Network Security Status Tracker
Overview
The Network Security Status Tracker is a simple but powerful tool for Incident Masters to maintain session momentum and provide clear feedback on team performance. This visual tracking system helps both facilitators and players understand the evolving security situation and the impact of their decisions.
How to Use This Tool
Before the Session
- Print one copy for yourself as the IM - this is your tracking reference
- Consider making the status visible to players via whiteboard or projected display
- Review status definitions to ensure consistent application during the session
- Start with realistic initial conditions - not all sessions begin at βSecureβ
During the Session
- Update immediately when player actions warrant status changes
- Announce changes to maintain tension: βYour quick response has improved our IR Effectiveness to βGoodββ
- Use as pacing tool - status changes create natural session rhythm
- Document key moments for post-session discussion and learning reinforcement
Status Change Triggers
Network Security Status Changes: - Secure β Monitored: First threat indicators discovered - Monitored β Compromised: Active malicious activity confirmed - Compromised β Critical: Threat spreads or achieves major objectives - Critical β Compromised: Effective containment actions implemented - Any status β Previous: Successful remediation or false positive identified
IR Effectiveness Tracking: - Improve status when team demonstrates good communication, role clarity, or collaborative problem-solving - Maintain status during steady, competent performance - Reduce status when team shows confusion, poor communication, or role conflicts
Quick Reference Tracking Sheet
Print this section and use during sessions to track the evolving security situation.
NETWORK SECURITY STATUS TRACKER
Session Info:
- Scenario: ____________________
- Malmon: ____________________
- Date: ____________________
Current Status (Check one box per track)
Network Security:
Incident Response Effectiveness:
Business Operations Impact:
Session Notes
Current Threat Indicators:
_________________________________________________
_________________________________________________
_________________________________________________
Key Player Discoveries:
_________________________________________________
_________________________________________________
_________________________________________________
Pending Team Decisions:
_________________________________________________
_________________________________________________
_________________________________________________
Status Change Log:
Time: _____ Network: _________ β _________
Reason: _____________________________________
Time: _____ IR Effectiveness: _____ β _____
Reason: _____________________________________
Time: _____ Business Ops: _______ β _______
Reason: _____________________________________
Quick IM Reminders
- Update based on player actions, not arbitrary timing
- Show status changes to players - make consequences visible
- Use status to drive tension - βWe just moved to Criticalβ¦β
- Reward effective teamwork with improved IR Effectiveness
- Keep it simple - quick updates, stay focused on facilitation