Cyber Security Tabletop Exercises: What They Are and How to Run One
Last updated: July 2026 · Prepared and reviewed by the Vintaris security team
A tabletop exercise is a rehearsal for your worst day: your team, a realistic scenario, and ninety minutes of decisions made around a table instead of during a crisis. No systems are touched. What gets tested is the thing that actually fails in real incidents: who decides, who calls whom, and whether the plan survives contact with pressure.
What a tabletop exercise looks like
Files began encrypting at 8:40am. Registers still work. Go.
Keep trading on an infected network, or stop? Who has the authority?
Has anyone called the insurer? Does the policy require it before acting?
A journalist rings the front desk. Who speaks, and what is the holding line?
Every gap logged, three fixes committed, owners named.
A facilitator narrates the scenario in stages, injecting complications on a clock. The team responds as they genuinely would: naming the actual people, using the actual plan, hitting the actual gaps. Every gap found around the table is one that never gets found during an incident.
Three scenarios worth running
Ransomware on a Tuesday
Files encrypt at 8:40am, registers still work. Keep trading on an infected network or stop? Who calls the insurer, and did anyone check the policy's conditions before acting?
The redirected settlement
A payment left yesterday on emailed instructions that turn out to be fraudulent. Recovery windows are measured in hours: who calls the bank, the client, the insurer, and in what order?
The quiet breach
A vendor notifies you their systems were compromised months ago, and your data may be involved. Nothing is on fire, but the Notifiable Data Breaches assessment clock may already be running.
How to run one yourself
Pick one scenario
And one hour. Ambition kills first exercises.
Assign a narrator
Who reveals the scenario in stages and refuses to let anyone say 'IT handles that'.
Write down every gap
Unknown phone numbers, unclear authority, untested assumptions.
Fix three things
Before the next one. A tabletop that changes nothing was theatre.
If you have no written plan to test, start with our free incident response plan template.
When to bring in a facilitator
Self-run exercises plateau: the narrator knows the script, and internal seniority shapes the answers. A facilitated session brings realistic attacker behaviour, insurer-condition traps your team has not considered, and an outsider’s permission to press on the uncomfortable questions. Facilitated tabletops are also evidence: insurers and tenders increasingly ask when response plans were last tested. Our IR training and tabletop sessions run on-site across South East Queensland and remotely Australia-wide.
Frequently asked questions
What is a tabletop exercise in cyber security?
A discussion-based rehearsal where your team works through a simulated cyber incident, decision by decision, without touching real systems. It tests the human layer of incident response: roles, authority, communication and the plan itself.
What are good tabletop exercise scenarios?
Ransomware during trading hours, payment redirection fraud discovered after the money moved, and a third-party breach notification are the three most valuable for Australian businesses, each tests different decisions and obligations.
How long does a tabletop exercise take?
A focused self-run exercise takes an hour; a facilitated session typically runs ninety minutes to half a day depending on depth, with a written findings summary afterwards.
Is there a tabletop exercise template?
The structure above is the template: one scenario, a staged narration, a gap log, and three committed fixes. Pair it with our incident response plan template so the exercise has a plan to test.
Prepared and reviewed by the Vintaris security team. Practical incident readiness for Australian businesses.
Vintaris provides cybersecurity assessment and advisory services.