Cyber tabletop exercise platform

Run tabletop exercises your executives will remember

TableTop Sim turns incident-response practice into a live simulation. Role-specific injects, a facilitator control room, AI that tailors the scenario to the client's real environment, and an after-action report at the end of the session — not a week later.

12+
Ready scenarios
60–120
Minutes per exercise
0
Participant accounts
1
Report, on the day
console.tabletopsim.com — Ransomware in the finance shared drive
03:00

Inject window

Northwind Logistics · Ransomware · Standard

9 / 9 connected
  1. Detection
  2. Triage
  3. Containment
  4. Escalation & Notification
  5. Eradication & Recovery
  6. Public & Legal
  7. Recovery & Lessons
On airstandardCISO laneresponse required

Helpdesk escalation: three users locked out of the finance share

Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.

Inject timeline

  1. 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
  2. 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
  3. 00:23The CFO asks whether to shut down the ERPqueued · CEO
  4. 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
  5. 00:48Trade press calls for comment before your statement is readyqueued · Comms Director

Live response feed

  1. 00:06CISO

    Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.

    Dana W.

Start the clock to watch responses land

This is the real facilitator console — take the full product tour

How it works

Four moves from scenario to signed-off report

The same flow whether you run one exercise a quarter or ten a month.

  1. 01

    Tailor

    Pick a scenario, then let AI reshape injects around the client's real environment — cloud or hybrid, device estate, industry, regulators.

  2. 02

    Launch

    Participants join with a code. No accounts, no installs. Each seat gets a role-specific incident bridge; observers stay view-only.

  3. 03

    Facilitate

    Release injects, pause the clock, read responses live, annotate as you go, and accept AI-improvised injects that react to what was actually said.

  4. 04

    Report

    Close out with a web and PDF after-action report: decisions, lessons learned, recommended alternatives, and hot-wash feedback.

Capabilities

Everything the facilitator needs, nothing the room shouldn't see

AI environment tailoring

Describe the client once. Injects, artefacts, and role prompts are rewritten to match their stack, workforce model, and sector.

Live facilitator control room

One screen for the whole exercise: inject timeline, countdown control, response feed, private facilitator notes, and pause.

Role-based participant views

CEO, CISO, General Counsel, Comms Director and more each see only what their seat would see — including private information.

AI-improvised injects

When the room goes somewhere unexpected, accept a suggested inject that follows the thread instead of forcing the script.

Professional after-action reports

A report your client can circulate to the board — web view plus branded PDF, generated from the exercise record.

Bespoke exercise themes

Mission Control, Corporate, D&D, Cyberpunk or Wardroom, set per organization with per-exercise overrides.

Participant experience

A bespoke incident bridge for every seat at the table

Participants join with a code and land in a room built for their role: their brief, their private information, the shared situation board, and the clock. Observers and note-takers watch without touching the exercise.

tabletopsim.com/join — incident bridge
02:02

Your seat

CEO — Priya S.

9 on the bridge
  1. Detection
  2. Triage
  3. Containment
  4. Escalation & Notification
  5. Eradication & Recovery
  6. Public & Legal
  7. Recovery & Lessons
Switch seat:

Your brief

You own the trading decision. Every hour of ERP downtime costs roughly one day of margin recovery, and your board chair will ask what you knew and when.

Private to this seat

Private to you: the board's risk committee meets tomorrow morning. Your cyber policy has a 24-hour notification clause you have not yet triggered.

No other participant can see this panel

response requiredhot seat

Do you keep shipping running while the blast radius is still unknown?

Type your decision and the reasoning behind it…

Shared situation board

  1. 00:04another role's lane

    CISO received new information

  2. 00:11another role's lane

    IT Operations received new information

  3. 00:23your lane

    The CFO asks whether to shut down the ERP

On the bridge

  • Priya S.CEO
  • Dana W.CISO
  • Alan R.General Counsel
  • Lena K.Comms Director
  • R. Alvarezobserver
  • T. Okaforobserver

Scenario library

Start from a scenario that already holds up under pressure

Every scenario ships with staged injects, role prompts, facilitator notes and artefacts. Tailor it, or build your own from scratch.

Destructive attack

Ransomware Encryption Event

Endpoint encryption spreads from a finance file share into virtual infrastructure while a ransom note demands payment within 48 hours. Backups are partially validated.

Fraud

Business Email Compromise

A spoofed executive thread pushes a same-day wire to a new supplier account. Finance has already released the first payment when the exercise opens.

Insider threat

Malicious Insider

A departing engineer bulk-downloads source code and customer records. HR, legal, and security must coordinate evidence handling without tipping off the individual.

Supply chain

Third-Party / Vendor Compromise

A managed IT provider discloses a breach of the remote access tooling it uses across your estate. Scope is unknown and the vendor is slow to answer.

Identity

Cloud Identity Takeover

MFA fatigue attacks land on a privileged administrator. Conditional access logs show new tenant apps consented and mail rules created.

Extortion

Data Extortion Without Encryption

An actor posts a sample of regulated customer data on a leak site and sets a countdown. Nothing is encrypted, so operations continue as normal.

Who it's for

Built for the people who run the exercise

vCISOs

Deliver a repeatable, premium exercise across a portfolio of clients without rebuilding decks.

MSSPs & MDR providers

Turn incident-response readiness into a productised, multi-tenant service line.

Internal security teams

Run quarterly exercises that executives actually attend — and remember.

Consultants & advisors

Show up with a control room instead of a slide deck, and leave with a report.

Trusted by security leaders and advisory teams

Financial services
Healthcare
Manufacturing
Public sector
SaaS

Start here

New to running tabletop exercises?

Our step-by-step walkthrough covers scoping, the right room, inject design, facilitation under pressure, the hot wash and the after-action report.

Your next exercise can be the one people talk about

Book a 30-minute walkthrough. We'll run a live inject with you and show the report it produces.

Why TableTop Sim exists