57% of major cyber incidents involve attack types teams never rehearsed. Too many tabletop exercises rely on familiar, dramatic attack scenarios... the kind people already expect. But the real danger is in what nobody saw coming: subtle lateral movement, quiet exfiltration, or chained compromises that don’t start with a big flash. To make exercises meaningful, they have to reflect your environment, your risks, your tech, your people. Teams should test contacting people, fallback comms, expired phone lists, even burner phone logistics. Those “mundane” failures often become the real showstoppers in a crisis. Real preparation is less about scripting a perfect drill and more about building adaptability, muscle memory for surprises, and resilience when chaos hits. #IncidentResponse #CyberReadiness #TabletopExercises
Tabletop Exercises for Emerging and Historical Risks
Explore top LinkedIn content from expert professionals.
Summary
Tabletop exercises for emerging and historical risks are structured simulations where teams rehearse how they would respond to various crisis scenarios, including both new and known threats. These exercises help organizations build preparedness by practicing decisions, communication, and coordination before real incidents occur.
- Tailor scenarios: Design exercises around your organization’s unique risks and systems, making sure each simulation mirrors realistic challenges your team could face.
- Test communication: Use the exercise to check how well your team communicates, including fallback methods and updating contact lists, so you’re ready when primary systems fail.
- Document readiness: Capture decision-making processes, actions taken, and areas for improvement during the exercise so you have tangible evidence of your preparedness for board reviews or audits.
-
-
How I Build “Engaging” ICS/OT (& IT) Incident Response Tabletop Exercises in 6 Steps (here's how) I have participated in and led more than a few tabletop exercises over the years. I have been fortunate to learn from some really great ones. And some REALLY bad ones. Here's my six-step process for creating a tabletop that participants will be engaged in: 1. Do the Research Do the research on the client and their environment. -> What is important to the client's industry? -> How does the client's industry make money? -> How do "general" cyber-attacks impact the industry? -> What are the most impactful cyber-attacks in their industry? 2. Understand the Environment EVERY environment is different. No matter if it is ICS/OT, IT or both. -> What critical systems exist? -> What does the IT network look like? -> What does the OT environment look like? -> Why is the business conducting the exercise? -> What happens if a critical system is compromised? -> What are the unique physics of their ICS/OT environment? 3. Create Realistic Scenarios Using the information gathered so far, it is time to design the scenario(s). -> Think like an attacker -> Ensure that the scenarios are realistic -> If you are not sure how an attack might work, do not use it -> Create scenarios based off of known attacks against their industry 4. Build Engaging Injects Injects are new pieces of information given to participants as the scenario unfolds. Like getting a new clue when solving a murder mystery. A few of the engaging ones I have used include: -> Realistic phishing emails designed to look exactly like one they would receive in their specific email client -> Fake Twitter and other social media feeds reporting a cyber-attack against the company -> Phone calls received (on speaker phone) by a participant - A security research calls into to report intel on hacker chatter of a breach of the company - How do the team members respond? - Someone calls in as a local reporter asking about a potential cyber-attack against the company - Will an employee share sensitive information openly with an outside party? 5. End with the Worst-Case Scenario Like in a risk assessment, the worst-case scenario for the company must be examined. This could include people being killed, injured, harm to the environment, and a site or the company becoming inoperable. Even worse? Is when it shows up on the news. Use a photo generator to create an image of their environment on the news that shows their worst-case scenario. 6. Finalize the Design WITH the Client It is your client's tabletop exercise, not yours. Make sure to meet their known needs and help them understand needs they might not be aware of. P.S. What do you think makes a good tabletop?
