Dispatches · Scenarios
Five cyber tabletop exercise scenarios for 2026, and the decision each one tests
Choose a scenario for the decision it forces, not for how dramatic it sounds. Five that fit 2026 attack data: an exploited internet-facing system, a voice-phishing call to the help desk, ransomware through an old compromise, a remote hire who is not who they claimed, and an industrial control system compromise. Each has three injects and one decision to test.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
By Security Training assessors · 8 July 2026
2-1How were these scenarios chosen?
Each scenario starts from a published finding. Four come from Mandiant's M-Trends 2026 report, published on 23 March 2026, which covers intrusions investigated in 2025. The fifth comes from the scenario topics in CISA's free Tabletop Exercise Packages, which cover ransomware, insider threats, phishing and industrial control system compromise.
One figure from M-Trends frames all five: 52% of intrusions in 2025 were first detected internally, up from 43% the year before. The rest were first reported from outside the organization. Plan for the first inject to come from someone who is not on your team.
2-2Scenario 1: an internet-facing system exploited before a patch exists
Why now: exploits were the most common initial infection vector in M-Trends 2026 for the sixth year running, at 32%, and the report gives a mean time to exploit of minus seven days, meaning exploitation before a patch is available.
- An external researcher reports suspicious traffic from your VPN appliance.
- The vendor confirms a vulnerability and says a patch is days away.
- Logs show an unfamiliar administrator account created a week ago.
The decision it tests: who can authorise taking a business-critical system offline with no patch available, and what the business loses while it is down.
2-3Scenario 2: a voice-phishing call to the help desk
Why now: voice phishing rose to 11% of initial infection vectors in M-Trends 2026, second only to exploits, while email phishing fell to 6%.
- A caller claiming to be a travelling executive asks the help desk to reset multi-factor authentication.
- An hour later, that executive's account downloads files from a finance share.
- The real executive, on a flight, cannot be reached.
The decision it tests: who can lock out a senior account without the account holder's approval, and what the help desk is allowed to verify before any reset.
2-4Scenario 3: ransomware through a compromise nobody closed
Why now: prior compromise was the top initial vector for ransomware in M-Trends 2026 at 30%, double the 15% of the year before. The report also found the median time between initial access and hand-off to a second threat group fell to 22 seconds in 2025.
- Files on a file server are encrypted overnight and a ransom note names your company.
- Forensics finds the access came from credentials exposed in an incident closed last year.
- A journalist asks whether customer data was taken.
The decision it tests: when the incident is declared, whether it could be material, and who speaks to the press before the facts are known. For US public companies, see rehearsing the materiality decision.
2-5Scenario 4: a remote hire who is not who they claimed
Why now: M-Trends 2026 reports a median dwell time of 122 days for cyber espionage and North Korean IT worker incidents, against a global median of 14 days. A long dwell time means the decisions are about scope and disclosure as much as containment.
- Payroll flags that a contractor's salary is paid to an account in a different country from the one on file.
- The contractor has administrator access to a code repository.
- HR asks whether the person can be dismissed today.
The decision it tests: how security, HR and legal act together, including whether to cut access before or after evidence is preserved, and how far back the investigation must look. Invite HR: a security-only exercise cannot test this decision.
2-6Scenario 5: an industrial control system compromise
Why now: industrial control system compromise is one of the cyber scenario topics in CISA's Tabletop Exercise Packages, which also offer sector versions for water, maritime ports and healthcare. For any organization that runs physical operations, it is the scenario where safety and production collide.
- Operators report that a process setpoint changed without anyone touching it.
- IT confirms an intrusion on a server that bridges the office and plant networks.
- The plant manager says a shutdown will take two days to recover from.
The decision it tests: who can order a shutdown on safety grounds, and whether security, operations and executives use the same definition of an incident.
2-7How should you run them?
One scenario per session, with the people who would really decide. Each scenario above has three injects; the six-step tabletop guide covers timing, roles and the hotwash. Write the decision each scenario tests as the exercise objective, and grade it afterwards. The lesson on writing exercise objectives shows how.
A CISA package can be adapted to any of these scenarios at no cost. Platforms that generate scenarios or react to player decisions shorten preparation and make it practical to run more than one a year; the rankings compare them.
Sources
- Google Cloud, M-Trends 2026: https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- CISA Tabletop Exercise Packages: https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
- NIST SP 800-61 Rev. 3: https://csrc.nist.gov/pubs/sp/800/61/r3/final