Most organisations have an Incident Response plan, a Disaster Recovery plan, or a Business Continuity Plan sitting in a folder somewhere. Few have tested whether the people named in those plans would actually make the right calls, in the right order, under time pressure.
A tabletop exercise (TTX) is a facilitated simulation of a realistic cyber incident. It is run in a room, not on a network. No systems are touched and no data is at risk. What gets tested is your people and your process: who has authority to make which decision, how fast information moves between technical and executive teams, and where your escalation and communication plans hold up or fall apart.
For resource-constrained organisations, this is one of the highest-value, lowest-disruption ways to find out whether your plan works before a real incident forces the answer on you.
Some of the most valuable exercises we run are for organisations with nothing documented at all. In that setting, the exercise does a different job: it puts your executive team in front of a realistic scenario and lets them discover, in real time, that they can't simply wing it. That realisation is usually what gets the budget released for the IR, DR, and BCP work that follows. A TTX is as useful for building the case for preparation as it is for testing preparation that already exists.
Exercise design draws on recognised frameworks for structuring test, training, and exercise programs, including guidance such as NIST SP 800-84, adapted for a business decision-making audience rather than a technical one.