Answers · 2026-09-04

Who should attend a cybersecurity tabletop exercise?

TL;DR

A cybersecurity tabletop exercise should include the people who would make decisions, provide specialist advice, communicate and restore operations during the incident being tested. Typical attendees include executive leadership, security, IT, legal, communications, privacy, risk and relevant business owners, with observers or external providers added when their real-world responsibilities justify it.

Abstract graphic representing cross-functional roles connected around an incident

Who should attend a tabletop exercise?

The right attendees are the people who would make or support real decisions during the incident being tested. A useful group usually combines executive authority, technical knowledge, legal and communications advice, and ownership of affected business operations.

Attendance should follow the exercise scope rather than an organisational chart. If the scenario concerns ransomware, for example, invite the people responsible for containment, service restoration, business continuity, legal advice, internal and external communications, and decisions about operational trade-offs.

TableTop Sim supports role-based participant views for roles including CEO, CISO, General Counsel, Communications Director, IT lead and observers. Participants join with a code, without creating accounts or installing software, and enter a role-specific incident bridge.

Core attendee groups

Executive decision-makers

Invite executives who would have authority during a material cyber incident. Depending on the organisation and scenario, that could include the CEO or another executive responsible for the affected operation.

Executive participants should be prepared to decide matters such as:

  • Whether to interrupt or suspend business operations
  • Which organisational priorities take precedence
  • When to escalate internally or externally
  • How to balance recovery, legal and reputational concerns
  • Who has authority when information remains incomplete

The exercise should test how decisions are made, not simply whether executives know technical terminology.

Security and incident response

The CISO, security lead or incident-response lead should normally attend. They interpret the available evidence, coordinate the response and explain technical risk to decision-makers.

Include additional responders only when their responsibilities are relevant to the chosen decision boundary. A focused room is often more useful than inviting every security specialist.

IT and service restoration

IT leaders and infrastructure or application owners should attend when the scenario affects systems, identities, data or service availability. Their role is to explain dependencies, recovery options and the operational consequences of containment decisions.

For a scenario involving a critical platform, include the person who can speak credibly about restoring it. The scenario library can help facilitators select a situation before identifying the necessary technical roles.

Legal, privacy and compliance advisers

General Counsel or another appropriate legal adviser should participate when the scenario could create contractual, litigation, notification or law-enforcement considerations. Privacy specialists should attend when personal data may be involved.

These participants advise the decision-makers; the exercise does not establish regulatory compliance by itself. It can instead reveal where responsibilities, escalation routes or decision criteria need clarification.

Communications

The Communications Director or relevant communications lead should attend when employees, customers, partners, media or other stakeholders may require information. Communications decisions should develop alongside technical and legal work, rather than beginning after the incident has been resolved.

The exercise can test who approves statements, what can be said with limited facts and how different audiences receive updates.

Business and operational owners

Invite the leaders responsible for the business process affected by the scenario. They can explain customer impact, operational priorities, manual workarounds and the consequences of prolonged disruption.

A technically realistic discussion can still fail if nobody represents the service or process the organisation is trying to protect.

Optional attendees

Human resources

HR may be needed when the exercise involves employees, insider activity, workforce communications or personnel decisions. Its involvement should be based on the scenario rather than treated as mandatory for every exercise.

Risk, insurance and third parties

Risk or insurance representatives may add value when the scenario tests escalation, documentation or external coordination. External counsel, incident-response providers, cloud providers, MSSPs, MDR providers or other partners can also attend if they would have a defined role during the real event.

Do not add external parties solely to increase attendance. Give each participant a clear responsibility or designate them as an observer.

Observers and note-takers

Observers can capture decisions, gaps and follow-up actions without taking part in every discussion. Their presence should not prevent participants from speaking candidly.

TableTop Sim provides observer views and private facilitator notes. Its live control room also includes an inject timeline, countdown control, response feed and pause capability, helping the facilitator manage a mixed executive and technical room.

How many people should be invited?

There is no single correct number in the provided methodology. Use the smallest group that represents the necessary authority, expertise and affected operations for the decision boundary being tested.

Before sending invitations, ask:

  • Who can authorise the decisions in scope?
  • Who supplies essential technical, legal or communications advice?
  • Who owns the affected service or process?
  • Which external parties would actually be contacted?
  • Who should observe and record actions rather than participate?

A participant should understand why they are in the room and what decisions they may be asked to make.

Assign roles before the exercise

Brief the room and assign seats before staged injects begin. Clarify the incident lead, decision authority, specialist advisers, operational owners, communications responsibilities and observer boundaries.

Avoid giving participants detailed answers in advance. They need enough context to understand their role, while the exercise should still expose assumptions and coordination problems under pressure. The facilitator guides and exercise walkthrough provide a practical structure for preparation and delivery.

Match attendance to the scenario

Start by scoping one decision boundary, then choose and tailor the scenario. TableTop Sim can rewrite injects to match the organisation's technology stack, workforce model and sector, making it easier to place the selected attendees in a recognisable environment.

During the 60-120 minute exercise, run staged injects with a live clock and apply pressure rather than reading slides. Hold a hot wash immediately afterwards, then issue the web and PDF after-action report with decisions, lessons learned, recommended alternatives, owners and due dates. TableTop Sim generates the report on the day of the exercise.

Related questions

Should executives attend a cybersecurity tabletop exercise?

Yes, when the scenario requires decisions within their authority. Executive participation is most useful when the exercise tests operational trade-offs, escalation, communications or business priorities rather than technical knowledge alone.

Should the CEO attend every tabletop exercise?

Not necessarily. The CEO should attend when the selected decision boundary includes CEO-level authority; otherwise, another executive or business leader may be the appropriate decision-maker.

Which technical roles should attend?

Include the security or incident-response lead and the IT or service owners needed for the scenario. Add specialists only when their expertise is necessary to explain containment, dependencies, recovery options or operational effects.

Should legal and communications teams participate?

They should participate when the incident could involve legal advice, privacy, contracts, external notification or stakeholder communications. Their involvement lets the team test how advice and message approval occur while facts are incomplete.

Can third-party providers join the exercise?

Yes, if they would have a defined responsibility during the real incident. Relevant participants may include external counsel, incident-response providers, cloud providers, MSSPs or MDR providers.

Do participants need TableTop Sim accounts?

No. Participants join TableTop Sim with a code, without creating accounts or installing software, and enter a role-specific incident bridge.

What should observers do during a tabletop exercise?

Observers should capture decisions, lessons and follow-up actions without taking over the response discussion. TableTop Sim supports observer views and private facilitator notes to help separate observation from active participation.

How should attendance decisions be documented?

Record each attendee's role, authority and expected contribution during planning. After the exercise, TableTop Sim can produce a web and PDF report containing decisions, lessons learned, recommended alternatives, owners and due dates.

See it in the product

Scenario library, facilitator control room and after-action reporting — all in the free trial.