Most tabletop exercises fail for one boring reason. They are not exercises. They are meetings with a scary slide deck, everyone talks, nobody is tested. ENISA recently published a cybersecurity exercise methodology for planners. It treats an exercise like a product launch. You plan, scope, build, run, measure, then improve. Three things I now push in fintech, and planning time is first. It is not a vibe, it is math. ENISA suggests a minimum of six months. They even give a rough formula for preparation time. More complexity and more stakeholder groups means more months, fast. Second, scope kills more exercises than attackers. If your scope is "test everything", results dilute fast. If it is "test the email server", reality disappears. Pick two or three critical processes. Map the dependencies, including vendors, handoffs, and comms. Be explicit on who plays, who observes, and who decides. Third, evaluation is the point. Without it, you ran training, not readiness. Set smart objectives with a clear measure of success. Define indicators, then metrics, then data sources. Decide what success looks like before day one. Build injects that force real decisions, at realistic pace. Use a master scenario event list as your conductor score. Your after action report becomes evidence, not opinion. Your action plan becomes prioritised, not hand waving. If your tabletop felt pointless, this is why, make it measurable or do not run it. #ENISA
Strengthening Cybersecurity Readiness Using Tabletop Exercises
Explore top LinkedIn content from expert professionals.
Summary
Strengthening cybersecurity readiness using tabletop exercises means practicing real-life crisis scenarios with your team to find weaknesses in your response plans before a cyber attack actually happens. Tabletop exercises are structured discussions where key people talk through hypothetical incidents, revealing gaps in communication, decision-making, and business processes that could leave the organization exposed.
- Choose realistic scenarios: Focus on probable situations, like account takeovers or ransomware, and involve people from different departments to see how your team would really respond.
- Test decision-making: Use tabletop exercises to identify who takes charge, who communicates with customers, and how critical actions are handled when systems are down.
- Document and improve: After each exercise, write down the gaps and confusion uncovered, then update your incident response plan so your team is better prepared for future threats.
-
-
50 Strategic Moves to Make Your Organization Crisis-Ready Most cybersecurity strategies fail one simple test: They look good on paper… But collapse in real-world decision-making. Cyber resilience isn’t built in tools. It’s built in how your organization responds under pressure. I’ve compiled 50 strategic moves behind one of the most underused leadership tools: 👉 Cyber Tabletop Exercises This isn’t about simulations. It’s about exposing how your business actually behaves during a crisis. What most organizations miss: They focus on: • Prevention • Detection • Technical controls But ignore the real risk: ❌ Decision delays ❌ Communication breakdowns ❌ Ownership confusion 1–12: Foundations → Understand response lifecycle → Define roles across IT, Legal, HR, Leadership → Shift mindset from prevention → readiness 13–25: Scenario Design → Ransomware + data exfiltration → BEC + AI phishing → Insider & supply chain threats 26–38: Advanced Simulation → Double extortion scenarios → Media & regulatory pressure → Executive decision-making under uncertainty 39–50: Maturity → Measure MTTR & response speed → Build continuous improvement loops → Turn exercises into a core business function A security plan tells you what should happen. A tabletop exercise shows you what actually will. The gap between those two? That’s where breaches become disasters. Be honest has your leadership team ever been tested in a realistic cyber crisis simulation? Follow Marcel Velica for more insights like this. And if this was valuable, reshare it with your network. If you want short daily thoughts, quick threat observations, and real-time discussions, follow me on X as well →https://x.com/MarcelVelica
-
If you haven’t practiced your incident plan lately, you don’t really have one. When something breaks, nobody opens a PDF. They grab phones and start guessing. Run a short tabletop: pick one scenario, run through it for 45 minutes, and see what would happen. Involve outside breach counsel. They’re the best quarterback for any incident, so bring them into the tabletop too. Then practice the plan, revise the plan, print the plan. How often? ↪ Full tabletop: every 6 months (or after major changes). ↪ Lighter drills: quicker single-scenario runs in between. ▶ Focus on: who declares the incident, how decisions are made, how you try to claw back money if it’s moved, and how you reach people if systems are down. ▶ Scenarios to choose from this week: Account takeover, Funds transfer fraud, Ransomware. #JasonMakevich #Cybersecurity #IncidentResponse #BusinessContinuity #Tabletop #RiskManagement
-
