Platform

A control room, a room full of roles, and a report at the end

TableTop Sim replaces the slide deck and the shared inbox with a purpose-built simulation environment for cybersecurity tabletop exercises.

Facilitator control room

Run the whole exercise from one screen

Release injects on your cue or on a timer. Pause when the discussion is worth having. Watch responses arrive by role, annotate them while they're fresh, and keep private facilitator notes that participants never see. When the room takes an unexpected turn, accept an AI-improvised inject that follows what was actually said instead of dragging everyone back to the script.

  • Inject timeline with release, hold and complete states
  • Live response feed grouped by role and seat
  • Inline annotation captured straight into the report
  • AI improvisation suggestions you approve or discard
console.tabletopsim.com — Ransomware in the finance shared drive
03:00

Inject window

Northwind Logistics · Ransomware · Standard

9 / 9 connected
  1. Detection
  2. Triage
  3. Containment
  4. Escalation & Notification
  5. Eradication & Recovery
  6. Public & Legal
  7. Recovery & Lessons
On airstandardCISO laneresponse required

Helpdesk escalation: three users locked out of the finance share

Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.

Inject timeline

  1. 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
  2. 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
  3. 00:23The CFO asks whether to shut down the ERPqueued · CEO
  4. 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
  5. 00:48Trade press calls for comment before your statement is readyqueued · Comms Director

Live response feed

  1. 00:06CISO

    Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.

    Dana W.

Start the clock to watch responses land

Participant rooms

Everyone sees exactly what their seat would see

Participants join with a code — no account, no install, no onboarding. Each role lands in a bespoke incident bridge: their brief, their private information, the shared situation board, and the exercise clock. Observers and note-takers get the same view read-only, so training staff can watch without nudging the outcome.

  • Join-code access with no participant accounts
  • Role-specific injects for CEO, CISO, General Counsel, Comms and more
  • Shared situation board with live status tiles
  • View-only observer and note-taker seats
tabletopsim.com/join — incident bridge
02:02

Your seat

CEO — Priya S.

9 on the bridge
  1. Detection
  2. Triage
  3. Containment
  4. Escalation & Notification
  5. Eradication & Recovery
  6. Public & Legal
  7. Recovery & Lessons
Switch seat:

Your brief

You own the trading decision. Every hour of ERP downtime costs roughly one day of margin recovery, and your board chair will ask what you knew and when.

Private to this seat

Private to you: the board's risk committee meets tomorrow morning. Your cyber policy has a 24-hour notification clause you have not yet triggered.

No other participant can see this panel

response requiredhot seat

Do you keep shipping running while the blast radius is still unknown?

Type your decision and the reasoning behind it…

Shared situation board

  1. 00:04another role's lane

    CISO received new information

  2. 00:11another role's lane

    IT Operations received new information

  3. 00:23your lane

    The CFO asks whether to shut down the ERP

On the bridge

  • Priya S.CEO
  • Dana W.CISO
  • Alan R.General Counsel
  • Lena K.Comms Director
  • R. Alvarezobserver
  • T. Okaforobserver

After-action reporting

A report you would hand to a board

The exercise record becomes the deliverable. Decisions and timings, response quality by role, lessons learned, AI-recommended alternatives to the choices made, and hot-wash feedback collected from the room — as a web report and a branded PDF, ready before the debrief coffee goes cold.

  • Web report plus branded PDF export
  • Decision timeline with timings by role
  • Lessons learned and recommended alternatives
  • Hot-wash feedback captured in-session
console.tabletopsim.com — after-action report

After-action report

Ransomware in the finance shared drive — Northwind Logistics

finalised

2.8 / 5

Confidence before

4.1 / 5

Confidence after

11

Injects released

23

Decisions logged

executive summary

What happened

Northwind Logistics ran a 90-minute ransomware exercise covering detection through public and legal response. The team isolated the affected file server within six minutes and correctly preserved volatile evidence before rebuilding. Decision-making slowed at the escalation boundary: the notification clock was debated for eleven minutes without an owner, and the trading decision on ERP availability was made without a documented risk acceptance.

observed

Strengths

  • Containment instinct was fast and correct — isolation before reboot, evidence preserved.
  • The service-account pivot was recognised from the EDR artefact without facilitator prompting.
  • Legal engaged outside counsel early and refused direct actor contact.

observed

Gaps

  • No single owner for the regulatory notification clock; it was discussed by three seats and started by none.
  • The ERP availability decision was verbal, with no recorded risk acceptance or review time.
  • Backup integrity was assumed. Nobody asked when the last restore test passed.

ai analysis

Alternative actions the AI recommends

  • Name a notification owner in the first ten minutes of any incident, before scope is known.
  • Require a timestamped risk acceptance for any decision that keeps a business system online during active encryption.
  • Add 'last successful restore test' to the incident-commander opening checklist.

carry forward

Lessons learned

  • The room defaults to technical containment and defers business decisions upward without a deadline.
  • Comms and Legal were working from different assumptions about what had already leaked.
  • Downtime procedures exist on paper but nobody could say where to find them under pressure.

action plan

Recommendations

  • CISO · 30 daysAdd a notification-owner field to the IR plan's first-hour checklist.
  • IT Operations · 45 daysRun a documented restore test on the finance volume and record the result.
  • Comms · 30 daysDraft holding statements for encryption and leak-site scenarios, approved by Legal.
  • General Counsel · 60 daysMap customer contract notification clauses into a single reference table.

Also included

The details that make it repeatable

AI environment tailoring

Describe the client's environment once — cloud, remote or hybrid, device estate, sector, regulators — and every inject, artefact and role prompt is rewritten to fit.

Multi-tenant organizations

Manage members and roles per organization, keep client exercises isolated, and reuse tailored scenarios across engagements.

Themes, per org and per exercise

Mission Control, Corporate, Wardroom, Cyberpunk or D&D. Set an org default and override it for a single exercise when the audience calls for it.

Scenario authoring

Fork a library scenario or build one from scratch: injects, timings, role targeting, artefacts and facilitator notes.

Timers and pacing control

Per-inject countdowns, global pause, and pacing that adapts when a discussion is worth extending.

Exercise history

Every session is retained with its injects, responses and report so you can show progress between exercises.