyber, and technology security. The responsibilities include support for designing cybersecurity strategies used to protect corporate data, assess risk across the organisation to improve on its cyber-defences as well as provide direct support to an organisations response before, during and after a breach.
