Complete guide
Cybersecurity tabletop exercises
A cybersecurity tabletop exercise is a discussion-based rehearsal of a cyber incident. Injects arrive in stages, each seat makes the decisions they would make for real, and nothing touches production. Done well, it is the cheapest way to find out that your incident-response plan names an authority who no longer works here.
On this page
What a cyber tabletop exercise actually tests
Not whether the plan exists. Whether the room can use it while information is incomplete and the clock is running.
Authority
Who can declare an incident, approve downtime, or start a regulatory notification clock — and whether that person is reachable.
Shared facts
Whether Security, Legal and Communications are working from the same understanding of what has happened and what has leaked.
Assumptions
The ones nobody states out loud: that backups restore, that the vendor will confirm, that the insurer has been told.
Sequencing
Whether containment destroys the evidence you later need to determine scope and satisfy notification thresholds.
Running order
A 90-minute exercise, phase by phase
The seven phases TableTop Sim uses map to how real incidents escalate.
- 01
Detection
Ambiguous signals. Who declares, and how fast?
- 02
Triage
Scope, evidence and the first technical artefact that contradicts an assumption.
- 03
Containment
Isolate now or preserve evidence first — and who owns that trade.
- 04
Escalation & notification
The regulatory clock, the insurer, the board, the customer contract.
- 05
Eradication & recovery
Backup integrity, rebuild order, and what 'recovered' means.
- 06
Public & legal
Press, leak site, employees posting publicly, counsel's constraints.
- 07
Recovery & lessons
Hot wash, confidence scoring, owned and dated actions.
Step-by-step detail lives in how to run a tabletop exercise, and a copyable structure in the tabletop exercise template.
In practice
This is what running one looks like
The facilitator console from a sample ransomware exercise. Start the clock and release an inject.
Inject window
Northwind Logistics · Ransomware · Standard
- Detection
- Triage
- Containment
- Escalation & Notification
- Eradication & Recovery
- Public & Legal
- Recovery & Lessons
Helpdesk escalation: three users locked out of the finance share
Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.
Inject timeline
- 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
- 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
- 00:23The CFO asks whether to shut down the ERPqueued · CEO
- 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
- 00:48Trade press calls for comment before your statement is readyqueued · Comms Director
Live response feed
- 00:06CISO
Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.
Dana W.
Start the clock to watch responses land
Scenarios
Which scenario should you run?
Choose by the decision you want tested, not by the threat that is in the news.
Destructive attack
Ransomware Encryption Event
Endpoint encryption spreads from a finance file share into virtual infrastructure while a ransom note demands payment within 48 hours. Backups are partially validated.
Fraud
Business Email Compromise
A spoofed executive thread pushes a same-day wire to a new supplier account. Finance has already released the first payment when the exercise opens.
Insider threat
Malicious Insider
A departing engineer bulk-downloads source code and customer records. HR, legal, and security must coordinate evidence handling without tipping off the individual.
Supply chain
Third-Party / Vendor Compromise
A managed IT provider discloses a breach of the remote access tooling it uses across your estate. Scope is unknown and the vendor is slow to answer.
Identity
Cloud Identity Takeover
MFA fatigue attacks land on a privileged administrator. Conditional access logs show new tenant apps consented and mail rules created.
Extortion
Data Extortion Without Encryption
An actor posts a sample of regulated customer data on a leak site and sets a countdown. Nothing is encrypted, so operations continue as normal.
By sector
Sector-specific tabletop exercises
Regulators, stakes and realistic injects differ by industry. Start where you operate.
FAQ
Cybersecurity tabletop exercise questions
- What is a cybersecurity tabletop exercise?
- A cybersecurity tabletop exercise is a discussion-based rehearsal in which executives and responders work through a realistic cyber incident under time pressure. Injects deliver new information in stages, participants make and record the decisions they would make for real, and no production systems are touched.
- How long does a cybersecurity tabletop exercise take?
- Most executive exercises run 60 to 120 minutes, with 90 minutes the practical sweet spot. Technical or multi-team exercises can run half a day.
- How often should we run cyber tabletop exercises?
- Quarterly for the core incident-response team and at least annually for executive leadership. Many regulated organisations must show documented annual testing as a minimum.
- Who should be in the room?
- Anyone who owns a real decision: executive leadership, the CISO or incident commander, IT operations, legal or privacy, communications, and the operational, clinical or plant leadership relevant to your sector. Everyone else attends as an observer.
- Do tabletop exercises satisfy compliance requirements?
- For many frameworks — including NIST SP 800-61 and 800-84 guidance, ISO 27035, HIPAA, PCI DSS and CMMC — a documented tabletop with objectives, participants, findings and an action plan is accepted evidence of incident-response testing. Confirm your specific obligations, as some regimes also expect functional testing.
- What is the difference between a tabletop exercise and a simulation?
- A tabletop exercise is discussion-based and touches no systems. A functional simulation exercises some tooling and processes, and a cyber range or live-fire test uses real or replica infrastructure. Tabletops are the only format senior executives reliably attend, which is what makes them high leverage.
Go deeper
Related guides
9 min read
How to Run a Cybersecurity Tabletop Exercise
8 min read
Cybersecurity Tabletop Exercise Scenarios That Hold Up Under Pressure
10 min read
Ransomware Tabletop Exercise: Full Scenario Walkthrough
7 min read
Incident Response Tabletop Exercises: What They Are and Why They Work
6 min read
Cybersecurity Tabletop Exercise Template
6 min read
