Service
Tabletop exercises
Put your decision-makers inside a realistic cyber incident and ask them to decide, out loud, with the information they would really have.
A tabletop exercise (TTX) is a facilitated, discussion-based walk-through of an incident. No systems are touched and nothing is simulated on your network. The value is in what the discussion exposes: unclear ownership, playbooks nobody has read, untested assumptions about backups and recovery, and slow or contradictory communication under pressure.
We write the scenario around your sector, your systems and your people, run it with a neutral facilitator, and record every decision, assumption and gap so that the result is a list of concrete improvements rather than a pleasant afternoon.
Who it is for
Leadership, responders and the functions around them
Most real incidents are decided by people outside the SOC. We build the session around the roles that actually carry the decisions.
- Executives and crisis teamDecision rights, business impact, ransom and disclosure questions, board and regulator communication.
- IT, security and incident responseTriage, escalation, containment and recovery decisions; how the playbook meets reality.
- Legal, communications, HR, operationsNotification duties, customer and media handling, staffing and continuity of critical processes.
- Organisations with regulatory exposureNIS2 and DORA expect in-scope organisations to test incident handling and continuity. We design the exercise around those expectations; whether and how a requirement applies to you is a matter for you and your advisers.
Formats
Pick the depth that fits the audience
Formats can be combined into a programme, for example executive first, operational second, then a technical drill.
- Executive trackTwo to three hours. Strategic decisions, business impact, communication, regulator and board questions.
- Operational trackHalf a day. Cross-functional response: triage, escalation, containment, recovery, handovers.
- Combined, multi-stageA full day with the scenario unfolding in stages, executives and responders interacting through injects.
- On-site or remoteBoth work. Remote sessions use a shared board and a dedicated control channel. Typical scenarios: ransomware with data extortion, supplier or SaaS compromise, personal-data leak, insider misuse, extended outage.
How an engagement runs
From first call to improvement plan
Every step produces something you keep.
- 01
Scope
Objectives, participants, systems in play and constraints. Success criteria agreed before design starts.
- 02
Rules of engagement
Who takes part, what is in and out of bounds, confidentiality, how notes and evidence are handled.
- 03
Design
Threat-informed scenario and timed injects, reviewed with your exercise lead so nothing surprises the wrong person.
- 04
Deliver
Facilitator, scribe and observers. The scenario adapts to the decisions made; a hot debrief closes the day.
- 05
After-action report
Findings against the objectives, timeline, root causes and a prioritised improvement plan.
Deliverables
Documents that stand on their own
Written for the people who must act on them, not for the shelf.
- Exercise planobjectives, scope, roles, rules of engagement
- Scenario and inject listtiming, expected actions, facilitator notes
- Participant guidebriefing so everyone knows their role
- After-action reportfindings, timeline, evidence of decisions
- Improvement planprioritised actions with suggested owners
- Executive debriefa short readout for leadership
What we need from you
- A named exercise lead on your side
- The participant list and their roles
- Your existing incident response plan, continuity plan and contact tree, if they exist (their absence is also a useful finding)
- Agreement on what may be said to whom before the session starts
Next step
Scope your tabletop exercise
Tell us what you want to test and who should take part. We reply with a proposed format and next steps.
Also