The cheapest security exercise you're probably not running takes six people, one hour, and a closed laptop. That's a tabletop. No tools, no budget, no vendor, no slide deck. And it'll tell you more about how your company handles a breach than any dashboard you own. Here's the whole thing. Pick a scenario that's actually likely. Not a nation-state zero-day. An employee's Microsoft 365 account gets taken over and starts emailing your customers new wire instructions. Write three sentences describing the opening moment. That's it. Get the right people in the room. Not just IT. Your CEO, your finance lead, whoever owns customer communication, your IT or MSP contact. The hard calls in a breach aren't technical ones. Run it in three 20-minute moves. Open with your three sentences, then go quiet and watch who takes charge. Twist it: "a reporter just emailed asking you to confirm the breach, deadline noon." Then debrief. What did we not know? What decision did we dodge? Who did we need who wasn't in the room? Write every gap on a whiteboard. Don't fix them in the meeting. The output of a tabletop isn't solutions. It's the list of things you didn't know you didn't know. Here's what you'll find. Your incident response plan lives in a folder nobody can reach with the network down. Three people think they're the one who calls the insurer, or nobody does. The MSP emergency line goes to voicemail after 6 p.m. "We'll just restore from backup" is a sentence nobody has actually tested. Cheap to learn in a conference room. Brutal to learn at 2 a.m. during the real thing. CISA publishes free tabletop packages (the CTEP series) with ready-made scenarios and facilitator guides. Steal from them. There's no prize for writing your own from scratch. The first time your leadership team makes a breach decision shouldn't be during a breach. An hour on Thursday is a cheap way to make sure it isn't. No pitch, just a conversation. Reach out. Full post: https://lnkd.in/eGDCrDWN
-
Your first cyber incident should not be the first time you test your cyber incident response plan. A lot of organisations have a plan sitting in a folder somewhere. It may even be a good plan. The problem is that nobody really knows if it works until the organisation has tested it under realistic conditions. That is a terrible thing to discover during a real breach, outage, ransomware event, or data exposure. Tabletop exercises are leadership rehearsal. They test who can declare an incident, who can authorise systems being taken offline, who contacts legal, who activates insurance, who speaks to customers, who briefs the board, and who decides which systems come back first. They also expose the assumptions that quietly sit inside recovery plans. Do the backups work? Who has access? How long would recovery actually take? Can the business run without email? What happens to payroll, dispatch, ticketing, finance, or customer service if the outage runs longer than expected? The goal is not to embarrass people or catch them out. The goal is to find the gaps while the cost of finding them is still low. Because discovering those gaps during a real incident can cost far more than an uncomfortable meeting... It can cost the business. Always happy to have a conversation around running tabletop exercises, one of the most fun things I get to do in my business. #Cybersecurity #IncidentResponse #CyberRisk #BusinessContinuity #DisasterRecovery #GRC #CyberGovernance #TabletopExercise #OperationalResilience #ExecutiveLeadership
-
I am excited to share that we’ve officially relaunched our Complete Guide to Running a Tabletop Exercise! Tabletop exercises are still one of the most under‑used and misunderstood tools in cyber resilience. Too many organisations treat them like a tick‑box exercise, or worse, run them once and assume they are “covered”. In reality, a well run tabletop will reveal more about your real‑world readiness than any piece of technology. It exposes assumptions. It forces decision makers to think under pressure. It uncovers the messy, human parts of a crisis that no playbook truly prepares you for. That is exactly why we created this guide - to help organisations run sessions that genuinely challenge them, spark uncomfortable but essential conversations, and ultimately improve their response capabilities.The updated edition includes: • Practical steps for planning, structuring, and facilitating a session • Common pitfalls and how to avoid them • Scenario building guidance grounded in real incident patterns • Advice on engaging executives and keeping the discussion meaningful • Tips for turning outcomes into lasting improvementsIf you want to elevate your exercises beyond surface‑level discussions and build real organisational resilience, this new version will help you do it You can download the updated guide now. And if you run an exercise using it, I’d love to hear how you got on — the insights we gather from the real world are what keep our work sharp, relevant, and impactful. Link in Comments
-
Every CISO faces a critical moment: It’s 9:14 AM on a Monday. Production is down. Legal is on speakerphone. The CFO is asking what to tell the board. The PR team wants a statement. The ransomware note is on every screen. And then someone asks: "what's our incident response plan?" The honest answer in too many companies is: "we have a binder." A binder is not a plan. A plan is something you've practiced. That’s where a Tabletop Exercise (TTX) comes in. We gather your team — IT, security, legal, communications, executive — and walk through a realistic scenario together. Whether it’s ransomware, insider data theft, third-party breach, or business email compromise, we pause at decision points and ask: • What do you do here? • Who calls who? • Who has authority? • Where's the backup? What you walk away with: • A clear gap analysis • Updated, useful IR runbooks • A team that has actually practiced the moves once • Documentation that satisfies cyber insurance carriers and SOC 2/HIPAA/CMMC auditors The first time your team runs the play should not be the day it’s real. We can run a tabletop in a half-day. The cost is a fraction of a single hour of unplanned downtime. Worth a conversation.
