Author a SOC 2-Ready Incident Response Playbook for Kestrel Pay
Overview
What this challenge is about.
Write a four-phase SOC 2-ready incident playbook for a fintech card issuer, then run two tabletop exercises. Get a verifiable certificate.
The scenario
Kestrel Pay is a London-based Series-B financial technology firm of about 240 people whose business-to-business platform issues payment cards for client companies and processes roughly USD 80 million in card spend monthly, putting it under SOC 2 Type II and payment-industry scrutiny. Like many fast-scaling fintechs, its engineering maturity has outpaced its security governance, leaving incident response as undocumented tribal knowledge.
The Brief
What you'll do, and what you'll demonstrate.
Kestrel Pay must turn an undocumented, Slack-pinned incident process into a NIST-aligned, tabletop-validated incident-response playbook that satisfies a SOC 2 Type II auditor and is genuinely usable by an on-call engineer at 3am.
Earning criteria — what you'll demonstrate
- Translate the NIST SP 800-61r2 incident lifecycle into operational, role-specific procedures for a regulated fintech
- Map incident-response controls to SOC 2 CC7-series Trust Services Criteria so they are audit-traceable
- Design and facilitate tabletop exercises that surface real coordination gaps, then iterate documentation from the findings
- Engineer operational documentation for usability under stress (3am on-call) rather than for completeness alone
- Communicate severity, escalation, and customer/regulator notification decisions clearly across technical and non-technical stakeholders
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Incident Response
Apply incident response to solve real industry problems and demonstrate production-level capability.
- Nist Sp 800 61
Apply nist sp 800 61 to solve real industry problems and demonstrate production-level capability.
- Security Governance
Apply security governance to solve real industry problems and demonstrate production-level capability.
- Compliance
Apply compliance to solve real industry problems and demonstrate production-level capability.
- Tabletop Exercise
Apply tabletop exercise to solve real industry problems and demonstrate production-level capability.
- Stakeholder Communication
Apply stakeholder communication to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Incident Response Engineer
This challenge builds the core craft of an IR engineer: turning a recognized standard into runnable procedures, validating them under simulated pressure, and ensuring on-call teams can execute when a real incident hits a payments platform.
This challenge sharpens
- incident-response
- nist-sp-800-61
- tabletop-exercise
Security Governance & Compliance Lead
Mapping controls to SOC 2 criteria and producing auditor-ready, traceable documentation mirrors the daily work of a governance lead who must satisfy auditors while keeping security operational and defensible.
This challenge sharpens
- security-governance
- compliance
- nist-sp-800-61
Security Program Manager
Coordinating engineering, customer-success, and legal stakeholders through tabletop exercises and clear escalation trees develops the cross-functional communication and program ownership a security PM needs to drive readiness on a deadline.
This challenge sharpens
- stakeholder-communication
- tabletop-exercise
- incident-response