A tabletop exercise is a structured conversation about a disaster that has not happened. No systems are touched and nothing is at risk. The entire value comes from discovering, in a conference room on a Tuesday, the questions nobody can answer.
Setup
Element
Detail
Participants
Six to eight maximum: owner or CEO, finance lead, operations lead, IT lead or provider representative, someone who speaks to customers, plus counsel and HR if you have them
Facilitator
One person who presents, asks, and takes notes. They do not participate
Duration
60 minutes, hard stop
Rules
Phones down. No lookups. The point is to find out what is known, not what is findable
Frequency
Annually. The first one will be uncomfortable, which is the point of doing it in a conference room rather than at 6:40 on a Monday
Scenario A: the standard opening
It is 6:40 on a Monday morning. Your operations manager arrives early and cannot log in. Neither can anyone else. Every workstation shows the same message: your files are encrypted, and there is a payment demand with a countdown. The file server is unreachable. The phone system, which runs on the same network, is dead. Somebody's personal cell phone is the only working communication in the building.
Read it cold. Start the clock. Do not soften it, and do not answer questions about what "really" happened.
Minutes 0 to 15: response
Who is called first, and how does the person calling reach them without the company phone system or email?
Who has authority to disconnect the network, and are they physically able to reach the equipment?
How do you tell 40 employees not to come in, or not to touch their machines, when your email is encrypted?
Where is the incident response plan stored? (If the answer is on the file server, the room usually goes quiet on its own.)
Who calls the insurance carrier, and what is the policy number? Almost no cyber policy allows you to hire your own forensics firm without approval, and doing so has caused coverage disputes.
Minutes 15 to 30: business continuity
Which operations can continue on paper, and does anyone still remember how?
How do you take orders, book appointments, or dispatch crews today?
Payroll runs Thursday. How does that happen?
Who calls your largest customer, what do they say, and who approves the wording?
This section usually produces the most valuable findings, because it is the part IT plans never cover and the part that determines whether the business survives.
Minutes 30 to 45: recovery and legal
Where is the most recent backup, when was it verified, and how long does a restore actually take? Ask for the measured number, not the target.
Assume data was taken as well as encrypted, which is now standard. What data would that be, and whose?
Arizona's breach notification statute has requirements and timelines. Who determines whether they are triggered, and who tells the affected people?
Do you have a lawyer's mobile number, right now, in a place you can reach without your systems?
Minutes 45 to 60: after-action
Go around the room. Each person names the single thing they did not know that they should have. Write everything down, assign an owner and a date to each gap, no more than three per person, and put the 30-day review on the calendar before anyone leaves.
Injects to drop in mid-exercise
Timing
Inject
What it tests
Minute 8
A local reporter has called the main line asking about an outage
Whether anyone is authorized to speak publicly
Minute 18
Your largest client emails asking why their portal is down
Customer communication under uncertainty
Minute 25
An employee mentions they clicked something on Friday
Whether reporting is safe, and evidence handling
Minute 33
The attacker emails a sample of your client data
Shift from encryption to extortion and disclosure
Minute 40
The backup restore fails on the first attempt
Whether there is a second option or only hope
Scenario B: vendor compromise
Your practice management vendor notifies you at 4:50 on a Friday that they have suffered a security incident. They cannot yet say whether your data was involved. Their system is offline and they have no restoration estimate. Your Monday schedule is inside it.
Tests third-party dependency, contractual notification rights, and whether anyone knows what the contract actually says.
Scenario C: business email compromise
Your controller reports that a $84,000 payment went to a supplier's updated bank details three weeks ago. The supplier has just called asking why they have not been paid. The email requesting the change came from the supplier's real address.
Tests payment controls, recovery speed, insurance coverage for social engineering, and the difference between a technical breach and a procedural one.
The four gaps almost everyone finds
The response plan exists only on a system that would be encrypted. Print it and keep copies offsite.
No out-of-band communication method was agreed in advance. A group text thread with everyone's personal number, set up before the incident, solves this for free.
The insurance policy has requirements nobody has read.
The measured restore time is far longer than the assumed one, and often nobody has measured it at all.
None of those four cost money to fix. They cost an hour of attention.
After-action record
Gap identified
Owner
Due date
Verified
An exercise with no assigned follow-up is an entertaining hour that changes nothing. 30-day review scheduled for: