Incident ResponseMay 7, 202611 min

Tabletop Exercises : A Practical Guide to Preparing Your Team

What is a tabletop exercise and why now?

Short answer: a tabletop exercise is a discussion-based crisis simulation in which decision-makers work through an incident scenario led by a facilitator, without touching real systems. It runs two to four hours, needs no technical environment, and exposes in a single session the blind spots no document review will ever find. Insurers increasingly ask about it on the underwriting application.

The value of a response plan is not measured by its thickness. It is measured by how fast a team makes the six or seven decisions that matter in the first hours: isolate or observe, disconnect or maintain, notify whom and when, communicate what, pay or not, call which provider.

In our real-world engagements, the difference between an organization back in business within 48 hours and one that loses three weeks rarely comes down to technology. It comes down to clarity of the decision chain.

Who needs to be in the room

The most common mistake is making this a technical exercise. A successful tabletop brings together:

Executive leadership : they decide on continuity, public communication and any payment

IT and security : real detection, isolation and restoration capabilities

Legal and compliance : Law 25, PIPEDA and sector obligations, management of legal privilege

Communications : customers, employees, media, partners

Human resources : if the incident involves an employee or forces temporary layoffs

Finance : crisis cash flow, emergency spending authority

The broker or insurer, where possible : their presence dramatically improves the quality of the exercise

An external facilitator is strongly recommended: they ask the uncomfortable questions nobody internal is willing to put to leadership.

A typical three-hour run of show

1.

Framing (0:00): rules of engagement, no-blame commitment, confidentiality, scope reminder

2.

Inject 1 (0:15): the weak signal. An employee reports odd behaviour, or a partner flags suspicious activity. What happens, who is told, how fast?

3.

Inject 2 (0:45): confirmed compromise. Isolation decision, crisis team activation, legal privilege and evidence preservation

4.

Inject 3 (1:15): business impact. Production systems are down, a major client calls, a journalist is writing. Continuity, communication, restoration priorities

5.

Inject 4 (1:50): the data is out. A sample is published, an extortion message arrives, and the question of notifying the regulator and affected individuals lands

6.

Inject 5 (2:20): pressure rises. A ransom demand with a countdown, and the attacker contacting your customers directly

7.

Hot debrief (2:45): decisions made, decisions blocked, missing information, commitments

Each inject should fit in five lines and be handed out in writing. The facilitator's discipline is to never answer technical questions on the group's behalf: the silence is what reveals the gaps.

Three scenarios suited to the Canadian context

Scenario A : Ransomware with double extortion

Partial domain encryption on a Friday at 4 p.m., backups reachable on the network share, extortion note claiming 400 GB exfiltrated. Pressure points: production shutdown decision, real restoration capability, Law 25 notification clock, position on payment.

Scenario B : Supplier compromise

Your managed service provider informs you that one of its access accounts was compromised and it cannot rule out propagation to clients. Pressure points: who holds which access, how to revoke without halting operations, which contractual obligations apply, who speaks to other clients.

Scenario C : Personal data exposure without ransomware

An external researcher reports that a cloud storage bucket containing client files has been publicly accessible since an unknown date. Pressure points: assessing risk of serious injury, reconstructing access history, notification, public communication.

What to measure

Mobilization time : delay between the signal and the crisis team actually convening

Decision clarity : for each major decision, a single identified decision-maker

Regulatory qualification time : how long it takes to determine whether notification is required

External dependencies : how many times the answer is "we would have to ask the provider"

Documentation gaps : outdated contacts, procedures nobody can find, missing break-glass accounts

After the exercise: the deliverable that counts

A tabletop without an action plan is a pleasant afternoon with no effect. The report should run a few pages and end in an action table: what, who, by when. Three to five corrective actions are enough, provided they are genuinely tracked and revalidated at the next exercise.

Keep the report: it documents your maturity for your insurer, your clients and, if it comes to it, the regulator.

Conclusion

Two exercises a year are enough to turn a theoretical plan into a collective reflex. It is the best cost-to-benefit cybersecurity investment available, because it costs only time and acts on the single variable that determines the final cost of an incident: decision speed. ITCS Group designs and facilitates tabletop exercises tailored to your sector, with custom scenarios and a maturity report your insurer can use. Contact us to schedule your next session.

Sources

Canadian Centre for Cyber Security : incident response planning guidance

Commission d'accès à l'information du Québec : guidelines on preventing confidentiality incidents, January 2026

Tabletop exercises facilitated by ITCS Group : 2024-2026

Share this articleLinkedInXFacebook