Tabletop exercises, explained

Cyber Security Tabletop Exercises: What They Are and How to Run One

Last updated: July 2026 · Prepared and reviewed by the Vintaris security team

A tabletop exercise is a rehearsal for your worst day: your team, a realistic scenario, and ninety minutes of decisions made around a table instead of during a crisis. No systems are touched. What gets tested is the thing that actually fails in real incidents: who decides, who calls whom, and whether the plan survives contact with pressure.

What a tabletop exercise looks like

A facilitator narrates the scenario in stages, injecting complications on a clock. The team responds as they genuinely would: naming the actual people, using the actual plan, hitting the actual gaps. Every gap found around the table is one that never gets found during an incident.

Three scenarios worth running

Ransomware on a Tuesday

Files encrypt at 8:40am, registers still work. Keep trading on an infected network or stop? Who calls the insurer, and did anyone check the policy's conditions before acting?

The redirected settlement

A payment left yesterday on emailed instructions that turn out to be fraudulent. Recovery windows are measured in hours: who calls the bank, the client, the insurer, and in what order?

The quiet breach

A vendor notifies you their systems were compromised months ago, and your data may be involved. Nothing is on fire, but the Notifiable Data Breaches assessment clock may already be running.

How to run one yourself

1

Pick one scenario

And one hour. Ambition kills first exercises.

2

Assign a narrator

Who reveals the scenario in stages and refuses to let anyone say 'IT handles that'.

3

Write down every gap

Unknown phone numbers, unclear authority, untested assumptions.

4

Fix three things

Before the next one. A tabletop that changes nothing was theatre.

If you have no written plan to test, start with our free incident response plan template.

When to bring in a facilitator

Self-run exercises plateau: the narrator knows the script, and internal seniority shapes the answers. A facilitated session brings realistic attacker behaviour, insurer-condition traps your team has not considered, and an outsider’s permission to press on the uncomfortable questions. Facilitated tabletops are also evidence: insurers and tenders increasingly ask when response plans were last tested. Our IR training and tabletop sessions run on-site across South East Queensland and remotely Australia-wide.

FAQ

Frequently asked questions

What is a tabletop exercise in cyber security?

A discussion-based rehearsal where your team works through a simulated cyber incident, decision by decision, without touching real systems. It tests the human layer of incident response: roles, authority, communication and the plan itself.

What are good tabletop exercise scenarios?

Ransomware during trading hours, payment redirection fraud discovered after the money moved, and a third-party breach notification are the three most valuable for Australian businesses, each tests different decisions and obligations.

How long does a tabletop exercise take?

A focused self-run exercise takes an hour; a facilitated session typically runs ninety minutes to half a day depending on depth, with a written findings summary afterwards.

Is there a tabletop exercise template?

The structure above is the template: one scenario, a staged narration, a gap log, and three committed fixes. Pair it with our incident response plan template so the exercise has a plan to test.

Prepared and reviewed by the Vintaris security team. Practical incident readiness for Australian businesses.

Vintaris provides cybersecurity assessment and advisory services.