Field guide · How-to
How to run a cyber tabletop exercise
Pick one objective, one scenario and the people who would actually make the calls. Start from a CISA Tabletop Exercise Package, which is free and includes objectives, scenarios, discussion questions, a slide deck, a feedback form and an after-action report template. Run 2–3 hours with a facilitator and a note-taker, hold a hotwash the same day, and give every finding an owner and a date.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
7-1What do you need before you start?
- A sponsor with authority: usually the CISO, ideally with an executive who will attend.
- Your incident response plan and any playbooks the scenario will touch.
- A CISA Tabletop Exercise Package that matches the threat (CISA lists more than 100, covering ransomware, insider threats, phishing, industrial control system compromise and sector versions).
- Four to six weeks of lead time if you facilitate yourself.
7-2The six steps
- 01Set one or two objectives. Write them as things you can observe: 'Decide within 60 minutes whether the incident is material for disclosure' is testable; 'improve readiness' is not. NIST SP 800-61 Rev. 3 (April 2025) frames incident response inside CSF 2.0 risk management, which is a useful source for objectives that tie to governance.
- 02Choose and tailor the scenario. Take the CTEP scenario closest to your risk and replace its generic systems and suppliers with yours. Keep the first scenario plausible and boring; a realistic ransomware case beats an exotic one.
- 03Invite the people who would decide. Incident commander, security operations lead, IT, legal counsel, communications, a business owner for the affected service, and an executive with authority to accept risk. Assign a facilitator who is not a player and a note-taker who records decisions and times, not opinions.
- 04Script the injects. Plan 3–5 injects that force decisions: a ransom note, a journalist's call, a regulator's question, a supplier admitting the breach started with them. Each inject gets a time, the information released and the decision it should trigger.
- 05Run it and hold the hotwash. Keep to 2–3 hours. The facilitator releases injects, asks the CTEP discussion questions, and stops debate that is not heading toward a decision. End with a 20–30 minute hotwash: what worked, what did not, what surprised people. Collect the CTEP feedback form before people leave.
- 06Write the after-action report within a week. Use the CTEP after-action report template. List each gap, the plan or playbook section it affects, an owner and a due date. Brief the result to the executive sponsor and, where relevant, the board.
Sources: cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages, csrc.nist.gov/pubs/sp/800/61/r3/final, csrc.nist.gov/pubs/sp/800/84/final · Reviewed Sep 2026
7-3Where do tabletop exercises usually go wrong?
- The scenario is generic, so players talk about what they would do in theory.
- The right people send deputies, and nobody in the room can accept risk.
- The facilitator is also a player and cannot keep time.
- Notes record the discussion, not the decisions, so the report is an opinion.
- The findings have no owners and the same gaps appear next year.
7-4When should you use a platform instead of a template?
A CTEP costs nothing and works well for a first exercise or an annual one. Platforms earn their price when you want to exercise more often than a facilitator can prepare, when the scenario should react to decisions, or when you need consistent evidence across many exercises. Crisis simulation platforms that generate scenarios quickly (Reflex Security, TryHackMe) cut preparation time; platforms built around evidence (iluminr, Immersive Labs) help when a board or regulator asks for proof. See the rankings.
7-5What should the board see afterwards?
One page: the scenario, the objectives, whether each was met, the top three gaps with owners and dates, and when the next exercise runs. For US public companies, Regulation S-K Item 106 requires describing the processes for managing material cybersecurity risk and the board's oversight of it, and Form 8-K Item 1.05 disclosure is generally due four business days after an incident is determined to be material. An exercise that tests the materiality decision is directly relevant to both.
Sources: sec.gov/newsroom/press-releases/2023-139 · Reviewed Sep 2026
7-6Frequently asked questions
How long should a cyber tabletop exercise take?
Two to three hours for the exercise, plus a 20–30 minute hotwash. Planning takes several weeks if you facilitate it yourself.
How often should you run an incident response tabletop?
At least once a year, and after major changes to systems, suppliers or the response team. Teams that use a platform can run shorter exercises quarterly or monthly.
What is a hotwash?
A short debrief held immediately after an exercise to capture what worked and what did not while it is fresh.
Are CISA tabletop exercise packages free?
Yes. CISA publishes them for stakeholders to run their own exercises.
Next lesson: How to write exercise objectives you can grade