-
Tabletop Exercises: Crisis is Inevitable, but Decisive Board Leadership is a Choice Executive tabletop exercises are strategic rehearsals that translate cyber and crisis strategy into rapid, board-level decision readiness. By simulating high-pressure scenarios, they stress-test escalation paths, stakeholder trade-offs, communication, and governance approvals before a real crisis exposes weaknesses. Even more importantly, they build your team’s connective tissue and confidence. Done well, they turn governance into a measurable, repeatable capability. Three critical outcomes for boards and executives: 1. Decisions under pressure: Build the muscle memory to prioritise, delegate, and frame trade-offs so leaders act decisively with imperfect information. 2. Cross-stakeholder alignment: Rehearse coordination across board, legal, communications, regulators, and partners to reduce friction and expose policy gaps. 3. Governance artefacts: Validate decision triggers, KPIs, escalation thresholds, and reporting structures that boards require to discharge fiduciary duties. In line with NCSC guidance, executive rehearsals should be treated as a repeatable discipline that matures governance capability over time, not a one-off compliance exercise. Organisations that invest in executive rehearsal shorten reaction time, reduce strategic risk, and protect reputation when it matters most. Crisis is inevitable, but decisive board leadership is a choice. 👉 Are your leadership teams prepared to make the right calls under pressure? My work with boards shows that rehearsal makes the difference.
-
Had a great conversation this week with a CRO who made the demanding but rewarding move from CISO to CRO at a large BFSI organisation. He shared something that stayed with me. In a recent Board meeting, a Director asked him a simple but pointed question: “How do you know your incident response playbooks actually work as intended?” Not “do you have an IR plan.” Not “when was it last updated.” But has it been tested, under pressure, with the people who’d actually execute it? What struck me is how far Board-level scrutiny has come. Boards aren’t satisfied with a policy document sitting in a folder anymore. They want evidence of readiness, drills, timelines, decision logs, gaps identified and closed. They’re asking the questions a seasoned CISO would ask, and that’s a healthy shift for the industry. It also reflects a hard truth that a playbook is only as good as the last time it was actually run. Static plans look great on paper and fall apart under real pressure, confused ownership, missed handoffs, no clarity on who talks to whom when the primary systems are down. This is exactly the gap PROGIST’s #WarRoom platform is built to close: → TTX (Tabletop Exercise) module: Runs realistic, AI-assisted crisis simulations with dynamic injects, so teams rehearse decision-making under pressure instead of just reading a document. Every exercise generates scoring, timelines, and AI reports that can be shown directly to the board as evidence of preparedness. → CCM (Crisis & Command Management / Bridge) module: Provides responders a single command center with playbooks, tasks, evidence handling, and out-of-band communication for when primary channels go down, so the same protocols tested in TTX are the ones executed live. Together, they turn “we have a playbook” into “we have proven, measured readiness” which is exactly what today’s boards are asking for. If your organisation is being asked similar questions in the boardroom, happy to share how #WarRoom can help build that evidence trail. #CrisisManagement #IncidentResponse #CyberResilience #BFSI #WarRoom #BoardGovernance Chaithanya Rao Savio Fernandes Lakshmi Prasath Rajnish Arun Wathodkar Sudarshan Kadam Vinisha Olga Mendonca Priyanka Sehgal Kadam Naman Patel Abhishek Sawant Charles Lawrence Siddhesh Rane Omkar Adak Aditya Apte Vedant Diwakar Monali Jha
-
I'm putting together a step-by-step guide on building and leading effective cyber tabletops. I've spent over 6 years running cyber tabletops on a monthly cadence. From my experience, it's tempting to focus on obscure APT campaigns. But orgs should be taking a risk-based approach to crafting exercises, based on real threat intelligence. For example, instead of running a generic phishing exercise, drill how your help desk would handle a vishing call where attackers impersonate a locked-out employee, use publicly available details to pass identity checks, and convince agents to reset MFA credentials. Over 70% of these attacks now use Google Voice to appear legitimate. Let's not stop there. - How would your SOC react if an attacker called your help desk at 2 AM claiming to be a "traveling executive" who needs urgent email access, and your team sees legitimate VPN logs from that user's account? - What happens when your incident commander gets locked out of Slack during a live ransomware event because the attacker changed MFA settings for admin accounts? - How do you coordinate when your primary incident response tools (email, MS Teams, phone system) are all compromised and you're reduced to personal cell phones and Signal? The devil is in the details — and I'd be happy to share what I know with you in a comprehensive guide. Interested? Comment "guide" if you want a copy when it's ready, and I'll reach out to you 👇
