How to Run a Cyber Incident Tabletop Exercise - System Force IT

How to Run a Cyber Incident Tabletop Exercise

A cyber incident plan that has never been rehearsed is just a set of assumptions in a document. The first time you find out that your emergency admin password is locked in a vault that itself needs that admin account to open, is during the incident, unless you tested it first. A tabletop exercise is the cheapest, lowest-risk way to find those gaps before an attacker does.

This guide explains what a tabletop exercise is, why it works, and exactly how to run one at a UK SME, even if you have never done it before. It is a companion to our full cyber incident response plan guide, and the free Cyber Incident Response Toolkit includes four ready-to-run scenarios you can use straight away.

What a tabletop exercise actually is

A tabletop exercise is a guided, talk-through rehearsal. You gather the people who would respond to a real incident, present them with a realistic scenario, and work through what they would actually do, decision by decision. Nobody touches a live system. It is a discussion, not a technical drill, and it usually takes about an hour. The point is not to test whether people know the “right answer”, it is to surface the gaps in your plan, your roles, your contacts and your assumptions, while it is safe and cheap to fix them.

Tabletop exercises sit alongside two more hands-on kinds of rehearsal. Technical exercises actually test the mechanics, such as isolating a machine or restoring a backup. Recovery exercises prove you can bring core services back. Start with tabletops, because they are the easiest to run and reveal the most for the least effort.

Who should be in the room

Invite the people who would run a real incident, thinking in functions rather than job titles: whoever would lead, your technical person or IT provider, someone who understands the business impact, whoever handles communications, someone who can speak to data-protection and legal questions, and a decision maker who can authorise significant actions. For a small business, that might be five or six people, and some will wear more than one hat. Keep it small enough that everyone contributes.

How to plan one

  • Pick a realistic scenario relevant to your business. Ransomware, a compromised Microsoft 365 account and invoice fraud, a stolen laptop, and a supplier breach are the four we see most.
  • Nominate a facilitator to run the session and keep it moving. It does not have to be the most technical person.
  • Nominate a note-taker to capture decisions, gaps and actions.
  • Prepare a short scenario and a handful of “injects”, new pieces of information you release as the exercise unfolds to keep it moving and raise the pressure.
  • Set aside about an hour, and make it clear this is a no-blame learning exercise, not a test of individuals.

How to run it

Read out the opening scenario, then work through it as a group. Release each inject in turn and pause for discussion. The facilitator’s job is to keep asking the useful questions: who leads now, what do we do first, who do we call, what do we tell people, what evidence do we need, what would make this worse? There are no trick questions. When the group gets stuck or disagrees, that is exactly the gap you came to find.

A worked example inject: “It is 08:40. Finance reports that a customer has received new bank details from the compromised mailbox.” Then ask the room: What changes now? Who needs involving? What evidence do you need? What do you stop? What do you communicate, and to whom? The disagreement and hesitation this provokes is the valuable part.

Capture what you learn

The exercise is only worth running if you act on it. In the last ten minutes, turn the gaps you found into a short list of actions, each with an owner, a priority and a due date. Typical findings include: nobody was sure who could authorise disconnecting the internet, the offline contact list was out of date, the backup restore had never actually been tested, or the plan lived only in Microsoft 365 and could not be read during a Microsoft 365 outage. Every one of those is cheaper to fix now than to discover live.

How often to run one

Match the frequency to your risk rather than a made-up legal interval. For most SMEs, a tabletop exercise once or twice a year is a sensible floor, plus a run after any significant change to your systems and after any real incident. The NCSC’s free Exercise in a Box is a good, no-cost resource, and the four scenarios in our toolkit are written to run in about an hour each.

Prefer to run your first one with help?

We run cyber-security webinars that walk teams through these exact scenarios, and we can facilitate a tabletop exercise for your business so your first one is guided rather than guessed.

See upcoming webinars

Frequently asked questions

What is a cyber incident tabletop exercise?

It is a guided, talk-through rehearsal of a cyber incident. You gather the people who would respond, present a realistic scenario, and work through what you would actually do, without touching any live systems. It usually takes about an hour and is designed to find gaps in your plan, roles and contacts before a real incident does.

Who should take part in a tabletop exercise?

The people who would run a real incident: whoever leads, your technical person or IT provider, someone who understands business impact, whoever handles communications, someone for data-protection and legal questions, and a decision maker. In a small business, five or six people is plenty, and some will cover more than one role.

How often should we run one?

Match it to your risk. For most SMEs, once or twice a year is a reasonable minimum, plus a run after any significant change to your systems and after any real incident. The value comes from acting on what you find each time.

Do we need special software to run a tabletop?

No. A tabletop is a discussion, so you only need a room, a facilitator, a note-taker and a scenario. Free resources like the NCSC’s Exercise in a Box and the four ready-to-run scenarios in our toolkit give you everything you need to start.

Related reading: the full Cyber Incident Response Plan guide, how to test your disaster recovery plan, and the free Cyber Incident Response Toolkit with four tabletop scenarios.

Practical guidance from System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name