A tabletop exercise walks your team through a realistic incident scenario - discussion-based, no real systems touched - to test the plan, the decisions and the communication before a real crisis does it for you.
Why they're high-value
Most incidents go badly not because of missing tools, but missing decisions and coordination: who declares an incident, who talks to legal/PR, when do we pull the plug, who has authority. A tabletop surfaces those gaps cheaply.
How to run one
- Pick a realistic scenario - ransomware, a compromised admin, a data-exfil discovery. Map it to your actual environment.
- Get the right people - not just the SOC: IT, legal, comms, leadership, and a facilitator.
- Inject in stages - reveal the incident in steps ("shadow copies deleted"… "encryption started"… "media is calling") and ask what each person does now.
- Capture friction - every "who owns that?" or "we don't have that log" is a finding.
- Produce actions - assign owners and deadlines to close each gap; re-test later.
What to measure
Time-to-decision, clarity of roles, whether the plan was actually usable, and the concrete gaps found. A good tabletop ends with a punch list that makes the next real incident less painful.
