A tabletop exercise is the cheapest way to find out whether your incident plan works before an attacker tests it for you. You gather the right people, walk through a realistic scenario, and see where the plan holds and where it falls apart. No systems go offline, and nobody gets graded.
What a tabletop exercise is (and what it is not)
Think of it as a fire drill for decisions. A facilitator describes an unfolding event in stages. Then the group talks through what they would do, who they would call, and what they would need.
It is not a penetration test. It is also not a technical recovery test, where you actually restore servers from backup. Those matter too, but they answer different questions.
Instead, a tabletop tests the human side of a crisis. For example, who has authority to shut down email, and who calls the insurance carrier?
Someone also has to tell staff what to say to customers. In my experience, those questions stall a real response far longer than any technical problem.
Why rehearsal matters for a 50-person organization
Large enterprises run these drills every year. Smaller organizations often skip them because they assume attackers are not interested. However, the numbers say otherwise.
The FBI’s 2024 Internet Crime Report logged 859,532 complaints and more than $16 billion in reported losses. Many of those victims were ordinary businesses and nonprofits, not household names.
Also, the first hours of an incident are expensive. Every minute spent hunting for a phone number or debating who is in charge is a minute the attacker keeps working. Rehearsal compresses that confusion into a conference room, where it costs nothing.
Who belongs in the room
Keep the group small enough to talk, usually six to ten people. Next, make sure each person has a real role in a real incident.
- An executive with authority to approve spending, downtime, and outside help.
- Your IT lead or provider, who knows what is technically possible and how long it takes.
- Finance, because many incidents involve payments, payroll, or wire fraud.
- HR or operations, who will handle staff communication and scheduling.
- Whoever owns client or donor relationships, since someone has to decide what to tell them.
Optionally, invite your insurance broker or outside counsel. They often surprise people with requirements nobody knew about, such as approved vendor lists.
Pick a scenario that could happen to you next week
The best scenarios feel uncomfortably plausible. Avoid movie plots. Instead, start from how organizations your size actually get hurt.
Three scenarios worth starting with
Business email compromise. The controller receives a convincing request to change a vendor’s bank details, and a payment goes out. Now what?
Ransomware on a Monday morning. Staff arrive to find files encrypted and a ransom note on every screen. Meanwhile, payroll runs Wednesday.
A departed employee with lingering access. Someone who left months ago still has a working login to your file sharing, and data starts moving.
If you want ready-made material, CISA’s Tabletop Exercise Packages include scenarios, discussion questions, and after-action templates at no cost.
How to run a tabletop exercise in 90 minutes
You do not need a full day. A focused session works well if you follow a simple structure.
- Set ground rules (5 minutes). Explain that this is a no-fault discussion. The goal is finding gaps, not blaming people.
- Deliver the first inject (15 minutes). Describe the opening situation only. Ask each person what they notice and what they do first.
- Escalate the scenario (30 minutes). Add two or three new developments, such as a press call or a second compromised account. Then watch how decisions change.
- Test the plan against reality (15 minutes). Open your written incident plan. Check whether it answered the questions people just asked.
- Capture gaps (15 minutes). List every “we don’t know” moment. For example, missing contacts, unclear authority, or untested backups.
- Assign owners (10 minutes). Give each gap a name and a due date before anyone leaves the room.
Finally, appoint a note-taker who does not participate. The facilitator should not be the person writing things down.
The questions that expose real gaps
Good facilitators push past easy answers. So when someone says “we’d call IT,” ask which number they would dial.
Then raise the stakes. What if it is 7 p.m. on a Friday, and email is down, and email is how you normally reach them?
A few other questions consistently reveal weak spots:
First, where is the offline copy of your contact list and incident plan? Second, who can authorize taking a system offline without waiting for the owner? Third, what does your cyber insurance policy require you to do in the first 24 hours?
Also, ask how you would know the incident is over. Recovery criteria are often missing entirely. As a result, organizations reopen systems before the attacker is fully removed.
After the exercise: turn findings into work
This is where most organizations fall short. The session ends, everyone agrees it was useful, and the list of gaps disappears into a shared drive.
Instead, treat the findings like a project. Write a short after-action report within a week, then track each item until someone closes it.
Common fixes include updating contact lists, clarifying decision authority, and testing a backup restore.
Also, map your plan to current guidance. NIST updated its incident response recommendations in April 2025 with SP 800-61 Revision 3, which ties response to the broader Cybersecurity Framework 2.0. It is a useful reference when you revise your plan.
Finally, schedule the next tabletop exercise before you close out this one. Once a year is a reasonable minimum. After a major change, such as a new provider or a merger, run one sooner.
How WEBIT approaches this
We treat incident rehearsal as part of ongoing planning, not a one-time event. It fits naturally into our strategic IT planning, because the gaps a drill uncovers usually become roadmap items.
We also bring the technical reality into the room. When someone asks how long a restore takes, we answer with what we have actually tested. That candor is the point, and it shapes how we build cybersecurity programs for clients.
Key takeaways
- A tabletop tests decisions and communication, not just technology.
- Keep the group small and include people with real authority.
- Use plausible scenarios, such as email fraud or ransomware.
- Every gap needs an owner and a due date before the meeting ends.
- Repeat the drill at least once a year and after major changes.
Related from WEBIT: cyber insurance readiness checklist and downtime cost calculator.
Want help running your first drill? Talk to an owner.





