University · Basics: formats and roles · Lesson 4
Who should be in a cyber tabletop exercise, and what each seat is for
Invite the people who would make the real decisions, not their deputies: the incident commander, the technical leads, legal, communications and the executive who owns the business risk. Add a facilitator, an evaluator and a note-taker who do not play. Keep observers out of the discussion, and decide in advance what happens when someone cannot attend.
Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026
By Security Training assessors · 15 July 2026
L4-1Who plays?
Players are the people whose decisions the exercise tests. Start from the decisions in your objectives and work backwards: whoever would make or approve each decision in a real incident takes a seat. For most security incidents that means the following roles.
- Incident commander: the person with overall authority for the response.
- Technical leads: the SOC lead and the IT or cloud operations lead who would contain and restore.
- Legal: general counsel or the lawyer who advises on notification and disclosure.
- Communications: the person who would approve internal and external statements.
- Business owner: the executive responsible for the affected service, who can state the cost of downtime.
- Executive decision-maker: the person who makes the final call on taking systems offline, paying for recovery or disclosing.
Add HR when the scenario involves an employee or contractor, finance when a ransom or a materiality estimate is in play, and a privacy lead when personal data is involved.
L4-2Who runs it?
The exercise team does not play. The facilitator runs the session, keeps time and steers discussion toward decisions. A controller releases injects on schedule; in a small exercise the facilitator does both. An evaluator watches players against the objectives and records evidence. A note-taker keeps the decision log: what was decided, by whom, when and on what information. That log becomes the backbone of the after-action report.
The facilitator should not be the most senior security person in the room. If the CISO facilitates, the CISO cannot play, and the exercise loses the person whose decisions matter most.
L4-3How many people is too many?
A discussion needs every player to speak. Once the room grows past what one facilitator can hear, decisions drift to whoever talks first. If more people need to take part, split the exercise: run the technical and executive tracks in parallel and join them at the decisions that need both, or run the same scenario twice. Crisis simulation platforms handle scale in different ways; Conducttr, for example, says it runs from one team to more than 1,000 simultaneous teams.
L4-4What about observers and the board?
Observers learn a lot, but they change the room. Seat them apart from players, ask them not to speak, and give them a short feedback form. CISA's Tabletop Exercise Packages include one.
Boards rarely play a full exercise. A better pattern is a short session for directors on the decisions reserved for them, and a one-page summary of the main exercise afterwards. US public companies must describe the board's oversight of cybersecurity risk under Regulation S-K Item 106, so a record of how the board took part is worth keeping.
L4-5What if a key person cannot attend?
Decide before the session, not on the day. Options: send a named deputy with the authority to decide, reschedule, or have the facilitator play the role from a written brief. Some platforms offer other routes. Reflex Security describes AI agents that fill the seats of absent roles, including the CEO, and supports asynchronous play; TryHackMe says its tabletops support unlimited participants. Whatever the route, the after-action report should record who played each role, so a gap caused by an absent decision-maker is not mistaken for a gap in the plan.
Sources: cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages, csrc.nist.gov/pubs/sp/800/84/final, sec.gov/newsroom/press-releases/2023-139 · Reviewed Sep 2026
Next lesson: How to run a cyber tabletop exercise