Tabletop exercises · Board and technical
A cyber crisis tabletop exercise puts your actual decision-makers in a room and walks them through a realistic incident in real time. The output is not a certificate. It is a short list of the things that did not work — the contact list that was out of date, the decision nobody was authorised to make, the backup nobody could confirm.
Board-level · technical · combined · scenario written to your estate
The exercise
What actually gets tested
The technology is rarely the thing that fails. Decisions, authority and communication are.
Who decides to disconnect
Pulling a production system offline is a commercial decision with a technical trigger. Most organisations discover during the exercise that nobody is clearly authorised to make it at 02:00.
Whether the contact list works
Out-of-hours numbers, escalation paths and the third parties you would need — insurer, counsel, provider. Tested by actually trying to reach them on paper.
What you would tell whom
Customers, staff, regulators and press each need different things at different times. Drafting that under exercise pressure is far cheaper than drafting it under real pressure.
Whether the backup is a plan
The exercise asks what you would restore from, how long it would take and who has confirmed it recently. See backup and DR.
Where the plan is
A response plan on a file share that has just been encrypted is not a response plan. This gets discovered every time.
What the board actually needs
Directors need exposure, options and a decision. Exercises consistently show technical teams reporting detail instead.
The format
How we run one
A scenario is written against your estate — your systems, your suppliers, your regulatory context — because generic scenarios produce generic answers. It is facilitated in person or remotely, typically in a half day, and injects new information as the exercise progresses so that decisions have to be revisited under changed facts, which is what real incidents do.
The deliverable is a written findings report: what happened, where the plan held, where it did not, and a ranked list of fixes with owners. It is deliberately short enough to be read by the people who attended.
Facts change mid-exercise, because they do in real incidents.
We do not score you. An exercise that produces a pass mark has usually been designed to.
Scenario library
Scenarios worth running
| Scenario | What it really tests | Who should be in the room |
|---|---|---|
| Ransomware across the estate | Backup integrity, the authority to disconnect, and how you operate with your own systems unavailable. | Board, IT, finance, communications |
| Supplier breach | Whether you know what a third party can reach, and what your contract entitles you to ask them. | Procurement, legal, IT |
| Insider data removal | Detection, evidence handling and the HR-legal-security interface, which is rarely rehearsed. | HR, legal, security |
| Credential compromise of an executive | Escalation when the affected person is senior to the responder — a failure mode organisations reliably underestimate. | Executive team, IT |
| Extended outage at a single site | Continuity assumptions, and whether the recovery plan depends on people who are also affected. | Operations, IT, site leadership |
Scroll the table sideways on a narrow screen.
Related
Related work
These sit alongside this engagement more often than not:
Backup and disaster recovery
Tested recovery, which decides how a ransomware incident actually ends.
Questions
Cyber Crisis Tabletop Exercises & Incident Response Drills India, answered
What is a cyber crisis tabletop exercise?
A facilitated discussion-based simulation. Your real decision-makers work through a realistic incident scenario in real time, making the decisions they would actually have to make, while a facilitator injects new information as it develops.
Who should attend?
It depends on which failure you want to test. A board-level exercise needs directors and executives and tests decision-making and communication. A technical exercise needs the responders and tests containment and recovery. Running both, separately, then together, finds the most.
How long does an exercise take?
A focused exercise typically runs a half day including the debrief. Longer formats exist but attention is the binding constraint — a tired room stops making realistic decisions, and unrealistic decisions teach nothing.
Do you use a generic scenario?
No. The scenario is written against your estate, suppliers and regulatory context. A generic ransomware script produces generic answers and misses the specific dependency that would actually hurt you.
What do we get afterwards?
A written findings report: what happened, where the plan held, where it broke, and a ranked list of fixes with owners attached. Short enough that the attendees will actually read it.
How often should we run one?
Often enough that the contact list and the authority chain stay current, and after any material change — a migration, an acquisition, a change of provider or a turnover in the leadership team. Those are the moments a plan silently goes stale.
Next step
Talk to someone who has done this before
Tell us where you are and we will tell you what the work actually involves. If you do not need us, we will say so.



