// Comparison

Cybersecurity Tabletop Exercises vs Incident Response and Computer Forensics: Which Should You Read?

Two cybersecurity books on Incident Response, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52024
Cybersecurity Tabletop Exercises

From Planning to Execution

Robert Lelewski, John Hollenberger

Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.

Intermediate
4/52014
Incident Response and Computer Forensics

Jason T. Luttgens, Matthew Pepe, Kevin Mandia

Luttgens, Pepe, and Mandia's working playbook for running an enterprise IR engagement: pre-engagement readiness, evidence acquisition, network and host forensics, and the project-management discipline that separates a controlled response from a panic.

Read this if

Incident responders, security managers, and anyone tasked with improving an organization's readiness who needs to actually run a tabletop, not just read about why they matter. Includes ready-to-adapt scenarios, injects, and storyboards for technical, executive, and cross-functional exercises.
Junior-to-senior incident responders, SOC leads, and CISOs who need the canonical cross-discipline reference for what a real IR program looks like end to end. Strongest as a structural primer — the maturity model implicit in the book is still the field's de facto baseline.

Skip this if

Readers looking for incident-response technique itself (forensics, containment, eradication); this book is about rehearsing and testing a response plan, not executing one. Pair with Incident Response and Computer Forensics or Intelligence-Driven Incident Response for that side.
Readers wanting current tradecraft on identity-attack response (AAD, OAuth abuse, golden SAML), cloud-IR specifically, or modern EDR-driven hunting; the book is largely on-prem 2014. Pair with cloud-IR-specific resources (Mandiant blog, AWS / Azure incident-response runbooks) for the missing layer.

Key takeaways

  • Splits cleanly into process (how to plan, facilitate, and evaluate an exercise) and content (ready-made scenarios across technical, executive, and cross-functional levels).
  • Facilitation technique gets real attention — keeping participants engaged is treated as a skill, not an afterthought.
  • Evaluation and follow-up are covered as seriously as the exercise itself, closing the loop that many tabletop efforts skip.
  • Readiness is the engagement: most of what determines the outcome of an IR is decided before the call comes in.
  • The acquire-then-analyze discipline still holds; cutting that corner is what produces the bad-headline retrospectives.
  • The book's project-management chapters are the underrated half — most failed responses are management failures, not technical ones.

How they compare

Cybersecurity Tabletop Exercises and Incident Response and Computer Forensics are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

Cybersecurity Tabletop Exercises and Incident Response and Computer Forensics both cover Incident Response, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics