
I have sat through more painful tabletop exercises than I can count. Two hours of reading from a script while executives check their phones. A facilitator who clearly downloaded the scenario the night before. Technical staff arguing about whether the fictional attacker would “really” use that technique. The worst part? Everyone walks out thinking they are prepared for an actual incident. They are not.
A good tabletop exercise builds muscle memory, reveals gaps, and creates relationships that matter when everything is on fire. A bad one wastes everyone’s time and creates false confidence. After running dozens of these across multiple organizations, I have learned what separates the two.
Why Most Tabletop Exercises Fail
The fundamental problem is that most tabletop exercises are designed to check a compliance box, not to actually prepare people. They follow a predictable pattern: someone reads an inject, the group discusses what they would do, someone writes it on a whiteboard, and everyone moves to the next inject. This teaches people to talk about incidents, not to handle them.
The second failure mode is scope. Organizations either go too narrow, testing only the security team, or too broad, trying to simulate every possible scenario in a single afternoon. Neither approach builds real capability. You need focused exercises that test specific decision points with the right people in the room.
The third problem is stakes. When everyone knows it is just an exercise with no real consequences, behavior changes. People make decisions they would never make under actual pressure. They consult resources they would not have time to check. They take risks knowing nothing bad will actually happen.
Tabletop Exercise Design That Actually Works
Start with a specific learning objective. Not “test our incident response plan” but “determine whether our legal team understands when we need to notify customers.” Or “find out if the SOC can escalate to executives when the CISO is unreachable.” Narrow focus produces actionable results.
Build your scenario from real incidents. I pull from public breach reports, adapt incidents that hit our industry, or use sanitized versions of things that actually happened to us. The scenario should feel plausible enough that participants stop thinking about whether it could happen and start thinking about what they would do.
Time pressure changes everything. Instead of leisurely discussions, give participants five minutes to make a decision. Present incomplete information and force them to act anyway. This is what the first 24 hours of a real breach actually feels like. Comfortable exercises create comfortable responses that fall apart under real stress.
Include curveballs. Real incidents never follow the playbook. Your primary contact is on vacation. The backup system you planned to restore from has the same malware. A reporter calls before you have finished your internal assessment. These moments reveal whether your team can adapt or just execute a checklist.
Who Needs to Be in the Room
The biggest tabletop exercise mistake I see is treating it as a security team event. If your exercise only includes security people, you are practicing the wrong skills. Security teams already know how to investigate and contain threats. What they do not practice is coordinating with legal, communicating with executives, managing vendor relationships, or handling media inquiries.
Your exercise roster depends on your learning objective. Testing executive communication? You need the C-suite or people empowered to make decisions on their behalf. Testing cross-functional coordination? Include IT, legal, HR, communications, and business unit leaders. Testing technical response? That is the only time an all-security exercise makes sense.
Getting executives in the room is hard. They are busy. They think exercises are beneath them. I have had success framing it as a risk reduction activity that requires their specific expertise. Not “we need you to attend a tabletop” but “we need to test a decision that only you can make.” Make it clear the exercise will be efficient and directly relevant to their responsibilities.
Running the Exercise
Start with context, not inject. Explain the current state of your environment, what systems are running, what recent changes have occurred. This grounds the scenario in reality. Then introduce the initial indicators without immediately revealing the full scope of the incident.
Play the role of the world, not the facilitator. When the team says they want to call the vendor, respond as the vendor would. When they ask what the firewall logs show, tell them. When they make a decision, fast forward time and show them the consequences. This active facilitation style keeps momentum and prevents the exercise from becoming a lecture.
Document everything. Who made which decisions. What information they asked for. Where they got stuck. What assumptions they made. This documentation is more valuable than the exercise itself because it feeds directly into process improvements.
Resist the urge to correct mistakes in real time. If the team goes in the wrong direction, let them. The debrief is where learning happens. Interrupting to fix errors teaches people to wait for the facilitator to give them the right answer, which is exactly the opposite of what you want.
The Debrief Matters More Than the Exercise
Schedule the debrief immediately after the exercise while everything is fresh. I have seen organizations promise to do it later and never get around to it. All the value from the exercise evaporates when that happens.
Structure the debrief around decisions, not events. “What information did you need to decide whether to shut down production?” reveals more than “What did you do when you saw the ransomware note?” This approach follows the same blameless postmortem principles that work for real incidents.
Identify the gaps, not the failures. The point is not to criticize people for making wrong decisions under pressure. The point is to find where processes, documentation, or communication broke down. “We did not have a clear escalation path to the board” is actionable. “Bob made a bad call” is not.
Assign owners to every identified gap and set deadlines. An exercise that produces a list of findings but no remediation plan is almost as useless as no exercise at all. I track exercise findings the same way I track audit findings. They go into a remediation tracker with owners and due dates.
Building a Tabletop Exercise Program
One exercise per year is compliance theater. You need a cadence that builds capability over time. I run quarterly exercises with different scopes and audiences. One focused on technical response. One on executive communication. One on third-party coordination. One on regulatory notification. Each exercise builds on lessons from the previous ones.
Vary your scenarios. Ransomware this quarter, insider threat next quarter, supply chain compromise the quarter after. Different scenarios test different muscles and prevent your team from over-preparing for a single threat type.
Track improvement over time. Compare how quickly decisions get made, how many gaps get identified, how well cross-functional communication works. This data helps justify the investment and shows whether your program is actually building capability.
Share results with leadership. Not just a summary of what happened, but what you learned and what you are doing about it. This visibility helps when you need executive time for future exercises and demonstrates that security is actively working to reduce risk. I cover exercise outcomes in my board updates because it shows proactive preparation rather than just reactive spending.
CISA provides free tabletop exercise packages that can serve as starting points for your scenarios.
What Good Looks Like
You know your tabletop exercises are working when people reference them during real incidents. “Remember in the exercise when we had trouble reaching legal? Let’s use the backup contact we established.” That is the goal. Building institutional knowledge and relationships that activate under pressure.
Good exercises surface uncomfortable truths. If every exercise ends with everyone feeling confident and prepared, you are not pushing hard enough. Real incidents are chaotic and stressful. Your exercises should give people a taste of that chaos so they are not experiencing it for the first time when something actually goes wrong.
The best compliment I ever received after an exercise was “that was terrible.” The participant meant it as criticism, but it told me we had created realistic pressure. They felt uncomfortable because they realized how unprepared they were. Six months later, when a real incident hit, that same person told me the exercise had been the only reason they knew what to do.
Stop running exercises that make everyone feel good. Start running exercises that make your organization better.