Skip to main content
Oyoon Altaqnya

Cyber Crisis Tabletop Exercises

Realistic incident scenarios run with technical and management teams to test plans, decisions and communication before a real crisis.

NIST CSF 2.0 functions
Respond Recover
Relevant for
  • Banking and financial services
  • Telecommunications
  • Government and public sector
  • Oil and gas

Overview

The first hours of a cyber crisis decide how much damage it causes. Teams that have never practiced lose time deciding who is in charge, who to call and what to tell customers and regulators.

Tabletop exercises let you practice those decisions in a safe setting and fix the gaps before they matter.

What you get

  • Incident plans tested against realistic scenarios
  • Clear roles and decision rights during a crisis
  • Gaps in plans, contacts and communication found early
  • An improvement plan based on the exercise

What we cover

  • Ransomware and extortion scenarios
  • Data breach and regulatory notification
  • Payment fraud and business email compromise
  • Service outage and supplier compromise
  • Separate or joint technical and executive exercises

How we work

  1. Design

    We agree objectives and participants, and write a scenario based on realistic threats to your sector.

  2. Prepare

    We review your plans and prepare injects that test key decisions.

  3. Run

    We facilitate the exercise and record decisions and issues.

  4. Debrief

    We hold a debrief while the exercise is fresh.

  5. Report

    We deliver findings and an improvement plan.

Deliverables

  • Exercise design and scenario
  • Facilitated exercise
  • Debrief session
  • After-action report
  • Improvement plan

Questions buyers ask

Do we need an incident response plan first?

No. An exercise without a plan shows clearly why one is needed. With a plan, it shows whether the plan works.

Who should take part?

It depends on the objectives. Executive exercises include management, legal and communications; technical exercises include IT and security teams.

  • Business Continuity and Resilience

    Business impact analysis, continuity plans and disaster recovery planning so critical services keep running through disruption.

    NIST CSF function: Govern NIST CSF function: Recover
  • Executive Cyber Briefings

    Short, focused briefings for boards and senior management on cyber risk, regulation and their role in preparing for incidents.

    NIST CSF function: Govern
  • Compromise Assessment

    A focused investigation to determine whether attackers are already inside your environment, what they accessed, and what to do next.

    NIST CSF function: Detect NIST CSF function: Respond