How to Run a Tabletop Exercise: A Cyber Incident Response Readiness Template
A tabletop is a scenario-based IR exercise played without touching physical systems. 2-4 hours, 6-12 participants. Four phases: scope, scenario injects, decision-making, lessons learned.
A tabletop exercise is a cyber incident response readiness exercise in which 6 to 12 participants make scenario-based decisions for 2-4 hours, around a table or in an online meeting, without touching production systems. Per the NIST SP 800-84 guide, it runs in four phases: preparation, conduct, evaluation and follow-up. The aim is to surface process gaps, not technical proof.
TL;DR
- Tabletop = a tabletop scenario-based IR exercise; systems are not touched.
- Duration 2-4 hours, participants 6-12 people (IT, legal, senior management, communications, HR).
- The NIST SP 800-84 and CISA Tabletop Exercise Package are taken as references.
- Output: a findings report, an action list, ownership assignments.
- Recommended at least once a year, twice for critical infrastructure.
Detailed Answer
The Difference Between a Tabletop and Other Exercise Types
| Type | Method | Duration | Risk |
|---|---|---|---|
| Tabletop | Discussion, scenario | 2-4 hours | Low |
| Functional | Limited system impact, controlled | 4-8 hours | Medium |
| Full-scale | Simulation on a live system | 1-3 days | High |
| Red team | Attacker simulation | 2-6 weeks | High |
The tabletop is the first step of the maturity journey. It is the most practical way to involve non-technical units such as senior management and legal in the process.
Phase 1: Preparation
- Set the scope: which system, which incident type (ransomware, data leak, DDoS, insider).
- Write the objectives: e.g. "Can a draft Board notification be produced within the KVKK 72-hour window?".
- Prepare the participant list: IT/SOC, legal, the KVKK compliance officer, senior management, communications/PR, HR, finance, operations.
- Assign a facilitator and an observer/rapporteur.
- Prepare the scenario cards and injects (e.g. T+0 the first alarm, T+30 minutes a second system affected, T+2 hours news in the press).
Phase 2: Conduct
The meeting generally follows this flow:
- 15 minutes: introduction of the roles and rules.
- 30 minutes: the first scenario brief and participant reactions.
- 90-120 minutes: the inject flow, decision points, cross-questioning.
- 30 minutes: an immediate hot-wash evaluation.
The facilitator draws out decisions without straying from the scenario. There is no right or wrong answer; there is a process gap. Example questions:
- "Who is going to send the notification to the Board right now?"
- "Who is going to verify the last 7 days of our backups?"
- "When will we call the third-party digital-forensics firm?"
In this phase, your existing schedules such as the ransomware first-24-hours action chart are tested; conflicting ownerships become immediately visible.
Phase 3: Evaluation
After the hot-wash, a formal report is written within 1 week. The report should contain:
- A scenario summary and the participants.
- A decision timeline.
- The gaps identified (people, process, technology).
- Recommended actions, owner, deadline.
- Topics to be tested in the next exercise.
Phase 4: Follow-up
The action list is tied to a 30/60/90-day calendar. A review meeting is held on day 90. For compliance with the KVKK Board, this cycle must be kept as a provable record; your KVKK 72-hour data-breach notification template process should be updated with the exercise's learnings.
Example Scenarios
| Scenario | Target units |
|---|---|
| Production-line SCADA ransomware | IT, OT, senior management, communications |
| Customer database leak | IT, legal, KVKK, PR |
| CEO impersonation BEC fraud | Finance, legal, IT |
| A developer account compromised, source code leaked | IT, legal, product |
| Post-ransomware backup corruption on RAID 5 | IT, storage, insurance |
For these scenarios, running them together with the cyber incident response playbook NIST 800-61 checklist is recommended. In storage-line scenarios, our RAID 5 collapse: the recovery process and cost article can be used as an inject source.
Common Mistakes
- Only IT attending, with legal and communications excluded.
- The scenario staying overly technical and failing to engage senior management.
- A search for "the right answer," hiding the real gaps.
- The report not being written, the actions forgotten.
- Being done once a year with no follow-up exercise planned.
Evidence and Compliance
For critical-infrastructure operators, regulators such as the BTK, BDDK and EPDK, and the ISO 27001:2022 A.5.24 control, require that incident response plans be tested. Tabletop records (the participant list, the scenario, the report) are evidence in these audits.
FAQ
How many people is a tabletop exercise run with?
The optimal number is 6 to 12 people. Fewer creates cross-disciplinary gaps, more weakens the discussion. If there are more than 12 participants, it is recommended that they be set aside as observers.
How often should it be done?
At least once a year for the whole organization, and twice is advised for critical-infrastructure operators and the financial sector. An additional exercise is run after major changes (a new ERP, a new data center).
Is an online tabletop effective?
Yes, it runs successfully over Zoom/Teams. Online formats are documented in the example packages of the CISA Tabletop Exercise Package and NIST SP 800-84.
How much does an exercise cost?
A tabletop with an external facilitator is in the range of roughly 25,000 to 80,000 TL. If run in-house, the cost is only staff time. To see the damage potential, you can use the ransomware damage estimate tool.
Does DSET provide tabletop facilitation?
Yes. DSET designs, facilitates and reports NIST SP 800-84-compliant tabletop exercises. Contact: Hacettepe Teknokent Beytepe, +90 536 662 38 09, [email protected].
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.