Find the gaps in your incident response before a real incident finds them for you.

A facilitated simulation that tests decision-making, communication, and escalation under pressure - with none of the actual damage.

Best practice: test the plan before you need it

Most organisations have an Incident Response plan, a Disaster Recovery plan, or a Business Continuity Plan sitting in a folder somewhere. Few have tested whether the people named in those plans would actually make the right calls, in the right order, under time pressure.

A tabletop exercise (TTX) is a facilitated simulation of a realistic cyber incident. It is run in a room, not on a network. No systems are touched and no data is at risk. What gets tested is your people and your process: who has authority to make which decision, how fast information moves between technical and executive teams, and where your escalation and communication plans hold up or fall apart.

For resource-constrained organisations, this is one of the highest-value, lowest-disruption ways to find out whether your plan works before a real incident forces the answer on you.

Some of the most valuable exercises we run are for organisations with nothing documented at all. In that setting, the exercise does a different job: it puts your executive team in front of a realistic scenario and lets them discover, in real time, that they can't simply wing it. That realisation is usually what gets the budget released for the IR, DR, and BCP work that follows. A TTX is as useful for building the case for preparation as it is for testing preparation that already exists.

Exercise design draws on recognised frameworks for structuring test, training, and exercise programs, including guidance such as NIST SP 800-84, adapted for a business decision-making audience rather than a technical one.

How the exercise runs

Every engagement starts with a short scoping questionnaire, so the scenario is built around your organisation, not a generic template. From there, delivery runs in three stages, scoped in writing before the session is booked.

1. Preparation

We agree objectives, focus area, and target audience, then build a scenario and exhibits around your actual Incident Response, Disaster Recovery, and Business Continuity documentation, where it exists. If it doesn't exist yet, we build the scenario around a lightweight escalation structure instead. A moderator and scribe are provided for the session.

3. Post-exercise analysis

A structured debrief, a short participant survey, and an after-action report covering findings, gaps, and prioritised recommendations - delivered to your main stakeholder with a follow-up discussion.

What you get

  • A facilitated exercise session, typically 90 minutes to half a day
  • A scenario and exhibit pack built around your organisation, not a generic template
  • An after-action report rating performance from Strong to Not Yet Tested across detection, containment, communication, and recovery, with prioritised recommendations
  • A debrief session presenting findings to your leadership team

Common scenario types

  • Phishing attack escalating to ransomware and data breach
  • Business email compromise and payment redirection
  • Third-party or supply chain compromise
  • Insider threat
  • Cloud or SaaS account compromise

Scenarios are built around your industry, your systems, and the threats most relevant to your organisation - not a generic template.

What's out of scope

  • Any physical access to your premises, systems, or applications
  • Deep technical simulation or system-level intervention
  • Non-cyber scenarios (natural disaster, pandemic, and similar)
  • Implementing recommendations after the fact - we tell you what to fix, actioning it is a client-side activity

Not sure if a tabletop exercise is the right starting point?

Tell us where your incident response plan stands today. We'll tell you honestly whether a TTX is the right next step, or whether you need something else first.

Book a free call