How to Run Cybersecurity Tabletop Exercises From Planning to Execution
A ransomware attack targets a business every 11 seconds.
The truth is that every level of business, from small businesses to global corporations and public agencies, is exposed to cyber threats on a regular basis — and this omnipresent risk will only grow in the age of AI-empowered bad actors.
It’s not enough to create a cybersecurity plan. Your team needs to practice it in order to test its integrity and find the weak points. If you don’t spend this time in advance, you could be in for a costly fight once a real attack happens (and the odds are that one will eventually happen).
You can start to harden your security posture with quick, simple steps that involve the largest number of stakeholders, such as regular email alerts about recent common scams in the headlines and cyber hygiene best practices. After all, around 88% of all data breaches result from avoidable employee mistakes, such as distractions that cause workers to miss common security red flags.
After that, get practical with participation-based preparations. Organize a tabletop exercise.
What is a Tabletop Exercise in Cyber Security?
A cybersecurity tabletop exercise is discussion-based simulation where participants walk through the impacts and steps of a prototypical cyber incident (e.g. an email phishing attack or disguised ransomware download).
No systems are put into distress, though — the entire exercise is a hypothetical conversation. It is an opportunity to get all of the key stakeholders into a room and practice getting into the mindset of each step of your cybersecurity incident response plan as if it was happening in real-time. In a way, it’s a low-stakes stress test of your plan and your team’s level of preparedness.
Why Should We Go Through Cybersecurity Tabletop Exercises?
The 2025 Cost of a Data Breach Report from IBM found that when a company experienced a data breach, the total estimated cost incurred in recovery was just over $4M. And that’s probably a conservative number.
Cybersecurity exercises are a crucial practice opportunity for the quick reactions your team will need to make in the event of a real attack. Such practice protects both your bottom line and your reputation. For an unprepared team facing a major incident , the long-term damage to public perceptions of your organization may be even more impactful than the immediate financial risks.
How Do You Run a Cyber Tabletop Exercise?
Most cybersecurity exercises are run in a three phase framework. Each phase should have specific pre-set objectives and defined outcomes that can be molded to the unique parameters of your business and stakeholders.
An experienced facilitator should develop a practical cyberattack scenario and keep the group discussion on-topic. If you don’t have an appropriate facilitator in house, work with a seasoned third-party cybersecurity firm to schedule an on-location visit. The scenario should unfold and branch off as the exercise develops so the true density of the cybersecurity plan can be tested.
Phase 1: Planning
In this phase, you lay down the foundation for the exercise.
● Set SMART objectives (specific, measurable, achievable, relevant, time-bound) for the exercise.
● Choose a relevant threat type and define a scenario that’s realistic for your industry and circumstances.
● Identify key stakeholders across functions (IT, Security, Legal, HR, Communications, Finance, Leadership…whoever could be relevant) and assemble the team.
● Collect documentation to have on hand for the session, such as your incident response plan (RIP), network diagrams, or contact lists.
Phase 2: Execution
This is the live portion of the exercise. Continue until the attack is resolved or no further progress can be made.
● The facilitator introduces the scenario and sets ground rules. Their job is to control the pace and keep the discussion on track..
● Each stakeholder (the “players”) will discuss their role/responsibilities and the steps they (or their team) would need to take. Dedicated note-takers record all decisions made and actions taken.
● The facilitator introduces “injects”, or timed updates and complications to increase pressure. For example, “news of the data breach has been leaked on social media.”
● Stakeholders must pivot and react to the unexpected complications — a good test of your incident response plan’s flexibility.
Phase 3: Debrief & Remediate
It’s important to dissect how things went to improve and update response plans.
● Discuss what went well (or didn’t) and anything that surprised the players. This is best to do right at the end of the exercise, while it’s fresh. Did your cybersecurity plan work as intended? Was anything missing that would have helped?
● Create an After-Action Report (AAR) that explains what the exercise uncovered about the plan and the organization’s preparedness, including actionable recommendations.
● Revise your IRP based on the findings in the report and then assign follow-up actions for specific teams — with deadlines — to make sure all gaps are closed.
Set Your Cybersecurity Tabletop Exercises Up For Success
A cybersecurity tabletop exercise is only valuable if participants feel comfortable enough to engage honestly and the lessons lead to meaningful improvements afterward. To that end:
● Establish a no-fault environment up front — people should know they can ask questions or admit uncertainty and make mistakes free from criticism.
● The session should be focused, ideally between one and three hours, so participants stay engaged.
● Run exercises at least once a year, or more frequently if your organization is growing, changing systems, or facing new compliance requirements.
● Finally, build scenarios around established frameworks like the NIST Incident Response Guidelines or the MITRE ATT&CK Framework so the discussion reflects realistic attack techniques and response expectations.
An experienced facilitator makes all the difference. Erudio designs and leads cybersecurity tabletop exercises custom-tailored to your organization. Our deep cybersecurity experience allows us to facilitate those exercises in a way that matches the often chaotic nature of real world attacks. Leave your session with actions you can implement right away to strengthen your security posture.
If you're ready to put your incident response plan to the test, contact Erudio and schedule a cybersecurity tabletop exercise today.
FAQs
What is a cybersecurity tabletop exercise?
A cybersecurity tabletop exercise is a discussion-based simulation of a cyberattack where no systems are put into distress. Erudio facilitates the exercise by guiding stakeholders through each step of the organization's cybersecurity plan as though the attack were happening in real time.
What types of cyber incidents make good tabletop exercise scenarios?
The most effective scenarios reflect the threats your organization is most likely to face. Common examples include ransomware attacks, phishing campaigns that lead to compromised credentials, business email compromise, insider threats, supply chain incidents, and data breaches involving sensitive information.
Who should participate in a cybersecurity tabletop exercise?
The right participants depend on the scenario, but most tabletop exercises include representatives from IT, cybersecurity, leadership, legal, human resources, communications, and any other department responsible for making decisions during a cyber incident. The goal is to test how the organization responds together, not just how the IT team reacts.
Can we run a cybersecurity tabletop exercise ourselves, or should we hire an experienced facilitator?
Many organizations can facilitate simple tabletop exercises internally, but an experienced third-party facilitator brings an objective perspective, introduces realistic scenarios, and asks questions that internal teams may overlook. An outside facilitator also keeps discussions focused and documents findings so your team can concentrate on responding to the scenario.
How long does a cybersecurity tabletop exercise take?
Most tabletop exercises last between one and three hours, depending on the complexity of the scenario and the number of participants. Additional time may be scheduled afterward to review findings, prioritize improvements, and assign follow-up actions.
How do we know if our tabletop exercise was successful?
A successful exercise isn't one where everything goes perfectly. It's one that uncovers communication issues, decision-making bottlenecks, missing documentation, or weaknesses in the incident response plan while there is still time to fix them.
How often should we run cybersecurity tabletop exercises?
Most organizations should conduct a cybersecurity tabletop exercise at least once a year. Businesses facing changing compliance requirements, significant technology changes, or evolving cyber risks often benefit from running exercises twice a year or after major updates to their incident response plan.
Can a tabletop exercise help with CMMC or other compliance requirements?
Yes. While a tabletop exercise is not a certification requirement on its own, it helps organizations validate their incident response procedures, clarify responsibilities, and identify documentation or process improvements that support frameworks such as NIST SP 800-171 and CMMC. It also provides valuable evidence that cybersecurity plans are being actively maintained and tested.