Most incident response plans have never been read under pressure

A tabletop exercise is two hours spent finding that out on purpose, in a meeting room, instead of finding it out during an actual incident. Here is how to run one with a leadership team that has never done one before.

People around a meeting table with notes and a laptop

What a tabletop exercise actually is

Not a fire drill, and not a technical test. Nobody's laptop actually gets encrypted, and IT does not simulate restoring a server. A tabletop exercise is a facilitated conversation in which a leadership team works through a realistic incident scenario in real time, making the same decisions they would have to make for real — with a facilitator injecting new information every fifteen or twenty minutes to keep it moving.

The whole exercise is two hours. Book a room, put phones away, and treat it as seriously as you would treat the actual incident it is standing in for — that seriousness is most of what makes it work.

Why leadership, not just IT

Most organisations that have rehearsed anything have rehearsed the technical response: restoring from backup, isolating a segment, rotating credentials. That is necessary and it is not what actually determines how bad an incident gets. What determines that is a sequence of commercial, legal and communications decisions, none of which IT is authorised to make alone:

  • Do we pay, and who has the authority to say yes
  • Do we tell staff today, and in what words
  • Do we tell clients before we are certain what happened, or after
  • Is this notifiable — under the Notifiable Data Breaches scheme, under the ransomware payment reporting obligation, or under a client contract — and who decides
  • Who talks to a journalist if one calls, and who explicitly does not

A competent technical team can contain a breach in hours. We have watched organisations take that same technical response and lose three additional days because nobody in the room had the authority, or the confidence, to make the decisions above. The exercise exists to move that cost out of the incident.

Who needs to be in the room

Six to eight people is the working number. Larger groups slow the pace and let people hide; smaller groups miss a perspective you need. As a baseline:

  • the CEO or Managing Director, or whoever actually holds payment and public-statement authority
  • an operations lead who understands what the business cannot function without
  • legal or compliance, internal or your external adviser
  • whoever owns communications — client-facing and staff-facing are often different people
  • your IT or MSP contact, present to answer "what do we actually know right now", not to run the meeting

If you carry cyber insurance, invite your broker or insurer contact to at least one exercise a year. The first time anyone reads the policy's notification clause should not be during a live claim.

Choosing a scenario that will not let anyone hide

A generic scenario produces a generic exercise. "There has been a cyber incident" lets everyone nod along without committing to anything. A specific scenario, close to how your organisation actually operates, does not:

  • A ransom note is found at 7am Monday by the first person into the office. Nobody senior is reachable for forty minutes.
  • A payment has already been sent to what turns out to be a fraudulent invoice, and the bank says recall is unlikely.
  • A staff member reports their laptop missing, and it was logged into the system holding client files two days ago.

Pick one, then plan two or three injects — new facts introduced partway through — that remove an easy option. If the group's plan is "restore from backup", the mid-exercise inject is that the backups were also affected. If the plan is "our insurer handles it", the inject is that the policy excludes the specific scenario you chose. The exercise is testing the decision, not the first answer everyone reaches for.

How the two hours actually go

  1. Brief the scenario (10 minutes). Set the facts as they would actually arrive — incomplete, and from more than one direction at once.
  2. Work the first decision point (20 minutes). Who is told, in what order, and what is actually said. Write the decision down as the group reaches it, not as a summary afterwards.
  3. Inject new information (repeat, three or four times). Each inject should force a decision the group thought it had already settled. This is where a facilitator who is not part of the leadership team earns their place — someone in the room has to be free to complicate things on purpose.
  4. Run a hot wash in the last 20 minutes. While the exercise is still fresh, ask each person one question: what would you actually have done differently if this were real? Capture the answers verbatim.

The only output that matters

Not a report that says the exercise went well. A written, specific list of what the exercise found — a decision nobody could make, a contact detail nobody had, a plan that assumed a person who left the organisation last year — with a named owner and a date for each item to be fixed. Circulate it within a week, while it still has the weight of the room behind it.

Then put a date on the next one. Annually is the reasonable default; sooner if you have had a leadership change, a material incident, or a significant change to what the organisation depends on technically.

Questions

How long should a tabletop exercise take?

Two hours is the right length for most leadership teams. Long enough to work through a scenario with two or three injects and a proper hot wash, short enough that people stay engaged and it is not too hard to get on the calendar.

Do we need an external facilitator?

Not for the first one strictly, but it helps more than most teams expect. An internal facilitator is also a participant with an opinion on the answer, which makes it hard to inject an uncomfortable complication into their own colleague's plan. An external facilitator has no stake in the outcome looking good.

How often should we run one?

Once a year is the reasonable baseline, and it is also what a genuine incident response plan review expects to see evidence of. Run an additional one sooner after a leadership change, a merger, or a material shift in what systems the business actually depends on.

What if the exercise reveals something embarrassing?

That is what a good exercise is supposed to do. A tabletop that finds nothing wrong either tested a scenario that was too easy, or the group already knew the answers — in which case you could have skipped the meeting. The gaps are the value; write them down and fix them rather than treating the exercise as a pass or fail on the day.

The value of a tabletop exercise is roughly inverse to how comfortable it feels. If everyone in the room already knew exactly what to do, you did not need the exercise — or you have already had it, during a real incident, and got lucky.

We can facilitate the first one for you

A scenario built around how your organisation actually operates, run by someone with no stake in the answer looking good, with a written list of gaps at the end rather than a congratulatory summary.