-
50 Strategic Moves to Make Your Organization Crisis-Ready Most cybersecurity strategies fail one simple test: They look good on paper… But collapse in real-world decision-making. Cyber resilience isn’t built in tools. It’s built in how your organization responds under pressure. I’ve compiled 50 strategic moves behind one of the most underused leadership tools: 👉 Cyber Tabletop Exercises This isn’t about simulations. It’s about exposing how your business actually behaves during a crisis. What most organizations miss: They focus on: • Prevention • Detection • Technical controls But ignore the real risk: ❌ Decision delays ❌ Communication breakdowns ❌ Ownership confusion 1–12: Foundations → Understand response lifecycle → Define roles across IT, Legal, HR, Leadership → Shift mindset from prevention → readiness 13–25: Scenario Design → Ransomware + data exfiltration → BEC + AI phishing → Insider & supply chain threats 26–38: Advanced Simulation → Double extortion scenarios → Media & regulatory pressure → Executive decision-making under uncertainty 39–50: Maturity → Measure MTTR & response speed → Build continuous improvement loops → Turn exercises into a core business function A security plan tells you what should happen. A tabletop exercise shows you what actually will. The gap between those two? That’s where breaches become disasters. Be honest has your leadership team ever been tested in a realistic cyber crisis simulation? Follow Marcel Velica for more insights like this. And if this was valuable, reshare it with your network. If you want short daily thoughts, quick threat observations, and real-time discussions, follow me on X as well →https://x.com/MarcelVelica
-
Have you done your tabletop this quarter? I've been conducting more and more tabletops for clients as we get closer to the end of the year. And I wanted to talk about the difference between a Decision-Based and a Scenario-Based tabletop exercise. Both are great tools, but they serve different purposes. If you’ve used the tabletop exercises from CISA or similar agencies, those are generally Scenario-Based. The full storyline is presented, and stakeholders discuss their processes and responses at each stage. It’s a good way to validate procedures, policies, and communication plans. When I am working with a client, I like to use Decision-Based Tabletops, where the team receives only fragments of information as an “incident” unfolds. Stakeholders must decide what to do next: declare an incident, escalate, engage law enforcement, or contain the threat. At the end, the full technical summary is presented, and we see whether the choices made were effective in protecting people and the organization. This is more realistic to how incidents happen, and the closer you train to the real thing, the better your response when an IR happens. Decision-based exercises allow decision-making under pressure. They add additional stress to better simulate a real incident and keep participants engaged throughout the process. Both styles can be valuable, but I feel 'Scenario's" build awareness, the "Decision Based" builds instincts. Regardless of which style you use — decision-based or scenario-based — I encourage every organization to run 4–5 tabletop exercises each year. At least one should be a formal tabletop with an outside facilitator or cybersecurity firm, bringing together your full Incident Command Team (IT, HR, Legal, Insurance, Communications, and Leadership). These larger exercises help validate coordination at the executive level. Then, run 3–4 smaller tabletops internally — maybe during a staff meeting or within a specific department. These lighter sessions are great for walking through your policies, procedures, and playbooks in a low-pressure setting. The more your teams practice across different scenarios, the more confident, coordinated, and fast they’ll be when a real incident hits. My instructor always said: "Practice doesn't make perfect.... perfect practice makes perfect... If you don't train, (or if you train incorrectly) then you are not building skills..."
