How to run a cyber tabletop exercise
To run a cyber tabletop exercise, pick one objective, write a scenario that could plausibly happen to you, and put the people who would really make the decisions in one room. Feed them five or six injects over two to three hours. A neutral facilitator keeps it moving, and an after-action report turns what surfaced into fixes with owners and dates.
Start with one objective
Write down the single thing you want to learn. “Can we decide to take the ordering system offline within an hour?” is an objective. “Test our incident response” is not, because it gives you no way to tell afterwards whether the exercise worked.
One objective also keeps the scenario honest. Every inject should push the group toward that decision.
Choose a plausible scenario
Use something that fits your business and your recent history: ransomware on the file servers, a vendor with remote access reporting a breach, a departing employee taking client data, or a cloned voice of your CFO asking for an urgent transfer. If people spend the session arguing that it could never happen, the scenario has failed.
Public material helps. CISA publishes free tabletop exercise packages with ready scenarios, and NIST’s SP 800-84 sets out how to design, run and evaluate an exercise programme. Adapt either to your own systems and people.
Who must be in the room
The people who would make the calls, not their delegates. That usually means an executive who can approve spending, the head of technology, whoever handles communications, the person who phones counsel and the insurer, and one engineer who knows how things really connect. Keep it under a dozen.
Observers are fine if they stay silent. A crowded room turns decisions into speeches. Alternate the audience across runs: an executive session one time, a technical one the next, and a combined run once the plan has settled.
How many injects a tabletop needs
Five or six. An inject is a new fact delivered at a set point: the helpdesk reports locked files, a journalist emails, the backups turn out to be encrypted too, the attacker posts a sample of your data. Each one should force a decision, and at least one should remove an option the group was relying on.
The facilitator’s job
Keep time, ask “who decides this?” out loud, and refuse fixes that do not exist yet (“we would just restore from backup” gets the question “which backup, and who has checked it?”). The facilitator does not play hero and does not grade people. A separate note-taker records every decision and every “we would need to check”, because those phrases are the findings.
What the after-action report must contain
- A timeline of decisions and the information each was based on.
- The gaps found in the plan, contact lists, authority and tooling.
- An action register: each fix with one named owner and a due date.
- The objective, and a plain answer on whether it was met.
Send it within a week, while memories are fresh. A report without owners is a record of a meeting, not an improvement.
Questions we are asked
How long should a tabletop exercise last?
Two to three hours for a single scenario is about right. Shorter and the group never reaches the hard decisions; longer and attention drops before the last inject lands.
How often should we run one?
At least once a year, and again after a major change: a new core system, a merger, a new leadership group, or a real incident. Rotate the scenario each time so nobody is rehearsing an answer they already know.
Should the scenario be a surprise?
Participants should know the date, the length and the general theme, but not the scenario details or the injects. Surprise about the story is useful; surprise about the meeting only produces empty chairs.
Can we facilitate it ourselves?
Yes, and many organizations do. The catch is that an internal facilitator usually has a stake in how the plan looks, so an outside facilitator earns its place for executive sessions and for the first run of a new plan.
Getting help with the first one
We design and facilitate these exercises; see cyber tabletop exercises. What to do if the scenario ever becomes real is in the first 24 hours of an incident, and related pieces are indexed at writing.