How to Run a Cyber Incident Tabletop Exercise
A cyber incident plan that has never been rehearsed is just a set of assumptions in a document. The first time you find out that your emergency admin password is locked in a vault that itself needs that admin account to open, is during the incident, unless you tested it first. A tabletop exercise is the cheapest, lowest-risk way to find those gaps before an attacker does.
This guide explains what a tabletop exercise is, why it works, and exactly how to run one at a UK SME, even if you have never done it before. It is a companion to our full cyber incident response plan guide, and the free Cyber Incident Response Toolkit includes four ready-to-run scenarios you can use straight away.
What a tabletop exercise actually is
A tabletop exercise is a guided, talk-through rehearsal. You gather the people who would respond to a real incident, present them with a realistic scenario, and work through what they would actually do, decision by decision. Nobody touches a live system. It is a discussion, not a technical drill, and it usually takes about an hour. The point is not to test whether people know the “right answer”, it is to surface the gaps in your plan, your roles, your contacts and your assumptions, while it is safe and cheap to fix them.
Who should be in the room
Invite the people who would run a real incident, thinking in functions rather than job titles: whoever would lead, your technical person or IT provider, someone who understands the business impact, whoever handles communications, someone who can speak to data-protection and legal questions, and a decision maker who can authorise significant actions. For a small business, that might be five or six people, and some will wear more than one hat. Keep it small enough that everyone contributes.
How to plan one
- Pick a realistic scenario relevant to your business. Ransomware, a compromised Microsoft 365 account and invoice fraud, a stolen laptop, and a supplier breach are the four we see most.
- Nominate a facilitator to run the session and keep it moving. It does not have to be the most technical person.
- Nominate a note-taker to capture decisions, gaps and actions.
- Prepare a short scenario and a handful of “injects”, new pieces of information you release as the exercise unfolds to keep it moving and raise the pressure.
- Set aside about an hour, and make it clear this is a no-blame learning exercise, not a test of individuals.
How to run it
Read out the opening scenario, then work through it as a group. Release each inject in turn and pause for discussion. The facilitator’s job is to keep asking the useful questions: who leads now, what do we do first, who do we call, what do we tell people, what evidence do we need, what would make this worse? There are no trick questions. When the group gets stuck or disagrees, that is exactly the gap you came to find.
Capture what you learn
The exercise is only worth running if you act on it. In the last ten minutes, turn the gaps you found into a short list of actions, each with an owner, a priority and a due date. Typical findings include: nobody was sure who could authorise disconnecting the internet, the offline contact list was out of date, the backup restore had never actually been tested, or the plan lived only in Microsoft 365 and could not be read during a Microsoft 365 outage. Every one of those is cheaper to fix now than to discover live.
How often to run one
Match the frequency to your risk rather than a made-up legal interval. For most SMEs, a tabletop exercise once or twice a year is a sensible floor, plus a run after any significant change to your systems and after any real incident. The NCSC’s free Exercise in a Box is a good, no-cost resource, and the four scenarios in our toolkit are written to run in about an hour each.
Prefer to run your first one with help?
We run cyber-security webinars that walk teams through these exact scenarios, and we can facilitate a tabletop exercise for your business so your first one is guided rather than guessed.
Frequently asked questions
It is a guided, talk-through rehearsal of a cyber incident. You gather the people who would respond, present a realistic scenario, and work through what you would actually do, without touching any live systems. It usually takes about an hour and is designed to find gaps in your plan, roles and contacts before a real incident does.
The people who would run a real incident: whoever leads, your technical person or IT provider, someone who understands business impact, whoever handles communications, someone for data-protection and legal questions, and a decision maker. In a small business, five or six people is plenty, and some will cover more than one role.
Match it to your risk. For most SMEs, once or twice a year is a reasonable minimum, plus a run after any significant change to your systems and after any real incident. The value comes from acting on what you find each time.
No. A tabletop is a discussion, so you only need a room, a facilitator, a note-taker and a scenario. Free resources like the NCSC’s Exercise in a Box and the four ready-to-run scenarios in our toolkit give you everything you need to start.
Related reading: the full Cyber Incident Response Plan guide, how to test your disaster recovery plan, and the free Cyber Incident Response Toolkit with four tabletop scenarios.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


