Home / Services / Tabletop exercises
Service

Tabletop Exercises

A guided, discussion-based drill that tests how your team would actually respond to an incident — before you find out the hard way.

What it is

A tabletop exercise walks your team through a realistic incident scenario, step by step, in a room (or a call) with no live systems involved. People talk through what they’d do, and the gaps surface naturally — the decision nobody owns, the contact list that’s out of date, the assumption two departments each thought the other was handling. It’s the cheapest way to find out where your plan breaks.

What’s included

  • A scenario tailored to your industry — ransomware, wire fraud, account takeover, vendor breach, and more
  • Facilitated discussion with structured injects that escalate realistically
  • Participation from leadership, IT, and any relevant business function
  • Built on the CISA CTEP methodology, sized for a smaller organization
  • No live systems touched and no technical setup required
  • A written after-action report with findings and recommendations

Who it’s for

  • Leadership teams who have never rehearsed an incident
  • Companies with an incident response plan that’s never been tested
  • Businesses facing an insurer or client asking whether they run exercises
  • Organizations in regulated industries with exercise requirements
Engagement
Starting at $2000
Final pricing depends on the size of your organization and scope. We’ll quote before any work begins.
Request a quote
FormatOn-site or remote
Session length2–3 hours
Participants6–12 typical
MethodCISA CTEP-based

How it works

A bounded engagement with a clear start and finish.

  1. Scope

    We pick a scenario that reflects a real threat to your business and agree who should be in the room.

  2. Prepare

    We build the scenario, the injects, and a read-ahead so participants arrive ready.

  3. Facilitate

    We run the exercise — typically 2–3 hours — keeping discussion focused and drawing out the gaps.

  4. Capture

    We document decisions, gaps, and open questions as they surface during the session.

  5. Report

    You receive an after-action report with prioritized findings and a concrete improvement plan.

What you get

Everything is delivered in plain language, written for owners and managers as well as technical staff.

Common questions

Do we need technical staff to participate?

No — and it’s better if you don’t only bring technical staff. The most valuable exercises include leadership, operations, finance, and whoever would talk to clients.

What if we don’t have an incident response plan yet?

That’s a common starting point, and the exercise is still worth running — it shows you exactly what the plan needs to cover. We can help build the plan afterward.

Is this stressful for participants?

It shouldn’t be. Exercises are explicitly no-fault and non-attributional. The point is to find gaps in the plan, never to grade people.

Next step

Let’s scope it together.

Tell us a little about your business and we’ll come back with a clear scope and a fixed quote — no obligation.

Request a quote