A cyber tabletop exercise is how organisations find out whether their incident response plan actually works, before an attacker forces the answer. Most plans have never been tested under pressure. Most security teams find this out the hard way.
A cyberattack doesn’t care about your documentation. When ransomware hits on a Friday afternoon, or your CFO gets a call from what sounds like the CEO asking to wire funds, what matters is whether the right people know what to do, who to call, and how to decide with maybe 30% of the information they’d like.
So what actually is a tabletop exercise?
A tabletop exercise (TTX) is a guided, discussion-based cybersecurity simulation. You gather the people who would actually respond to an incident, walk them through a realistic attack scenario, and see what happens. No live systems are touched. No actual disruption occurs. But the conversations that come out of it? Those are very real.
Think of it as a fire drill, but for your organisation’s decision-making. Instead of testing whether the fire exits work, you’re testing whether your team knows who has authority to pull the plug on a production system, who calls the regulator, and what your communications team says publicly before you even know what’s been stolen.
Unlike a penetration test, which probes your technical defences, a cyber tabletop exercise probes your people and processes. And that’s usually where the scariest gaps hide.
The honest truth about incident response plans
Here’s a pattern that comes up constantly: an organisation has a solid, well-documented incident response plan. It covers containment, eradication, recovery, the works. But nobody has actually run through it together. Nobody has asked:
- What happens if the CISO is on holiday?
- What happens if two departments disagree about whether to go public?
- What happens if the third-party vendor you’re counting on for forensics has a 72-hour SLA?
A cybersecurity tabletop exercise stress-tests those assumptions in a safe environment. It finds the gaps in your cyber incident response plan before an attacker does. And the findings almost always surprise people, regardless of how mature the security programme already is.
Who needs to be in the room?
This is one of the biggest misconceptions about tabletop exercises: that they’re just for the IT or security team. They’re not.
Cybersecurity incidents are business crises. They involve legal decisions, regulatory notifications, board communications, HR issues, supplier relationships, and public statements. Your Computer Security Incident Response Team (CSIRT) handles the technical response, but your Crisis Management Team (CMT) handles everything that happens around it. Both need to practice, and both need to practice separately before they can work well together.
Regulatory frameworks are starting to make this explicit. NIS2 requires covered organisations to have tested incident handling capabilities. DORA, which targets financial entities, mandates operational resilience testing. Cyber insurance underwriters are increasingly asking for evidence that incident response plans have actually been rehearsed, not just written. A tabletop exercise creates that evidence.
Two exercises, two very different conversations
At Refracted, we run cyber tabletop exercises for two distinct groups. They cover the same incident, but from completely different angles.
The CSIRT Tabletop
Your Computer Security Incident Response Team (CSIRT) is the technical engine of your response. They need to analyse what’s happening, contain the damage, preserve forensic evidence, and start the clock on recovery. In a CSIRT tabletop, we put that team through a realistic attack scenario (a phishing campaign that leads to credential compromise, a supply chain attack, ransomware spreading across the network) and we keep introducing complications as they respond.
New evidence surfaces. The scope turns out to be bigger than expected. A key system isn’t available. These “injects” mirror how real incidents actually develop, and they reveal whether the team’s playbooks are fit for purpose or whether they’ve been living in a document nobody reads.
The CMT Tabletop
While the technical team is triaging, your Crisis Management Team (CMT) is facing a completely different set of decisions:
- Do we notify customers before we know the full extent of the breach?
- Who is the spokesperson?
- What do we tell the board, and when?
- Do we involve law enforcement?
A CMT tabletop exercise runs at the strategic level, with executives, legal counsel, communications leads, and business unit heads working through these questions in real time. The point isn’t to get the “right” answers, because often there aren’t any. It’s to build the shared understanding and communication muscle that makes leadership decisive when speed actually matters.
What a tabletop exercise looks like in practice
A well-run cybersecurity simulation exercise isn’t a lecture or a workshop. It’s closer to live improv: structured, but responsive. A skilled facilitator introduces the scenario, drives the narrative forward with timed injects, and probes responses without letting the team settle into comfortable assumptions.
After the exercise, you get a hot debrief while observations are fresh, followed by a written report with prioritised findings. Those findings don’t just show you what went wrong. They give you a concrete roadmap for improving your cyber resilience posture.
The facilitator matters more than most people expect. Someone who wrote your incident response plan will unconsciously steer the exercise toward comfortable outcomes. An external facilitator from a cybersecurity firm like Refracted brings a different kind of pressure, and usually surfaces things an internal team would never surface themselves.
How often should you be running them?
Once a year is a reasonable starting point. But organisations with mature security programmes run tabletop exercises more frequently, especially after significant infrastructure changes, key personnel changes, or a major incident in their sector that revealed new attack patterns.
Running CSIRT and CMT exercises separately first, before running a combined exercise that tests how both teams interact, tends to produce much better results. Each group builds depth in their own domain before the complexity of cross-team coordination gets layered in.
And if you’re subject to NIS2, DORA, or ISO 27001, the question isn’t really whether to run them. It’s how to make them as useful as possible.
The bottom line
Your incident response plan is a hypothesis. A cyber tabletop exercise is how you test it.
If you want to find out where your response capability actually stands, get in touch with Refracted. We design and facilitate tabletop exercises that are specific to your organisation, your threat landscape, and your regulatory context, because a generic exercise finds generic problems, and you deserve better than that.
People also ask:
It depends on where you are starting from. If your technical team has never rehearsed incident response together, start with a CSIRT exercise. If your leadership has never had to make real-time crisis decisions, a CMT exercise tends to be more urgent. Most organisations find that running both (separately first, then combined) gives them the most complete picture. The two exercises complement each other because they test entirely different failure modes.
You can, and some organisations do. The risk is that the person facilitating is usually too close to the plan to pressure-test it objectively. Internal teams tend to unconsciously steer scenarios toward outcomes they already know how to handle, which means the most valuable findings never surface. An external facilitator brings the discomfort that makes the exercise genuinely useful.
A tabletop exercise is usually most effective after you have an incident response plan in place and most effective before you have had to use it for real. It sits between planning and actual crisis response. Many organisations use the findings to update their plan, then retest the following year to validate that improvements held. For organisations subject to NIS2 or DORA, it also feeds directly into the evidence base for compliance.
Ransomware with data exfiltration tends to be the most requested, because it forces decisions across both technical response and crisis communication simultaneously. Business email compromise, supply chain attacks, and cloud account compromise are also common. The most useful scenarios are the ones tailored to your sector and your actual infrastructure, not generic templates used across every client.
