A tabletop exercise is a cyber incident response readiness exercise in which 6 to 12 participants make scenario-based decisions for 2-4 hours, around a table or in an online meeting, without touching production systems. Per the NIST SP 800-84 guide, it runs in four phases: preparation, conduct, evaluation and follow-up. The aim is to surface process gaps, not technical proof.

TL;DR

  • Tabletop = a tabletop scenario-based IR exercise; systems are not touched.
  • Duration 2-4 hours, participants 6-12 people (IT, legal, senior management, communications, HR).
  • The NIST SP 800-84 and CISA Tabletop Exercise Package are taken as references.
  • Output: a findings report, an action list, ownership assignments.
  • Recommended at least once a year, twice for critical infrastructure.

Detailed Answer

The Difference Between a Tabletop and Other Exercise Types

Type Method Duration Risk
Tabletop Discussion, scenario 2-4 hours Low
Functional Limited system impact, controlled 4-8 hours Medium
Full-scale Simulation on a live system 1-3 days High
Red team Attacker simulation 2-6 weeks High

The tabletop is the first step of the maturity journey. It is the most practical way to involve non-technical units such as senior management and legal in the process.

Phase 1: Preparation

  • Set the scope: which system, which incident type (ransomware, data leak, DDoS, insider).
  • Write the objectives: e.g. "Can a draft Board notification be produced within the KVKK 72-hour window?".
  • Prepare the participant list: IT/SOC, legal, the KVKK compliance officer, senior management, communications/PR, HR, finance, operations.
  • Assign a facilitator and an observer/rapporteur.
  • Prepare the scenario cards and injects (e.g. T+0 the first alarm, T+30 minutes a second system affected, T+2 hours news in the press).

Phase 2: Conduct

The meeting generally follows this flow:

  1. 15 minutes: introduction of the roles and rules.
  2. 30 minutes: the first scenario brief and participant reactions.
  3. 90-120 minutes: the inject flow, decision points, cross-questioning.
  4. 30 minutes: an immediate hot-wash evaluation.

The facilitator draws out decisions without straying from the scenario. There is no right or wrong answer; there is a process gap. Example questions:

  • "Who is going to send the notification to the Board right now?"
  • "Who is going to verify the last 7 days of our backups?"
  • "When will we call the third-party digital-forensics firm?"

In this phase, your existing schedules such as the ransomware first-24-hours action chart are tested; conflicting ownerships become immediately visible.

Phase 3: Evaluation

After the hot-wash, a formal report is written within 1 week. The report should contain:

  • A scenario summary and the participants.
  • A decision timeline.
  • The gaps identified (people, process, technology).
  • Recommended actions, owner, deadline.
  • Topics to be tested in the next exercise.

Phase 4: Follow-up

The action list is tied to a 30/60/90-day calendar. A review meeting is held on day 90. For compliance with the KVKK Board, this cycle must be kept as a provable record; your KVKK 72-hour data-breach notification template process should be updated with the exercise's learnings.

Example Scenarios

Scenario Target units
Production-line SCADA ransomware IT, OT, senior management, communications
Customer database leak IT, legal, KVKK, PR
CEO impersonation BEC fraud Finance, legal, IT
A developer account compromised, source code leaked IT, legal, product
Post-ransomware backup corruption on RAID 5 IT, storage, insurance

For these scenarios, running them together with the cyber incident response playbook NIST 800-61 checklist is recommended. In storage-line scenarios, our RAID 5 collapse: the recovery process and cost article can be used as an inject source.

Common Mistakes

  • Only IT attending, with legal and communications excluded.
  • The scenario staying overly technical and failing to engage senior management.
  • A search for "the right answer," hiding the real gaps.
  • The report not being written, the actions forgotten.
  • Being done once a year with no follow-up exercise planned.

Evidence and Compliance

For critical-infrastructure operators, regulators such as the BTK, BDDK and EPDK, and the ISO 27001:2022 A.5.24 control, require that incident response plans be tested. Tabletop records (the participant list, the scenario, the report) are evidence in these audits.

FAQ

How many people is a tabletop exercise run with?

The optimal number is 6 to 12 people. Fewer creates cross-disciplinary gaps, more weakens the discussion. If there are more than 12 participants, it is recommended that they be set aside as observers.

How often should it be done?

At least once a year for the whole organization, and twice is advised for critical-infrastructure operators and the financial sector. An additional exercise is run after major changes (a new ERP, a new data center).

Is an online tabletop effective?

Yes, it runs successfully over Zoom/Teams. Online formats are documented in the example packages of the CISA Tabletop Exercise Package and NIST SP 800-84.

How much does an exercise cost?

A tabletop with an external facilitator is in the range of roughly 25,000 to 80,000 TL. If run in-house, the cost is only staff time. To see the damage potential, you can use the ransomware damage estimate tool.

Does DSET provide tabletop facilitation?

Yes. DSET designs, facilitates and reports NIST SP 800-84-compliant tabletop exercises. Contact: Hacettepe Teknokent Beytepe, +90 536 662 38 09, [email protected].