-
Here's how to run a tabletop exercise that does more than check a compliance box. Involve the right people. The actual incident response team — not just executives. The people who pull logs, isolate systems, and make calls under pressure. If they're not in the room, you're rehearsing the wrong play. Use a realistic scenario. Not "a sophisticated nation-state attacked us." Use something that happened to a company in your industry in the last 18 months. Ransomware via a vendor connection. A compromised admin account. BEC on a wire transfer. Focus on decision points. Who authorizes paying a ransom? Who contacts legal? When do you notify customers? These questions come up every time. If you don't have answers before an incident, you'll find them during — which is the worst possible moment. Debrief honestly. Write down what broke down and actually update the plan.
-
I'm putting together a step-by-step guide on building and leading effective cyber tabletops. I've spent over 6 years running cyber tabletops on a monthly cadence. From my experience, it's tempting to focus on obscure APT campaigns. But orgs should be taking a risk-based approach to crafting exercises, based on real threat intelligence. For example, instead of running a generic phishing exercise, drill how your help desk would handle a vishing call where attackers impersonate a locked-out employee, use publicly available details to pass identity checks, and convince agents to reset MFA credentials. Over 70% of these attacks now use Google Voice to appear legitimate. Let's not stop there. - How would your SOC react if an attacker called your help desk at 2 AM claiming to be a "traveling executive" who needs urgent email access, and your team sees legitimate VPN logs from that user's account? - What happens when your incident commander gets locked out of Slack during a live ransomware event because the attacker changed MFA settings for admin accounts? - How do you coordinate when your primary incident response tools (email, MS Teams, phone system) are all compromised and you're reduced to personal cell phones and Signal? The devil is in the details — and I'd be happy to share what I know with you in a comprehensive guide. Interested? Comment "guide" if you want a copy when it's ready, and I'll reach out to you 👇
-
💡 With the 3rd quarter Board meetings over, the trend I found in the Board discussions this year, is the question gradually shifting to 'is your business truly ready' from 'have the audit observations been closed'. 💡 This readiness is from a larger view of parameters such as operating efficiency, margins, risk management, people availability and more; but also includes technology robustness and security governance. And underlying on all the above, is regulatory compliance. 🔅 Let's discuss on technology regulatory compliance. - The new directives issued by the three lead regulators in India, viz, RBI, SEBI and IRDAI between 2023-24, with added guidelines in 2025, are more than regulations, they're the blueprints for survival in this digital age (if taken seriously). - The guidelines make clear that the technology backbone, digital practices and cybersecurity aren't just IT checkboxes anymore; they're about credibility, operationalizing trust into preparedness and bring board-level accountability. 🔑 For Tech and Cyber leaders and Chief Risk Officers, the mandate isn’t merely compliance — it’s a chance to lead transformation. 🔑 Building an operational, real-time, tested, trained #cybercrisismanagement framework, which goes beyond just a document in the shared drive, strengthens trust with policyholders, partners, and regulators alike. 🪝 However, most organizations fail or fall short in moving beyond documentation and checkbox exercises, and to demonstrate real readiness, resulting in regulatory penalties, inordinate delays in recovering from incidents, lack of visibility and control over critical vendors / service providers and so on. 💡 Let's take some examples : 1. In the 'Incident Response' Playbook : - Classify incidents (data breach, insider abuse, cloud infra unavailability etc) with severity levels, not only on the impact of the potential loss of business, but also with expenses (ex, consultants, forensic experts, additional server space, penalty etc) that may be incurred to recover and restore. - As part of the Tabletop exercises, conduct crisis simulations across primary, DC and DR - simultaneous and asynchronous; measure responses against the documented timelines and procedures for communication, containment, recovery; capture learning from the mistakes / gaps, improve the plan and training of relevant team members. 2. In the 'Crisis Communication' playbook : - Map each incident (as above) to escalation protocols. From SOC analysts to crisis coordinators to the CEO, every person should know their action - first 30 minutes, first 2 days, first week, if this goes beyond 1 week. - Design Crisis Communication scripts, in hard copy (systems may not be available during a cyberattack) for media, regulators, and customers Are you ready to translate compliance into strategic capability and competitive edge? Want to learn more? Let's talk! #CyberSecurity #RegTech #IncidentResponse #CyberResilience #RiskManagement #DigitalTrust
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development