Cyber tabletop exercises
A cyber tabletop exercise is a facilitated discussion in which your leaders and technical staff walk through a realistic incident, one decision at a time, without touching a live system. We design the scenario around your real risks, run the session, and hand you an after-action report with a named owner and a date against every fix. The exercise can be booked on its own; when the plan and playbooks also need writing, it is part of incident response readiness.
What a tabletop exercise actually tests
It tests decisions, not technology. Who can authorize taking the payment system offline at 2 a.m.? Who calls the insurer, and is the policy number anywhere except the email server that just went down? Does the plan name a person or a job title that no longer exists?
These gaps are invisible on paper and obvious within twenty minutes of a well-built scenario. Finding them in a meeting room is far cheaper than finding them during the real thing.
Scenarios built from your own risks
A generic scenario produces generic lessons. We start from what could plausibly happen to you and pick one of these, or combine two:
- Ransomware that reaches backups, forcing a choice between restoring and rebuilding. See ransomware readiness.
- Vendor breach, such as a managed provider with admin access to your payroll system reporting a compromise on a Friday afternoon.
- Insider activity: a departing employee exporting a client list, or an administrator acting outside their role.
- AI-enabled fraud, such as a cloned executive voice asking finance to move money today. The controls side is on deepfake fraud controls.
Executive, technical, or both
An executive exercise focuses on authority, money, communications and counsel. A technical exercise focuses on detection, containment, evidence and recovery order. Running both, linked, shows where the two groups assume the other one is handling something that nobody is.
Who should attend?
The people who would really make the calls: an executive who can authorize spending, whoever runs technology, whoever speaks for the organization, the person who calls counsel, and someone who knows how the systems actually work.
How a session runs
How long does a tabletop exercise take?
Most single-scenario sessions run two to three hours. A combined exercise often runs as two linked sessions on the same day, so what the technical group decides feeds straight into the executive discussion.
The scenario unfolds through five or six injects: new facts delivered at set points, each one forcing a decision. The facilitator keeps time, asks who owns each call, and stops the group from solving the problem with a tool it does not have. A note-taker records every decision and every “we would need to check”.
Do you need access to our systems?
No. A tabletop is a discussion exercise. Nothing is tested, scanned or changed, and the inputs are your existing plans, contact lists and an honest conversation about how your systems work.
If a scenario touches notification, the exercise records who would decide. That decision belongs to your counsel, not to us.
What the after-action report contains
What do we get afterwards?
You receive an after-action report listing what worked, what did not, and each fix with a named owner and a due date. A short follow-up later checks which of those actions actually closed.
| Section | What it is for |
|---|---|
| Timeline of decisions | What the group decided, when, and on what information |
| Gaps found | Plan, contacts, authority or tooling that did not hold up |
| Action register | Each fix with an owner, a due date and a priority |
| Next scenario | What the following exercise should test |
The register usually feeds the incident response plan and, where recovery order was contested, a business impact analysis. For the method itself, see how to run a cyber tabletop exercise.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Plan your first exercise
Tell us who would be in the room and which incident worries you most. The reply proposes a scenario outline and a format. See also all security services.