Cyber Tabletop Exercises: The Two-Hour Session That Could Save Your Business
- Dev Pandya

- 5 hours ago
- 5 min read
Most businesses have some kind of plan for a cyber incident. It usually lives in a policy document, written some time ago, stored somewhere on a shared drive. Almost nobody has read it, and nobody has ever tested whether it works. A tabletop exercise fixes that in an afternoon, and it consistently reveals problems that no document ever catches.

What Is a Cyber Tabletop Exercise?
A tabletop exercise is a structured walkthrough of a realistic incident. No systems are touched and nothing is switched off. A small group sits around a table, someone presents a scenario, ransomware has locked your files, a supplier has been breached, a director's email account is sending invoices to clients, and the group talks through what they would actually do, step by step, in real time.
The facilitator adds complications as the session goes on. The scenario starts at 4pm on a Friday. Your IT contact is on holiday. The attacker has emailed a payment deadline. Each twist forces the group to make decisions with incomplete information, which is exactly what a real incident feels like.
It sounds simple, and it is. That is the point. There is no software to buy and no technical knowledge required from most participants. The value comes entirely from the questions the exercise forces into the open.
Why Do Tabletop Exercises Expose Gaps That Policies Miss?
A written incident response policy describes what should happen. A tabletop exercise reveals what would actually happen, and the distance between the two is usually uncomfortable. Some of the questions that reliably stump a room full of otherwise well-organised people:
Who has the authority to decide whether to pay a ransom, and can they be reached on a Friday evening?
Who calls the ICO, and does anyone know the 72-hour reporting rule under UK GDPR actually starts from when you become aware of a breach, not when you finish investigating it?
Where is the offline copy of the staff and supplier phone list if email and shared drives are down?
That last one catches almost everyone. Most contact lists live in the very systems an attacker has just encrypted. The same goes for the incident response plan itself. A plan you can only read by logging into a compromised network is not a plan.
Other gaps surface just as quickly. Nobody knows who speaks to clients, or what they are allowed to say. Nobody knows whether the cyber insurance policy requires the insurer to be notified before anyone touches the affected systems, which many policies do. Nobody knows how long the backups take to restore, or whether anyone has ever tried. None of this appears in a policy review. All of it appears within the first hour of a decent tabletop.
How Do You Run a Basic Tabletop Exercise for a UK SME?
You do not need a consultant to run your first one, though an experienced facilitator makes later sessions sharper. A workable format for a small or medium-sized business looks like this.
Pick a scenario that is plausible for your business, not a Hollywood one. Ransomware through a phishing email is the obvious choice because it remains the most common serious incident affecting UK SMEs. Invite five to eight people: whoever runs the business, whoever handles IT (in-house or your provider), and whoever deals with finance, HR and client communication. Block out two hours and put phones away.
The facilitator, who can be anyone willing to prepare, opens with the scenario and then asks one question repeatedly: what do you do now? Every fifteen or twenty minutes, a new development lands. The backups appear to be encrypted too. A journalist has emailed. A client is asking why their portal is down. Someone takes notes throughout, not minutes, but a list of every question the room could not answer.
That list is the deliverable. A two-hour session typically produces ten to twenty concrete gaps, each one fixable, most of them cheaply. Printing the contact list costs nothing. Agreeing who holds decision authority costs a conversation. Testing a backup restore costs an afternoon.
The National Cyber Security Centre offers free scenario packs through its Exercise in a Box service, built specifically for organisations without security teams, which removes any excuse about not knowing where to start.
What Happens When Businesses Do This Before an Incident Rather Than During One?
The contrast is stark, and it shows up in three places: time, money and composure.
A business that has rehearsed knows within the first hour who is in charge, who is calling the insurer, and whether the ICO clock is running. A business that has not spends that first hour, often the first day, working out who should even be on the call. During a live ransomware incident, that lost day is when attackers exfiltrate data, when backups get encrypted, and when the eventual recovery bill grows.
The regulatory side matters too. The ICO looks more favourably on organisations that can show they prepared, rehearsed and responded in an organised way. Turning up to a breach report with no plan and no evidence of testing invites harder questions and, in serious cases, harder penalties.
Then there is the human element. Real incidents are frightening. People make poor decisions under pressure, and they make worse ones when the pressure is combined with total unfamiliarity. A team that has walked through the scenario, even once, works from memory of a rehearsal rather than raw panic. That difference alone can decide how an incident ends.
Prevention still comes first, of course. As we argued in why managed IT should include cybersecurity by default, not as an add-on, keeping systems running and keeping them secure are the same job. But no defence is perfect, and the businesses that recover well are the ones that assumed something would eventually get through.
What Should You Do After Your First Tabletop?
Fix the gaps, then book the next one. A tabletop is not a one-off exercise, because businesses change. Staff leave, systems move, suppliers come and go. A session every six to twelve months keeps the plan matched to reality.
The first exercise also tends to raise bigger questions the room cannot fix on its own. Where does our data actually sit, and who can reach it? If you cannot answer that precisely, start with where exactly your data is and whether it is actually secure. How good are our backups really? Do we need a formal incident response plan, a retainer with a response provider, or changes to our insurance?
This is where structured incident response planning comes in. A tabletop shows you the gaps. Turning that list into tested procedures, defined roles, communication templates and a plan that survives contact with a real attacker is a different piece of work, and it is one we help businesses with regularly. If your first session leaves you with more questions than answers, that is the exercise working. Get in touch and we can help you close the list.




Comments