-
💀 𝗦𝗰𝗿𝗲𝗲𝗻 𝗧𝘂𝗿𝗻𝘀 𝗕𝗹𝘂𝗲 🟦, 𝗟𝗶𝗴𝗵𝘁𝘀 𝗚𝗼 𝗢𝘂𝘁 🌑, 𝗔𝗹𝗮𝗿𝗺𝘀 𝗕𝗹𝗮𝗿𝗲 🚨... 𝗪𝗵𝗮𝘁 𝗗𝗼 𝗬𝗼𝘂 𝗗𝗼? 😱 That terrifying scenario was the opening to the powerful Singapore Institute of Directors / Singapore Total Defence Tabletop Cybersecurity Exercise last week. For too long, cybersecurity has been an abstract annoyance — a phishing email or another forced password change. But a real attack is a business emergency that demands decisive leadership, not just technical fixes. Moderated by Psalm Lew, the exercise highlighted a critical truth: Cyber resilience is a leadership issue, not just an IT problem. Here are the key, actionable steps leadership must take across the three phases to ensure business continuity: 🛡️ 𝗕𝗲𝗳𝗼𝗿𝗲: 𝗧𝗵𝗲 𝗣𝗿𝗲𝗽𝗮𝗿𝗮𝘁𝗶𝗼𝗻 𝗣𝗵𝗮𝘀𝗲 (𝗕𝘂𝗶𝗹𝗱 𝗥𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲) ➡️ Establish Ownership: Integrate cyber risk into the enterprise risk management (ERM) framework. Appoint a board member as the Cyber Risk Champion to ensure executive oversight. ➡️ Invest Strategically: Approve and fully fund a comprehensive, tested Incident Response (IR) Plan. These plans must be validated with realistic tabletop exercises involving the CEO, Board, Legal, and Communications. ➡️ Define Authority: Clearly delegate immediate decision-making authority (e.g., system shutdown, external communication) before an event to remove paralysis during the critical first hour. 🔥 𝗗𝘂𝗿𝗶𝗻𝗴: 𝗧𝗵𝗲 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲 𝗣𝗵𝗮𝘀𝗲 (𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝘁𝗵𝗲 𝗖𝗿𝗶𝘀𝗶𝘀) ➡️ Activate the Plan: Immediately convene the executive-level Incident Response Team and follow the pre-defined IR protocols. ➡️ Prioritize Business: Focus decisions on minimizing impact to critical business functions and protecting customer data. ➡️ Communicate Decisively: Ensure a single, consistent, and legally vetted message is used. The communications and legal teams are as crucial as the technical team in managing regulatory and reputational risk. 📈 𝗔𝗳𝘁𝗲𝗿: 𝗧𝗵𝗲 𝗥𝗲𝗰𝗼𝘃𝗲𝗿𝘆 𝗣𝗵𝗮𝘀𝗲 (𝗟𝗲𝗮𝗿𝗻 𝗮𝗻𝗱 𝗘𝘃𝗼𝗹𝘃𝗲) ➡️ Ensure Continuity: Oversee the orderly, phased restoration of services based on business priority, with integrity checks at every step. ➡️ Conduct a Review: Mandate a thorough, independent post-mortem analysis. Go beyond technical failure and focus on process gaps, decision-making speed, and communication effectiveness. ➡️ Invest in Change: Approve the strategic investments and systemic changes identified in the review. Enhance resilience to prevent a recurrence and build future strength. ☠️ The blue screen skull is the final warning. Are you prepared to lead your organization through its worst digital day? Let's elevate this conversation in the boardroom. 👇 #CyberSecurity #BusinessContinuity #CyberResilience #TotalDefence Laura Tanner Darren Lim Budiman Andrew Paolo Miranda Gerald Tan Dr.Josemund Menezes Nitin Chhatwani YONG ANN GAN
-
Failure-Mode Tabletop: Security Under Failure! Most tabletop exercises assume that systems work, tools respond correctly, and data is available. Real incidents rarely do. If Your Tools Go Down, Who’s in Charge? The failure-mode tabletop flips that assumption. Instead of asking “What happens when an attack occurs?” it asks: “What happens when our defenses, data, or assumptions fail?” Scenarios intentionally include: • Tool outages • Incomplete or delayed logs • Conflicting alerts or signals • Vendor blind spots or incorrect detections The goal is not to test technology. It’s to test decision-making under uncertainty. During these sessions, the focus shifts to how decisions are made when information is incomplete, who validates what, and based on which evidence, and what happens when automation is unavailable or misleading! This exposes gaps that dashboards and metrics never reveal: • Hidden dependencies on single tools or vendors • Unclear ownership of validation and escalation • Overconfidence in automated conclusions • Decision paralysis when certainty disappears Failure-mode tabletops build something tools can’t provide! leaders who can think, decide, and act when systems don’t behave as expected. I don't know what you heard about me! I practice, test, learn in public, and share what actually works ... daily and free! Threat hunting 101 series on YouTube: https://lnkd.in/g7D4pTVk Daily Cyber Drops on Medium: https://lnkd.in/gsekf7kB Nothing Cyber. Keep hunting. #cybersecurity #threathunting #threatdetection #opensource #tips #career #blueteam #soc #socanalyst #skillsdevelopment #careergrowth #IR #dataanalysis #incidentresponse #ai
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development