Guides · 9 min read
How to Run a Cybersecurity Tabletop Exercise
A tabletop exercise fails for boring reasons: the scope was vague, the wrong people were in the room, and the facilitator read slides instead of applying pressure. This is the sequence that produces a session executives remember and an artefact the board will read.
1. Decide what the exercise is testing
Pick one decision boundary, not a whole incident-response plan. "Can we decide to take the ERP offline while encryption is active?" is testable in 90 minutes. "Test our IR readiness" is not.
Write the objective down and read it out at the start. Everything you cut later gets cut against that sentence.
- One primary objective, at most two secondary ones.
- A named incident commander for the exercise, decided before the session, not during it.
- A hard stop time. Exercises that overrun teach people that the clock is negotiable.
2. Cast the room by decision, not by job title
Every seat should own a decision the scenario will force. If a participant has nothing to decide, make them an observer and tell them that is a real role — note-takers produce half the value of the after-action report.
- Executive decision: CEO or COO — trading, downtime, and public posture.
- Technical command: CISO or IR lead — containment, evidence, and scope.
- Legal and regulatory: General Counsel or privacy lead — notification clocks.
- Communications: internal messaging first, external second.
- Operations or clinical or plant leadership, depending on sector.
3. Build injects that remove options
A good inject narrows the choice set. It should not be new information for its own sake — it should make one of the room's assumptions untrue.
Stage them across phases so the pressure compounds: detection, triage, containment, escalation and notification, eradication and recovery, public and legal, recovery and lessons.
- Standard injects move the timeline forward.
- Technical artefacts (a log excerpt, an EDR timeline) reward people who read carefully.
- Hot-seat injects put one named person on the record within two minutes.
- Wildcards break the plan: a leak site, a journalist, an employee post.
4. Facilitate, don't narrate
Your job is silence management. When the room goes quiet, do not fill it — ask who owns the decision. When two people agree too quickly, introduce the constraint that makes them disagree.
Hold the clock visibly. A countdown on screen changes behaviour more than any inject you write.
- Never answer a question you can hand back: "What would you need to know, and who would you ask?"
- Log decisions verbatim with a timestamp. Paraphrase later, not live.
- Pause the clock deliberately when a discussion is genuinely valuable, and say that you are doing it.
5. Close with the hot wash, then the report
Run fifteen minutes of hot wash while people are still in the room: what surprised you, what would you change, what do you now know you cannot do. Capture confidence scores before and after — that delta is the number executives quote back.
The after-action report should land the same day. A report that arrives two weeks later is a document; a report that arrives before people leave the building is a decision.
Common mistakes
- Running the exercise as a plan review. If nobody is uncomfortable, it was a briefing.
- Letting the technical seats answer business questions.
- No named owner for the regulatory notification clock.
- No recorded risk acceptance for decisions that keep systems online during an active incident.
- Ending without dated, owned actions.
Frequently asked questions
- How long should a cybersecurity tabletop exercise be?
- Sixty to 120 minutes for an executive exercise. Ninety minutes is the sweet spot: long enough for three or four phases, short enough that senior people stay in the room.
- How often should we run tabletop exercises?
- Quarterly for the core incident-response team and at least annually for the executive group. Regulated organisations often need documented evidence of annual testing at minimum.
- Who should facilitate?
- Someone with no stake in the outcome. Internal teams often bring in a vCISO, MSSP or consultant precisely so the CISO can participate rather than run the clock.
Run this exercise in TableTop Sim
The scenario library, the facilitator control room and the after-action report — included in the free trial.
