This month in Harvard Business Review, we finally get a case study that applies to Information Assurance! “Boss, I Think Someone Stole Our Customer Data” ($4 PDF) tells a story that many CEOs fear, and some can give you a first hand account about–a breach of customer data.

While the case study does speak in some general terms, it is an excellent table-top exercise to run through during your regularly scheduled incident response plan test. This exercise should include various functional groups such as Legal and Marketing in addition to the traditional security or information technology employees. The case study is written in general terms, and can be used multiple times as the law changes.

