The board question I had not rehearsed before my phishing briefing

The incident slide was finished on Tuesday. Four bullets, no logos, the word "contained" used once. One member of staff typed their password into a fake login page, we caught it the same morning, the account was reset, and nothing suggested data had left. I have delivered that slide more times than I would like.

What I had never done was rehearse the part after the slide. The silence, then the chair looking up and asking something. Four minutes on the agenda, between the audit update and lunch, and the only part that matters is the part I do not control.

My team is the wrong audience for this

I know what my deputy would ask, because he asked it in the war room: did we pull the lookalike domain, was the MFA push approved or merely prompted. Good questions. Not board questions.

Our board is not technical and does not pretend to be. Their questions come from a different place: is it over, will it happen again, what did it cost, do we have to tell anyone. Rehearsing with someone from security trains the wrong reflex. The finance director is a fine stand-in, but she knows the real incident, so I cannot test a sanitised version on her, and I get one round in her calendar rather than ten on a Sunday evening.

A board member who is always available

What I ended up using was the page on rewind.ai where you talk to ai voice. No account: the fewer places a rehearsal exists, even a sanitised one, the better. One microphone, one text field for the moments you cannot speak, a choice of voices. Each reply shows up on screen and is spoken at the same time, and you can cut it off mid-sentence, which is more than most board members allow.

The page before you say anything. Nothing to sign, nothing to install.

For the first round I typed, because I wanted my opening on the screen word for word. The brief: play a non-technical board member, hear my opening, then ask the one question a board member would most likely ask, in plain spoken sentences with no lists. Then the opening, stripped to its shape: one of our staff, a fake login page, spotted the same morning, account reset, no sign that data left.

It asked how I had made sure the fake page was not one piece of a wider campaign, and what was now in place to stop it happening again.

My opening and the question it handed back, which was then read out loud.

That is two questions wearing one sentence. The first is about scope. "No sign that data left" answers a question nobody asked; the board wants to know whether this was one person or the first one we noticed. 

The second is about recurrence, and the honest answer is uncomfortable: the next one will get through too, so what changed is how fast we notice and how little a stolen password buys.

My briefing gained two sentences that evening. One on how we checked the blast radius: who else received the mail, who else visited the page, what the sign-in logs said. One on what is different now, named as a control rather than a plan. 

Then the next rounds with the microphone, standing, in the four minutes I would actually have. Hearing a follow-up come back is a different exercise from reading off a slide.

What never goes into an outside tool

The rehearsal needed the shape of the incident, not the incident. A board member's question came out of "one of our staff", "a fake login page" and "last month". It did not need, and did not get, the person's name or department, the lookalike domain, any vendor, the ticket number, the date, how many people received the mail, or anything from the forensic notes.

My rules, for any outside tool, free or licensed, typed or spoken:

  • No names of people, and no roles specific enough to be a name.
  • No system, product or vendor names. "Our identity provider" is enough.
  • No dates, counts or amounts that would let someone match the story to a disclosure.
  • Nothing that is not already in the board pack, and nothing from the forensic report at all.
  • If the sanitised version still feels like something you would redact, it is not sanitised yet.

The voice path is not an exception: spoken words become text somewhere, and you should assume they are kept. The same goes for the assistant your company has licensed; a contract changes who is accountable, not whether the text exists. 

Read your own acceptable use policy before deciding it does not apply to you. You probably wrote it. If it says no outside tool at all, two of the options below need none.

The other ways to rehearse

Option

Asks you a question

Account

Watch out for

Colleague outside security

Yes, good ones

None

Knows the real incident; one round

Phone voice recorder

No

None

Delivery only

PowerPoint Speaker Coach

No

Microsoft account

Delivery only, inside PowerPoint

Yoodli

Yes, role plays

Sign-up

Sold to teams, demo-led

VirtualSpeech

Yes, avatars

Demo or subscription

Team licensing

rewind.ai voice chat

Yes, in the role you give it

None

The first message sets who it plays

I still use the voice recorder for the opening, because I ramble when nervous and a recording does not lie about that. It will never ask me a question, and neither will Speaker Coach, which listens for pacing, filler words and slide-reading, then writes you a report once you have signed in.

Speaker Coach rehearses your delivery inside PowerPoint, after a Microsoft sign-in.

Yoodli has the right idea, role plays with an AI persona, and sells it to teams: Get a Demo twice above the fold, and Try Yoodli Free opens a registration form. Fine if you are buying for a sales floor. Heavy for one briefing.

Yoodli. Role plays with a persona, behind an account, sold to teams.

VirtualSpeech is the same shape with avatars and scored feedback, a demo button first and pricing by team size. There is a subscription for individuals, but that is a training platform bought to rehearse four minutes.

VirtualSpeech. Avatars and scores, a demo first.

Poised was on my list from last year and now carries a banner saying it is shutting down.

How I word the opening now

Tell it who it is, how much it knows, and how it should talk: a non-technical board member, no background beyond my opening, one question at a time, spoken sentences, no lists. Give the sanitised opening in the same message. After you answer, ask whether a board member would be satisfied and what they would ask next. 

Once it works, change the brief and get asked the ones you dread: what would this have cost if you had not noticed, do we have to tell anyone, why did the training not stop it. Do not ask it to check your technical facts. That is your team's job; this exercise is for the other half of the room.

And answer out loud, every time. Typing the answer is a different skill, and it is the one you already have.

The briefing

The chair did not ask about scope. She asked whether the person who typed the password still works for us. I had not rehearsed that, and I am glad the answer was yes and that I said it without a pause. The scope question arrived ten minutes later from the audit committee chair, over coffee, almost word for word. I had it ready, and he looked faintly surprised that I did.

★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

Scott is a Marketing Consultant and Writer. He has 10+ years of experience in Digital Marketing. If you need more information please contact on readdive@gmail.com.

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion