Buyer journey · Step-by-step
How to run a cybersecurity tabletop exercise
A cybersecurity tabletop exercise is a facilitated, discussion-based rehearsal of a cyber incident: you release staged injects to a room of decision-makers, apply time pressure, and record what they decide. Done properly it takes 60–120 minutes, needs eight to twelve of the right people, and ends with an after-action report the board will actually read. Below is the sequence we use, and what the tooling looks like at each step.
The sequence
Seven steps from a vague request to a signed-off report
Steps one to three happen before the day. Four to six are the exercise itself. Step seven is the deliverable your client keeps.
01Decide what you are actually testing
30 min prepChoose one decision boundary the room genuinely owns. "Do we take the ERP offline while encryption is still spreading?" is testable in 90 minutes. "Test our incident response" is not. Write the objective in a single sentence and read it out at the start; everything you cut later gets cut against it.
- One primary objective, at most two secondary ones.
- Name the decision-maker for each objective — if nobody owns it, it is not a decision.
- Agree what a successful exercise looks like with the sponsor before you build anything.
02Pick the right people and seats
1 week aheadA tabletop is a decision rehearsal, not a technical drill. You want the executives who authorise money, downtime and public statements, plus the technical lead who can say what is actually possible. Eight to twelve participants is the sweet spot; beyond fifteen, split into a decision table and an observer ring.
- Core seats: CEO or MD, CISO or security lead, IT/infrastructure lead, General Counsel, Comms, HR or Ops if people are affected.
- Optional seats: finance (ransom and recovery cost), insurer or broker, key supplier contact.
- Observers and note-takers watch without touching the exercise — give them a view-only seat, not a chair at the table.
03Choose and tailor the scenario
1-2 hours prepStart from a scenario that already holds up under pressure, then make it theirs. Generic injects get dismissed with "that could not happen here". Rewriting injects around the real environment — cloud or hybrid, device estate, sector, regulators — is what turns polite agreement into an argument worth having.
- Match the scenario to a plausible threat for the sector, not the scariest headline.
- Tailor names, systems, suppliers, regulators and reporting deadlines to the organisation.
- Prepare artefacts: the ransom note, the journalist's email, the regulator's enquiry, the supplier's statement.
04Set the clock and the rules
10 min at startSet the exercise clock before the first inject and state the ground rules: assume nothing off-screen, no hero solutions, no punishing honest answers. Say clearly whether the exercise is compressed time (four hours of incident in ninety minutes) and how you will signal a jump forward.
- Confirm confidentiality and that no real systems will be touched.
- Explain that private information may go to individual seats only.
- Tell the room you will pause the clock deliberately — it is a facilitation tool, not a failure.
05Release injects and apply pressure
60-90 minRelease staged injects and let the room work. Your job is pressure, not narration: ask who decides, by when, with what authority, and what they will say publicly. When the discussion drifts somewhere more interesting than your script, follow it — an improvised inject that reacts to what was actually said is worth three scripted ones.
- Keep injects short and unambiguous; ambiguity should come from the situation, not the wording.
- Time-box decisions out loud: "you have six minutes before the journalist publishes".
- Note the decisions, the gaps and the moments of hesitation as they happen — you will not remember them later.
06Run the hot wash immediately
15-20 minDo the hot wash while the room is still in it. Ask each seat for one thing that worked and one thing that would have failed for real. Capture verbatim quotes — they are the most persuasive part of the report.
- Separate process failures from people failures; only one of them belongs in the report.
- Ask what information they wanted and did not have — that list becomes half your recommendations.
- Collect written feedback before people leave the room.
07Issue the after-action report
Same dayThe exercise is the event; the report is the deliverable. It should record the timeline, the decisions taken, the lessons learned, the recommended alternatives, and an owner with a due date for every action. Delivered on the day, it lands while the discomfort is fresh. Delivered a fortnight later, it lands in an inbox.
- Structure: objective, scenario summary, timeline, decisions, findings, recommendations, owners and dates.
- Circulate a web version for the team and a branded PDF for the board.
- Book the follow-up before the report is read, and re-test the same decision boundary next quarter.
Step 5, in the product
What facilitating from a control room looks like
Release injects, hold the clock, read responses live and accept an AI-improvised inject when the room goes somewhere your script did not.
Inject window
Northwind Logistics · Ransomware · Standard
- Detection
- Triage
- Containment
- Escalation & Notification
- Eradication & Recovery
- Public & Legal
- Recovery & Lessons
Helpdesk escalation: three users locked out of the finance share
Two accounts payable clerks and a controller report that files on the finance share now end in .nwlk and open as gibberish. A README appears in every folder. The helpdesk has already rebooted one machine.
Inject timeline
- 00:04Helpdesk escalation: three users locked out of the finance sharereleased · CISO
- 00:11EDR timeline: service account authenticated from an unmanaged hostqueued · IT Operations
- 00:23The CFO asks whether to shut down the ERPqueued · CEO
- 00:34A customer emails a screenshot of your data on a leak sitequeued · General Counsel
- 00:48Trade press calls for comment before your statement is readyqueued · Comms Director
Live response feed
- 00:06CISO
Isolating FILE-02 and the three endpoints now. Do not reboot anything else — we need the volatile evidence.
Dana W.
Start the clock to watch responses land
Step 2, in the product
Every seat sees only what that seat would see
Participants join with a code and land in a role-specific incident bridge: their brief, their private information, the shared situation board and the clock.
Your seat
CEO — Priya S.
- Detection
- Triage
- Containment
- Escalation & Notification
- Eradication & Recovery
- Public & Legal
- Recovery & Lessons
Your brief
You own the trading decision. Every hour of ERP downtime costs roughly one day of margin recovery, and your board chair will ask what you knew and when.
Private to this seat
Private to you: the board's risk committee meets tomorrow morning. Your cyber policy has a 24-hour notification clause you have not yet triggered.
No other participant can see this panel
Do you keep shipping running while the blast radius is still unknown?
Shared situation board
- 00:04another role's lane
CISO received new information
- 00:11another role's lane
IT Operations received new information
- 00:23your lane
The CFO asks whether to shut down the ERP
On the bridge
- Priya S.CEO
- Dana W.CISO
- Alan R.General Counsel
- Lena K.Comms Director
- R. Alvarezobserver
- T. Okaforobserver
Step 7, in the product
The after-action report, generated on the day
Decisions, findings, recommended alternatives and owners — as a web report for the team and a branded PDF for the board.
After-action report
Ransomware in the finance shared drive — Northwind Logistics
2.8 / 5
Confidence before
4.1 / 5
Confidence after
11
Injects released
23
Decisions logged
executive summary
What happened
observed
Strengths
- Containment instinct was fast and correct — isolation before reboot, evidence preserved.
- The service-account pivot was recognised from the EDR artefact without facilitator prompting.
- Legal engaged outside counsel early and refused direct actor contact.
observed
Gaps
- No single owner for the regulatory notification clock; it was discussed by three seats and started by none.
- The ERP availability decision was verbal, with no recorded risk acceptance or review time.
- Backup integrity was assumed. Nobody asked when the last restore test passed.
ai analysis
Alternative actions the AI recommends
- Name a notification owner in the first ten minutes of any incident, before scope is known.
- Require a timestamped risk acceptance for any decision that keeps a business system online during active encryption.
- Add 'last successful restore test' to the incident-commander opening checklist.
carry forward
Lessons learned
- The room defaults to technical containment and defers business decisions upward without a deadline.
- Comms and Legal were working from different assumptions about what had already leaked.
- Downtime procedures exist on paper but nobody could say where to find them under pressure.
action plan
Recommendations
- CISO · 30 daysAdd a notification-owner field to the IR plan's first-hour checklist.
- IT Operations · 45 daysRun a documented restore test on the finance volume and record the result.
- Comms · 30 daysDraft holding statements for encryption and leak-site scenarios, approved by Legal.
- General Counsel · 60 daysMap customer contract notification clauses into a single reference table.
Timing
Pick a format before you pick a scenario
| Format | Total time | Injects | Best for |
|---|---|---|---|
| Express | 60 minutes | 4-5 | Board-level awareness, first-time participants |
| Standard | 90 minutes | 6-8 | Executive decision rehearsal, quarterly cadence |
| Extended | 120 minutes | 9-12 | Multi-team response, regulatory reporting drills |
Facilitator checklist
Ten things to have ready
- Objective written in one sentence and agreed with the sponsor
- Seats confirmed, with named decision-makers
- Scenario chosen and tailored to the real environment
- Injects staged with timings and artefacts attached
- Private briefs prepared per role
- Exercise clock and pause plan ready
- Note capture set up for decisions and quotes
- Hot wash questions prepared
- After-action report template ready to populate
- Follow-up session already in the calendar
Failure modes
Six ways exercises go flat
Reading slides instead of facilitating
If the room can predict the next slide, nobody is being tested. Release information, then get out of the way and ask who decides.
Inviting the wrong room
A tabletop full of engineers rehearses containment, not governance. Without the executives who authorise downtime and statements, the hard decisions never get made.
A scenario that could not happen here
Untailored injects invite the room to argue with the premise instead of the decision. Tailor to their stack, sector and suppliers.
No artefacts
"A journalist has contacted you" is a prompt. The actual email, with a deadline in it, is an exercise.
Losing the record
If the decisions and quotes are not captured live, the report becomes a summary of your memory. Capture as you go.
No follow-up
An exercise with no owners, dates or re-test is entertainment. Close it out with actions and a date in the calendar.
FAQ
Frequently asked questions
- How long should a cybersecurity tabletop exercise take?
- Sixty to one hundred and twenty minutes of exercise time, plus a fifteen to twenty minute hot wash. Anything under an hour rarely gets past the first decision; anything over two hours loses executive attendance.
- Who should attend a cybersecurity tabletop exercise?
- The people who authorise money, downtime and public statements: CEO or MD, security lead, IT lead, General Counsel and Communications, plus HR or Operations when people are affected. Eight to twelve participants keeps the discussion sharp.
- How often should we run one?
- Quarterly for regulated or high-exposure organisations, at least twice a year otherwise, and always after a material change: a merger, a new core platform, or a new executive team.
- What is the difference between a tabletop exercise and a simulation?
- A tabletop tests decisions and communication in a discussion-based format; a technical simulation tests systems and detection. A tabletop needs no live infrastructure, which is exactly why executives will attend one.
- What should the after-action report contain?
- The objective, scenario summary, timeline, decisions taken, findings and lessons learned, recommended alternatives, and an owner with a due date for every action. TableTop Sim generates web and PDF versions from the exercise record on the day.
- Do participants need accounts or software?
- Not in TableTop Sim. Participants join with a code and land in a role-specific incident bridge in the browser — no accounts, no installs.
Keep going
