Tabletop and cybersecurity exercises
How do I run a cybersecurity tabletop exercise?
For Security leaders, IT teams, executives, legal, communications, and operations
- Last updated
- Reading goal
- Plan and facilitate a cyber incident discussion exercise
Start here
Run a cybersecurity tabletop by choosing one credible incident, defining the decisions you want to examine, and bringing together every role that would detect, contain, communicate, authorize, or recover. Reveal the incident in short stages, ask what the team would do with the information available at that moment, document assumptions and dependencies, then turn the debrief into owned updates to plans, contacts, and decision rules.
What to prepare
- Exercise decision-making and coordination, not trivia about attack techniques.
- Include business, legal, communications, and executive roles when the objective requires them.
- Make injects plausible and tied to a specific objective.
- Do not call a discussion exercise proof of technical recovery capability.
What should a cyber tabletop exercise test?
Start with a decision or handoff that matters to the organization: when to escalate, who can isolate a system, how to preserve evidence, who approves customer communications, or how recovery priorities are set. NIST SP 800-84 treats exercises as part of a broader test, training, and exercise program for IT plans and capabilities; a tabletop is especially suited to roles, plans, communications, and coordination.National Institute of Standards and Technology
- Detection and internal escalation
- Incident command and decision authority
- Business impact assessment and service priorities
- Legal, regulatory, insurer, customer, and public communications decisions
- Third-party coordination and dependency management
- Recovery sequencing and return-to-service criteria
How do you design the scenario and injects?
Select one incident pattern
Use a credible pattern such as ransomware, compromised credentials, cloud-service disruption, or a third-party breach. Avoid combining every possible crisis into one exercise.
Write a plain-language opening
State what the organization knows, when it learned it, and what business service may be affected. Keep the technical detail proportionate to the audience.
Add three to five injects
Each inject should change a decision: a new indicator, an unavailable system, a customer inquiry, an executive request, or evidence that the impact is wider than first believed.
Map each inject to an objective
If an inject does not create evidence for an objective, cut it. This keeps the session useful and makes evaluation more defensible.
CISA publishes customizable tabletop packages and cybersecurity scenarios that pair scenarios with objectives, discussion questions, and references. Those public materials are useful starting points, but organizations should adapt names, systems, vendors, authorities, and notification paths to their actual environment.Cybersecurity and Infrastructure Security AgencyCybersecurity and Infrastructure Security Agency
What should happen during and after the session?
| Moment | Prompt | What to capture |
|---|---|---|
| First report | What do we know, and how reliable is it? | Facts, assumptions, missing evidence |
| Escalation | Who needs to be informed now, by whom? | Triggers, contacts, authority |
| Containment | What action is proposed and what could it disrupt? | Tradeoffs and approval path |
| External pressure | What can we say accurately at this point? | Message owner, review, timing |
| Recovery | Which service returns first and what makes that safe? | Priorities, dependencies, criteria |
Swipe or use the left and right arrow keys to see more
End with a short hotwash while details are fresh. Separate confirmed strengths, gaps, and open questions. Give each improvement action an owner and a target date, then schedule a follow-up check or a more operational test when the discussion exposed a capability that cannot be verified in a tabletop.Federal Emergency Management Agency
What Escape Scenario can and cannot test
Escape Scenario offers Cybersecurity Incident TTX as a selectable scenario for structured incident-prioritization discussion. It is currently selectable in the public catalog and asks the group to prioritize an incident and explain one team decision.
Use it to practice judgment, evidence-sharing, and debriefing. It cannot validate cybersecurity operations, certify readiness, or replace specialist advice.
Related practical questions
- Should executives attend a cybersecurity tabletop?
- Invite executives when the objectives involve enterprise priorities, public statements, material business impact, major spending, risk acceptance, or decisions reserved to senior leadership. They need not attend a technical drill that does not exercise those decisions.
- Should the scenario surprise participants?
- The specific injects can be unknown, but participants should know the purpose, scope, ground rules, and expected preparation. Surprise is not a substitute for a well-designed objective.
Sources and limits
NIST, CISA, and FEMA support the design and improvement guidance; they do not endorse Escape Scenario. We rechecked scenario availability and the product's validation limits on August 29, 2026.
- Guide to Test, Training, and Exercise Programs for IT Plans and CapabilitiesNational Institute of Standards and Technology, 2006. Guidance for designing, developing, conducting, and evaluating IT test, training, and exercise events.
- CISA Tabletop Exercise PackagesCybersecurity and Infrastructure Security Agency. Customizable packages with objectives, scenarios, discussion questions, and supporting references.
- Cybersecurity ScenariosCybersecurity and Infrastructure Security Agency. Public scenarios intended to help organizations discuss cybersecurity response decisions.
- Homeland Security Exercise and Evaluation ProgramFederal Emergency Management Agency. A common doctrine for exercise program management, design, conduct, evaluation, and improvement planning.