Tabletop Exercises

How a tabletop exercise works

A well-structured tabletop exercise follows a consistent format:

Scenario design

The facilitator designs a realistic incident scenario based on threats relevant to the organisation. This might be a ransomware attack encrypting critical systems, a data breach involving customer records, a supply chain compromise affecting a key vendor, or a business email compromise targeting the finance team. Good scenarios are drawn from real-world incidents and tailored to the organisation’s sector and risk profile.

Phased injects

The scenario unfolds in phases, with new information (“injects”) introduced at each stage. For example:

  • Phase 1 – the SOC detects unusual outbound traffic from a server containing customer data. What do you do?
  • Phase 2 – investigation reveals the server has been compromised for three weeks. Attacker has exfiltrated 50,000 customer records. The regulatory clock starts. Who do you notify?
  • Phase 3 – a journalist contacts your press office asking for comment. The attacker posts a ransom demand on a leak site. What is your public statement?

Each phase forces participants to make decisions, assign responsibilities, and confront trade-offs. The facilitator probes assumptions: “Who makes the call to pay or not pay the ransom? What if your CEO is on holiday? Where is the incident response plan – has anyone read it recently?”

Debrief and gap analysis

After the scenario concludes, the facilitator leads a structured debrief. This identifies gaps in the incident response plan, unclear roles and escalation paths, missing capabilities (such as forensic readiness or media handling), and decisions that would have delayed response in a real incident. The output is typically a written report with prioritised recommendations.

Tabletop exercises vs full simulations

Tabletop exerciseFull [crisis simulation](/glossary/cyber-crisis-simulation-exercises/)
FormatDiscussion-basedOperational – may include live technical elements
Systems testedNoneMay test SOC procedures, comms tools, failover
ParticipantsBoard, executives, senior managementAll levels including technical responders
Duration2-4 hoursHalf day to multiple days
ComplexityLower – accessible to non-technical participantsHigher – requires technical coordination
CostLowerHigher
Best forBoard engagement, plan validation, regulatory evidenceEnd-to-end response testing, SOC readiness

Both formats are valuable. Tabletop exercises are typically a starting point. Organisations with mature incident response capabilities progress to full crisis simulations that test technical execution alongside strategic decision-making.

Why tabletop exercises matter for boards

The UK Corporate Governance Code and NCSC board toolkit both emphasise that cyber security is a board-level responsibility. Tabletop exercises are one of the most effective ways to engage board members with cyber risk because they require no technical knowledge. Directors participate as decision-makers – the same role they would play in a real incident.

Regulators increasingly expect evidence of exercising. Organisations subject to NIS2 requirements must demonstrate incident response preparedness. Financial services firms operating under DORA must conduct regular scenario testing. A tabletop exercise provides documented evidence that the board has tested its response.

Cyberfort and tabletop exercises

We design and facilitate tabletop exercises for boards, executive teams, and incident response teams. Scenarios are built from real threat intelligence relevant to your sector and tailored to your organisation’s systems, suppliers, and regulatory obligations. Our facilitation team includes experienced incident responders who know what breaks under pressure because they have handled real breaches through our incident response service.

Related glossary terms

  • Cyber Crisis Simulation – full operational simulation that extends beyond discussion into live response testing
  • DFIR – the digital forensics and incident response capability that tabletop exercises are designed to test
  • Red Teaming – adversarial simulation that tests defences through live attacks, unlike the discussion-based tabletop format
  • NIS2 Directive – EU directive requiring incident response preparedness, for which tabletop exercises provide evidence
  • DORA – financial services regulation mandating scenario-based resilience testing

External references

Frequently asked questions

What is a cyber tabletop exercise?

A cyber tabletop exercise is a facilitated, discussion-based session where key personnel walk through a simulated cyber security incident without interacting with live systems. Participants are presented with a scenario that unfolds in phases, and they discuss how they would respond at each stage. The purpose is to test incident response plans, identify gaps in roles and procedures, and prepare decision-makers for a real incident.

Who should participate in a tabletop exercise?

Tabletop exercises are most effective when they include the people who would be involved in a real incident response. This typically means the CEO or managing director, CISO or IT director, legal counsel, communications or PR lead, HR, and representatives from affected business units. Board members should participate at least annually. Technical staff can also be included, but the primary audience is strategic decision-makers.

How often should tabletop exercises be conducted?

At least once a year, and after any significant change to the organisation’s risk profile – such as a major system migration, acquisition, new regulatory requirement, or a real incident. Organisations in regulated sectors (financial services, critical infrastructure, healthcare) may need to exercise more frequently to meet compliance requirements. Each exercise should use a different scenario to avoid rehearsal bias.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.