Data Protection

How to Run a Cybersecurity Tabletop Exercise

Practice incident response with a realistic scenario, clear roles, and documented lessons learned.

Reviewed October 10, 2026 3 minute read Reviewed by Meta IT Pro
Part of the Data Protection & Recovery Learning Center

A tabletop exercise is a guided discussion in which leaders and staff walk through a realistic cyber incident. It tests the plan, contacts, and decisions without touching production systems.

Key takeaways

What to know before you act

  • A tabletop exercise tests people, decisions, and communication—not technology.
  • Ninety minutes with the right participants can expose gaps in contacts, authority, and procedures.
  • The value comes from the follow-up actions assigned afterward.

Why it matters

What business leaders should understand

Incident plans that have never been practiced often fail on basics such as who decides, who calls the insurer, and how staff communicate if email is down. A short exercise reveals those gaps safely.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

Plan the exercise

Choose a scenario that reflects your real risks. Ransomware, a compromised email account used for payment fraud, and a lost laptop with sensitive data are common starting points. Free resources such as CISA's tabletop exercise packages provide scenarios and discussion questions that can be adapted.

  • Set objectives, such as testing escalation, insurer notification, or recovery priorities.
  • Invite leadership, IT or your MSP, finance, operations, and communications.
  • Appoint a facilitator and a note-taker.
  • Keep it to 60–120 minutes.

Run it in stages

Present the scenario in stages, adding new information—called injects—as the discussion progresses. Ask participants what they would do, who they would call, and what information they would need at each stage.

  • Detection: how would we find out, and who is told first?
  • Escalation: who declares an incident and makes key decisions?
  • Containment: what systems or accounts do we shut down, and who approves?
  • Communication: how do we reach staff, customers, the insurer, counsel, and the bank if email is down?
  • Recovery: which systems come back first, and how long will it take?

Capture lessons and follow up

Close with a short debrief: what worked, what was unclear, and what is missing. Turn findings into actions with owners and dates, update the incident plan, and schedule the next exercise—typically at least annually.

Practical action plan

Steps your business can take

01

Choose a realistic scenario such as ransomware or a fraudulent wire transfer.

02

Invite leadership, IT, finance, and the people who would make key decisions.

03

Walk through detection, escalation, communication, and recovery step by step.

04

Record gaps, assign owners, and update the incident plan.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • The incident plan has never been reviewed with leadership
  • Nobody knows how to contact the cyber insurer
  • Staff would rely on company email to coordinate during an email outage

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.