Structured IR Tabletops Led by a Practitioner
Incident Response Tabletop Facilitator
A tabletop is only as useful as the person running it. After 150+ exercises spanning state agencies, hospital systems, manufacturers, and Fortune 500 enterprises, patterns emerge: the real failures happen in decision rights, escalation paths, and legal coordination, not in the playbook itself. Sessions are built around NIST SP 800-61 phases and mapped to MITRE ATT&CK techniques so participants leave with findings that map cleanly into their existing program.
Quick Answer
{{quickAnswer}}
Last updated: April 2026 · Verified by Mark Lynd, 5x CIO/CISO with 25+ years of experience
Keynote Topics
Executive-Level IR Tabletops
Designed for CEO, CFO, General Counsel, and board members. The scenarios force decisions on public disclosure, ransom posture, regulator notification, and stakeholder communications. No technical jargon, just the decisions leadership actually owns.
Best for: Executive teams, board audit committees, C-Suite offsites
Duration: 3-4 hours
Technical IR Tabletops for SOC and IR Teams
Built around realistic MITRE ATT&CK kill chains with injects that test detection, containment, and forensic preservation. Participants work through log analysis, EDR telemetry, and coordination with threat intel in compressed time windows.
Best for: SOC analysts, IR teams, threat hunters
Duration: Half-day or full-day
Board-Level Crisis Simulations
A specialized format for directors who need to rehearse their oversight role during a live incident. Covers the information they should demand, the questions to ask management, and the fiduciary decisions only the board can make.
Best for: Public and private company boards, director education
Duration: 90 minutes to half-day
{{quotablePull}}
— Mark Lynd, 5x CIO/CISO, Head of Executive Advisory & Strategy at Netsync
Why Teams Bring in Mark for IR Tabletops
150+ exercises delivered. Deep pattern recognition on what actually breaks during an incident.
NIST SP 800-61 and MITRE ATT&CK aligned. Findings map to frameworks your program already uses.
SLED, commercial, and enterprise experience. Scenarios calibrated to your sector and threat model.
Facilitator who has been the CISO. Five times over. Participants are not being coached by a consultant who has never had to make the call.
Written after-action report. Gap analysis, prioritized remediation, and a replay plan, not just a summary email.
Where Has Mark Spoken?
According to venue records, Mark has delivered keynotes at: RSA Conference · Oracle CloudWorld · Cisco Partner Summit · Dell Technologies World · IBM Think · T-Mobile Events · Gartner Security & Risk · InfoSecurity · ISACA Conferences · ISSA Events · Cloud Security Alliance · CyberSecurity Summit · BSides · FLGISA · MISAC · SMU Cox School of Business · and 100+ more.
How Do You Book Mark Lynd for Your Event?
The booking process is straightforward and typically completes within 3 business days. Mark customizes every keynote to the audience, industry, and event objectives.
- Submit an inquiry. Fill out the contact form with your event date, audience, and objectives. Response within 48 hours.
- 15-minute discovery call. Discuss your event in detail, including audience makeup, key messages, and desired outcomes.
- Proposal & contract. Receive a tailored proposal with format options (keynote, workshop, panel), fee, and travel terms.
- Customization. Mark customizes content to your audience, industry examples, and desired takeaways.
- Expert delivery. Mark brings 25+ years of real-world executive experience to every stage.
Frequently Asked Questions
How long does an incident response tabletop typically run?
Who should participate in the tabletop?
What deliverables come out of the engagement?
Are tabletops delivered remote or on-site?
Ready to Book Mark?
Mark customizes every keynote to the audience, industry, and event objectives. Contact the booking team to check availability.
Fee range: $12,000 – $30,000+
Formats: In-person, virtual, hybrid
Duration: 30–120 minutes depending on format