
A written incident-response plan is useful only if the people expected to use it can find the right information and make decisions under pressure. A tabletop exercise gives a small business a practical way to check that readiness without taking systems offline or staging a live attack.
A tabletop is a facilitated discussion about a fictional but plausible situation. Participants talk through what they would do, what information they need, who has authority, and where the existing plan is unclear. CISA describes tabletop exercises as a way to discuss roles, response procedures, interdependencies, and recovery. NIST’s exercise guidance also emphasizes defined objectives, a structured scenario, facilitation, evaluation, and improvement work.
Start with a narrow objective
Do not begin with the goal of proving that the business is fully secure. Choose one or two questions the session should answer. For example:
- Can the team identify who may declare an incident and who coordinates the first response?
- Can staff preserve useful evidence without making the situation worse?
- Can the business keep customers and employees informed through an approved channel?
- Can the team decide which operations must continue, pause, or move to a manual process?
A narrow objective keeps the conversation useful. It also gives the facilitator a fair way to evaluate the exercise. The purpose is to expose decisions and dependencies that need improvement, not to grade individual employees.
Choose a realistic scenario
Use a scenario that matches the business’s systems and work. A suspicious sign-in to an administrator account, a lost laptop, a ransomware notice on a shared file system, or a vendor account with unusual activity can all work. Avoid unnecessary technical drama. Participants should be able to discuss the business impact even if they are not security specialists.
Write a short opening statement with only the facts participants would initially know. For example: an employee reports that they cannot access a shared folder, the help desk sees repeated sign-in failures, and a customer is waiting for an order update. Do not reveal the full solution in the opening. The facilitator can introduce additional facts as the discussion progresses.
Invite the people who make decisions
A useful group is small enough for everyone to speak and broad enough to cover the business. Consider including an owner or senior manager, an operations lead, the person responsible for IT or a managed provider, and someone who understands customer or employee communications. Include a finance, HR, facilities, or legal contact when their decisions are relevant to the scenario.
Assign a facilitator who can keep the group moving and a note-taker who records decisions, questions, assumptions, and action items. Participants should discuss their normal roles rather than inventing an emergency department that does not exist. If an outside provider would be called, note the provider as a dependency and identify the contact process without putting private contact details in the exercise document.
Run the discussion in stages
A 60-to-90-minute session is enough for a first exercise. Begin by explaining that this is a no-fault discussion and that the scenario is fictional. Review the objectives, the assumptions, and the limits of the exercise. Then move through a few timed prompts:
- Detection: What has been observed, and who receives the first report?
- Stabilization: Which account, device, integration, or service might need to be isolated? Who can authorize that action?
- Business impact: Which customer commitments, internal processes, or safety considerations are affected?
- Communication: Who needs to know now, what can be stated confidently, and which channel is approved?
- Recovery: What evidence is needed before restoring access, and how will the team verify that an important process is working?
After each prompt, ask participants to explain the next decision, the owner, the information required, and the fallback if that information is unavailable. Those four questions turn general discussion into operational evidence.
Record decisions, not just observations
Notes such as “improve communication” are hard to act on. Capture a decision record with a short description, owner, deadline, dependency, and current status. If the group cannot decide, record what blocked the decision. The missing item may be an escalation path, a current asset list, a recovery priority, or an agreed message template.
Keep exercise notes free of real passwords, access tokens, customer data, or detailed security weaknesses. Use fictional names and sample identifiers. The exercise should improve readiness without creating a new sensitive document that is copied widely.
Test the human side of recovery
Technical recovery is only part of the problem. Ask how employees will work if a key system is unavailable, how urgent requests will be verified, and how the team will distinguish a legitimate recovery instruction from a fraudulent one. Discuss who can approve a temporary workaround and how the business will return from that workaround to normal processing.
Also ask when an incident should be escalated to an insurer, outside specialist, law enforcement, regulators, customers, or other parties. The right answer depends on the facts, contracts, jurisdiction, and professional advice. A tabletop should identify who makes those calls and where the current plan needs review; it should not attempt to provide legal conclusions.
Finish with an after-action plan
Reserve time for a short debrief while the conversation is fresh. Ask what worked, what surprised the group, which assumption proved false, and which decision took too long. Group findings into immediate fixes, planned improvements, and questions requiring outside expertise.
Give each improvement an owner and a target date. Examples include updating an on-call list, documenting a manual order process, confirming backup access, creating a staff reporting route, or testing a provider’s escalation path. Keep the list short enough to manage, then schedule a follow-up review. CISA’s exercise materials emphasize an after-action report and improvement plan because the value of the exercise comes from closing the gaps it reveals.
A simple starting checklist
- Choose one or two objectives tied to business operations.
- Write a plausible opening scenario and three to five follow-up prompts.
- Invite decision-makers from management, operations, IT, and communications.
- Assign a facilitator and a protected note-taking process.
- Record owners, dependencies, unanswered questions, and fallback actions.
- Exclude real credentials, customer data, and unnecessary sensitive details.
- Publish an internal improvement list with owners and review dates.
A tabletop exercise does not need elaborate equipment or a dramatic scenario. Its practical value is the shared understanding created when people rehearse how they will detect a problem, protect the business, communicate clearly, and recover responsibly. Start with one important workflow, learn where the plan depends on undocumented knowledge, and improve that specific area first.
Next step: Schedule a short consultation to identify the next useful improvement.