This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Beyond Prevention: Building a Culture of Incident Readiness in the Modern Enterprise

Download resources

About this session

Sabine Lainer, a governance, risk and compliance specialist who reviews and rebuilds incident response plans for a living, argues that most IRPs she sees are outdated paperweights, thick with textbook definitions of an incident instead of clear, immediate instructions. Tracing incident response from the 1970s to today's AI-driven, automated attacks, she catalogs what makes modern readiness hard: distributed and legacy systems side by side, heavy third-party dependency, alert fatigue, siloed teams, and a regulatory landscape spanning Quebec's Law 25, GDPR, HIPAA, NIS2 and DORA. Using Apollo 13's paper runbooks as a model, she insists an IRP should read like a fire-extinguisher label, pull the pin, point, press, not a narrative, and should sit alongside separate playbooks, contact lists, out-of-band communication plans, and deputization for every key role so one absent person cannot collapse the response. In an extended Q&A, she walks through designing tabletop exercises at different levels, short and checklist-driven for boards and executives, technical for IT, and role-shuffled scenarios that pull departments like HR and marketing into the exercise instead of leaving cybersecurity to handle everything alone.

In today’s hyper-connected digital landscape, the question is no longer if a security incident will occur, but when. Despite significant investments in prevention technologies, many organizations remain underprepared to respond effectively when incidents strike. This presentation will explore the critical importance of incident readiness as a core component of a resilient cybersecurity strategy. Attendees will gain insights into: The evolving threat landscape and why traditional prevention-first approaches are no longer sufficient. The business and reputational costs of poor incident response. Key components of an effective incident readiness program, including playbooks, simulations, cross-functional coordination, and executive engagement. Real-world case studies highlighting both failures and successes in incident response. Practical steps organizations can take to assess and improve their current readiness posture. This session is designed for security leaders, IT professionals, risk managers, and executives who are looking to strengthen their organization’s ability to respond swiftly and effectively to cyber incidents. Join us to learn how to shift from reactive to proactive, and turn incident readiness into a strategic advantage.

Key takeaways

  • Write the IRP itself like a fire-extinguisher label, direct action steps only, and move all definitions, examples, and background material into separate training documents.
  • Assign a deputy for every critical role, technical and executive, and test what happens when your key incident responder is genuinely unreachable, not just theoretically absent.
  • Maintain an out-of-band communication plan (a second domain, an alternate conferencing tool) and rehearse it, since your primary channel may be exactly what the attacker controls.
  • Map your third-party and tooling dependencies like API contracts: document what data flows where, who activates what, and under what conditions, before you need it under pressure.
  • Run different tabletop formats for different audiences: short checklist-driven simulations for the board and executives, technical root-cause scenarios for IT, and role-shuffled exercises that force other departments like HR to participate.

Speakers

Sabine Lainer
Sabine Lainer
Governance, Risk and Compliance · GoSecure
Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University… Read moreRead less

Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University of South Australia; McGill University; Concordia University; and the University of Alberta. Sabine is passionate about security, privacy, learning, and teaching. She was awarded an innovative teaching prize in 1997 and was nominated for the Women in IT Award – Security Champion in the UK in 2016. Having lived and worked in nine countries, Sabine is now a proud permanent resident of Canada. Outside of her professional life, Sabine enjoys running, cycling, hiking, paddle boarding, and indulging in science fiction and fantasy stories through various media. A dedicated Star Trek fan, she takes great pride in living in the birthplace of William Shatner.

Resources

Tags

More from GoSec 2025

Also from Sabine Lainer

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.