Oct 08 2026
Security

Why Tabletop Exercises Expose More Than Technical Weaknesses

Incident response plans need to be tested. Running scenarios involving cybersecurity breaches reveal issues with communication, decision-making and bottlenecks in implementing solutions.

Organizations that want to understand where they might have security gaps have several options. A vulnerability scan will expose obvious holes in their defenses, while a penetration test run by a third-party facilitator can find more subtle weaknesses.

But for a business to be truly cyber resilient, it must know with confidence exactly how it will respond to an actual cyberattack. And while scans and pentests are vital, they won’t tell you that. For that information, you’ll need to conduct a tabletop exercise. During these exercises, a facilitator, often hired from an incident response (IR) firm or another third-party organization, walk an organization’s decision-makers through a scenario where unexpected information is given.

Scenarios can be obtained from a number of sources, including the Cybersecurity and Infrastructure Security Agency, or they can be created based on real-life data such as past incidents, threat intelligence and audit findings. They can be run verbally, in a meeting where the key players are in one room or dialed in remotely, or via simulation platforms.

“Tabletops vary greatly in scope and execution, from simple ‘everyone sits at the table and reads the plan’ to complex, simulated events where a third-party acts as an attacker while the organization’s security operations center and IR teams are tested on if, when and how to detect and contain,” says Heather Hinton, an advisory board member of the Harvard cybersecurity program. “Whichever approach you take, the goal is the same: Build muscle memory and relationships so you can respond quickly.”

Click the banner below to learn why detection and response has become vital to cybersecurity.

 

Process and Coordination Gaps Are Found During Tabletop Exercises

It’s during these scenarios where the parties discuss their procedures and the chain of command. The technical exercises are designed to let IT organizations know where their security issues lie, but what ends up happening is that other, nontechnical issues arise that need to be addressed.

“The biggest findings are almost always about process and coordination,” says Jess Burn, a principal analyst at Forrester. “Exercises reveal whether people agree on incident severity, who has authority to shut down a system, when executives or the board get involved, who approves customer or media communications, and when to contact the cyber insurance representative.” While the plans may look clear on paper, she says, different departments might be operating on different-enough assumptions to cause issues.

An effective tabletop exercise is designed to throw untested scenarios at its participants and get them to rely on their instincts. “A simulated event that was not announced, where people are not prepared, will expose the fundamentals: What can I do right now to contain, and who do I contact to help with next steps?” says Hinton. “These are exceptionally valuable and very hard to implement in a manner that gets the adrenaline going in a way that actually simulates — and stimulates — the response process.”

It’s not supposed to be a “clean” exercise where everyone feels good at the end, according to Hinton. "The incident response team knows what to do and how to respond to contain an incident. The executive team needs to be taken on the journey of ‘this is what happened, this is what we did to fix it,’ without understanding the details of the environment or trying to second-guess the trained subject matter experts in the security operations center and on the incident response team. This is extraordinarily difficult for most senior leaders who are used to making and owning decisions based on a full analysis of situation, impact, options and so on.”

How Often Should Tabletop Exercises Be Run?

It’s these gaps in communication and execution that lead Burn to think that these exercises should be run regularly, ideally before an incident happens. “I recommend at least one cross-functional executive tabletop each year, supported by more frequent technical drills using a cybersecurity skills and training platform with a cyber range that provides a realistic simulation of the organization's environment,” she says.

The frequency may vary by organization, says Hinton. If a business is always in “fire drill mode,” tabletop exercises probably need to be run less often than in organizations where there are fewer attacks, she says.

However frequently they run them, organizations need to come out of each exercise with a plan of action for each participant. “Organizations should leave the exercise with an owner, deadline and expected outcome for each finding,” Burn says. “Some fixes, such as updating contact lists or drafting communication templates, can happen quickly. Issues involving authority, governance, contracts, staffing or business continuity usually take longer.”

The hardest fixes are those involving gaps in authority, she says, “because the security team cannot resolve them alone. Deciding who can take a critical system offline, approve an emergency expenditure, determine materiality or speak publicly requires agreement across legal, financial, operational and executive teams.”

Jess Burn headshot
Exercises will become more dynamic as AI-enabled attacks create faster-moving incidents and messier evidence trails.”

Jess Burn Principal Analyst, Forrester

Tabletop Exercises Are Made More Complex by New Tech

Scenarios that are used in tabletop exercises are only going to get more complicated, given advances in technology. “Exercises will become more dynamic as AI-enabled attacks create faster-moving incidents and messier evidence trails,” Burn says. “Scenarios will need to account for prompts, model outputs, agent actions, data pipelines, access controls and human approvals alongside endpoint, identity, cloud and network evidence.”

Quantum computing cyberattack scenarios are also being developed, because algorithms that can do things such as crack current cryptographic systems are ready to be implemented by bad actors as soon as the technology is mature.

But just as new technology can make the scenarios more complicated, it can also help design those scenarios and guide their users to effective solutions. AI-powered exercises can react dynamically to changing conditions and decision-making. “This means that teams must be empowered to act, prepared to respond, and have the alerts and responses to allow them to act at as close to machine speed as they can,” says Hinton. “The muscle memory is moving from people to instructions given to autonomous AI defenders.”

Despite those advantages, however, Burn still thinks that the human element is key: “AI can help create realistic tabletop injects and adapt scenarios based on participants’ decisions, but human facilitators still need to validate the content.”

PixeloneStocker/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.