What Is a Tabletop Exercise?

Also called: Tabletop drill, TTX

Related problems: We have an incident response plan but have never tested it; Not sure who makes the call to shut systems down or pay a ransom; Cyber insurer or board asking whether we rehearse incidents; Executives have never practiced a breach scenario together

A tabletop exercise is a structured, discussion-based rehearsal in which a team talks through a realistic incident scenario, such as a ransomware attack or a data breach, step by step. A facilitator presents the situation in stages and asks participants what they would do, who they would call and what they would decide. The goal is to find gaps in the plan, roles and communication before a real incident does.

At a glance

  • It is a discussion around a table or video call: no systems are attacked, shut down or changed.
  • A facilitator walks the group through a scenario in stages, adding new information (“injects”) as it unfolds.
  • It tests people, decisions and the written plan, not the technology itself.
  • Sessions commonly run two to four hours and end with a list of gaps and owners for fixing them.
  • Insurers, auditors, customers and boards often ask whether you run them and what you learned.

What problem it solves

Many organizations have an incident response (IR) plan that has never been used. It sits in a shared folder, names people who have since left, and assumes the email system and phone list will be available during the attack. Nobody has agreed who can authorize taking systems offline, who talks to the insurer, when to call outside counsel, or how to reach staff if the usual tools are down.

These questions are much harder to answer in the middle of a real incident, under time pressure, than in a planned meeting. A tabletop exercise surfaces them in a low-stakes setting. It also gives executives a feel for what an incident is like, which often changes how they prioritize security spending and how quickly they make decisions when it matters.

How it works

Planning. The organizer picks objectives (for example, test ransomware decision-making, or test breach notification steps), chooses participants and builds a scenario that fits the business. Good scenarios use your real systems, vendors and constraints rather than a generic story.

The session. A facilitator sets the scene (“Monday at 7 a.m., the help desk reports that file shares are unreadable”) and releases new developments in stages: the attackers demand payment, a customer calls, a reporter emails, backups turn out to be affected. At each stage participants discuss what they would do, who decides and what they would say. A note-taker records decisions, disagreements and open questions.

Debrief and follow-up. At the end, the group reviews what worked and where the plan, contacts or authority were unclear. The output is an after-action report with specific fixes, owners and dates, such as updating the call tree, pre-approving containment actions with your managed detection provider, or confirming how to reach your insurer’s breach hotline. The fixes are the real value; a tabletop without follow-up is mostly theater.

Formats vary. Executive tabletops focus on business decisions such as ransom, disclosure and customer communication. Technical tabletops go deeper into detection, containment and recovery steps. Some organizations combine a tabletop with a test of business continuity and disaster recovery (BCDR) plans.

When it matters for buyers

  • When you write or update an incident response plan. A plan is a hypothesis until a team has walked through it.
  • When cyber insurance renews. Applications increasingly ask about incident response planning and testing; evidence of a recent exercise can help your answers.
  • When the board asks about cyber risk. An executive tabletop shows leadership what their role would be and builds a record that the risk is being managed.
  • When you sign or renew an incident response retainer. Many retainers include an exercise, and running one is a good way to test how the firm and your team would work together.
  • After a peer is hit by ransomware. A scenario based on a real, recent attack in your industry gets attention and is easy to make concrete.

Questions to ask vendors

  • Will the scenario be built around our systems, vendors and industry, or is it a standard script?
  • Who facilitates, and have they handled real incidents of the kind we are rehearsing?
  • Do you run separate executive and technical sessions, or can you combine them?
  • What will the after-action report include, and will it assign specific fixes and owners?
  • Can the exercise involve our outside parties, such as our MSP, MDR provider, insurer’s breach panel or outside counsel?
  • Is a tabletop included in our incident response retainer or managed security contract, and how many per year?
  • How will you help us track whether the fixes from the last exercise were completed?

How it differs from a penetration test

A penetration test is a technical assessment in which testers try to break into your systems to find weaknesses an attacker could use. A tabletop exercise assumes something has already gone wrong and tests how your people respond: who decides, who communicates and whether the plan works. The two answer different questions, so many security programs use both. For help planning exercises and response, see our incident response overview.

Frequently Asked Questions

How long does a tabletop exercise take?
Most run between two and four hours, including a short debrief. Executive sessions are often shorter and focus on decisions; technical sessions can run longer and go deeper into containment and recovery steps.
Who should attend a tabletop exercise?
Everyone with a role in the plan: IT and security, plus the people who make business decisions during an incident, such as executives, legal, communications, finance and HR. Many organizations run separate technical and executive sessions so each group can work at the right level of detail.
How often should we run one?
Many organizations aim for at least once a year, and again after major changes such as a new plan, an acquisition, new key systems or turnover in key roles. Some frameworks, contracts and insurers expect regular testing, so check what applies to you.
Do we need an outside facilitator?
Not necessarily, but an outside facilitator from an incident response firm, MSSP or advisor brings realistic scenarios, keeps the session moving and can ask uncomfortable questions an employee might avoid. Some incident response retainers include a tabletop exercise.
Is a tabletop exercise the same as a penetration test?
No. A penetration test checks whether attackers could break into your systems. A tabletop exercise is a discussion that checks how your people and processes would respond once something has gone wrong. Nothing technical is attacked or changed during a tabletop.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.