Process and Coordination Gaps Are Found During Tabletop Exercises
It’s during these scenarios where the parties discuss their procedures and the chain of command. The technical exercises are designed to let IT organizations know where their security issues lie, but what ends up happening is that other, nontechnical issues arise that need to be addressed.
“The biggest findings are almost always about process and coordination,” says Jess Burn, a principal analyst at Forrester. “Exercises reveal whether people agree on incident severity, who has authority to shut down a system, when executives or the board get involved, who approves customer or media communications, and when to contact the cyber insurance representative.” While the plans may look clear on paper, she says, different departments might be operating on different-enough assumptions to cause issues.
An effective tabletop exercise is designed to throw untested scenarios at its participants and get them to rely on their instincts. “A simulated event that was not announced, where people are not prepared, will expose the fundamentals: What can I do right now to contain, and who do I contact to help with next steps?” says Hinton. “These are exceptionally valuable and very hard to implement in a manner that gets the adrenaline going in a way that actually simulates — and stimulates — the response process.”
It’s not supposed to be a “clean” exercise where everyone feels good at the end, according to Hinton. "The incident response team knows what to do and how to respond to contain an incident. The executive team needs to be taken on the journey of ‘this is what happened, this is what we did to fix it,’ without understanding the details of the environment or trying to second-guess the trained subject matter experts in the security operations center and on the incident response team. This is extraordinarily difficult for most senior leaders who are used to making and owning decisions based on a full analysis of situation, impact, options and so on.”
How Often Should Tabletop Exercises Be Run?
It’s these gaps in communication and execution that lead Burn to think that these exercises should be run regularly, ideally before an incident happens. “I recommend at least one cross-functional executive tabletop each year, supported by more frequent technical drills using a cybersecurity skills and training platform with a cyber range that provides a realistic simulation of the organization's environment,” she says.
The frequency may vary by organization, says Hinton. If a business is always in “fire drill mode,” tabletop exercises probably need to be run less often than in organizations where there are fewer attacks, she says.
However frequently they run them, organizations need to come out of each exercise with a plan of action for each participant. “Organizations should leave the exercise with an owner, deadline and expected outcome for each finding,” Burn says. “Some fixes, such as updating contact lists or drafting communication templates, can happen quickly. Issues involving authority, governance, contracts, staffing or business continuity usually take longer.”
The hardest fixes are those involving gaps in authority, she says, “because the security team cannot resolve them alone. Deciding who can take a critical system offline, approve an emergency expenditure, determine materiality or speak publicly requires agreement across legal, financial, operational and executive teams.”
