Complete guide

Cybersecurity tabletop exercises

A cybersecurity tabletop exercise is a discussion-based rehearsal of a cyber incident. Injects arrive in stages, each seat makes the decisions they would make for real, and nothing touches production. Done well, it is the cheapest way to find out that your incident-response plan names an authority who no longer works here.

On this page

What a cyber tabletop exercise actually tests

Not whether the plan exists. Whether the room can use it while information is incomplete and the clock is running.

Authority

Who can declare an incident, approve downtime, or start a regulatory notification clock — and whether that person is reachable.

Shared facts

Whether Security, Legal and Communications are working from the same understanding of what has happened and what has leaked.

Assumptions

The ones nobody states out loud: that backups restore, that the vendor will confirm, that the insurer has been told.

Sequencing

Whether containment destroys the evidence you later need to determine scope and satisfy notification thresholds.

Running order

A 90-minute exercise, phase by phase

The seven phases TableTop Sim uses map to how real incidents escalate.

  1. 01

    Detection

    Ambiguous signals. Who declares, and how fast?

  2. 02

    Triage

    Scope, evidence and the first technical artefact that contradicts an assumption.

  3. 03

    Containment

    Isolate now or preserve evidence first — and who owns that trade.

  4. 04

    Escalation & notification

    The regulatory clock, the insurer, the board, the customer contract.

  5. 05

    Eradication & recovery

    Backup integrity, rebuild order, and what 'recovered' means.

  6. 06

    Public & legal

    Press, leak site, employees posting publicly, counsel's constraints.

  7. 07

    Recovery & lessons

    Hot wash, confidence scoring, owned and dated actions.

Step-by-step detail lives in how to run a tabletop exercise, and a copyable structure in the tabletop exercise template.

In practice

This is what running one looks like

The facilitator console from a sample ransomware exercise. Start the clock and release an inject.

console.tabletopsim.com — Ransomware in the finance shared drive
03:00

Inject window

Northwind Logistics · Ransomware · Standard

9 / 9 connected
  1. Detection
  2. Triage
  3. Containment
  4. Escalation & Notification
  5. Eradication & Recovery
  6. Public & Legal
  7. Recovery & Lessons
On airstandardCISO laneresponse required

Helpdesk escalation: three users locked out of the finance share

Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.

Inject timeline

  1. 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
  2. 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
  3. 00:23The CFO asks whether to shut down the ERPqueued · CEO
  4. 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
  5. 00:48Trade press calls for comment before your statement is readyqueued · Comms Director

Live response feed

  1. 00:06CISO

    Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.

    Dana W.

Start the clock to watch responses land

Scenarios

Which scenario should you run?

Choose by the decision you want tested, not by the threat that is in the news.

Destructive attack

Ransomware Encryption Event

Endpoint encryption spreads from a finance file share into virtual infrastructure while a ransom note demands payment within 48 hours. Backups are partially validated.

Fraud

Business Email Compromise

A spoofed executive thread pushes a same-day wire to a new supplier account. Finance has already released the first payment when the exercise opens.

Insider threat

Malicious Insider

A departing engineer bulk-downloads source code and customer records. HR, legal, and security must coordinate evidence handling without tipping off the individual.

Supply chain

Third-Party / Vendor Compromise

A managed IT provider discloses a breach of the remote access tooling it uses across your estate. Scope is unknown and the vendor is slow to answer.

Identity

Cloud Identity Takeover

MFA fatigue attacks land on a privileged administrator. Conditional access logs show new tenant apps consented and mail rules created.

Extortion

Data Extortion Without Encryption

An actor posts a sample of regulated customer data on a leak site and sets a countdown. Nothing is encrypted, so operations continue as normal.

By sector

Sector-specific tabletop exercises

Regulators, stakes and realistic injects differ by industry. Start where you operate.

FAQ

Cybersecurity tabletop exercise questions

What is a cybersecurity tabletop exercise?
A cybersecurity tabletop exercise is a discussion-based rehearsal in which executives and responders work through a realistic cyber incident under time pressure. Injects deliver new information in stages, participants make and record the decisions they would make for real, and no production systems are touched.
How long does a cybersecurity tabletop exercise take?
Most executive exercises run 60 to 120 minutes, with 90 minutes the practical sweet spot. Technical or multi-team exercises can run half a day.
How often should we run cyber tabletop exercises?
Quarterly for the core incident-response team and at least annually for executive leadership. Many regulated organisations must show documented annual testing as a minimum.
Who should be in the room?
Anyone who owns a real decision: executive leadership, the CISO or incident commander, IT operations, legal or privacy, communications, and the operational, clinical or plant leadership relevant to your sector. Everyone else attends as an observer.
Do tabletop exercises satisfy compliance requirements?
For many frameworks — including NIST SP 800-61 and 800-84 guidance, ISO 27035, HIPAA, PCI DSS and CMMC — a documented tabletop with objectives, participants, findings and an action plan is accepted evidence of incident-response testing. Confirm your specific obligations, as some regimes also expect functional testing.
What is the difference between a tabletop exercise and a simulation?
A tabletop exercise is discussion-based and touches no systems. A functional simulation exercises some tooling and processes, and a cyber range or live-fire test uses real or replica infrastructure. Tabletops are the only format senior executives reliably attend, which is what makes them high leverage.

Run your next cyber tabletop exercise in TableTop Sim