CyberISolve

Incident Response

Why We Run Tabletop Exercises Before a Business Ever Needs Incident Response for Real

October 22, 2025 · 5 min read

A lot of businesses have an incident response plan sitting in a document somewhere that nobody has looked at since it was written. A tabletop exercise is where we actually walk a team through a simulated incident, in real time, and see whether the plan holds up outside of the document it’s written in.

What the exercise actually looks like

We present a realistic scenario — a ransomware note appearing on file servers, or a report of unusual account activity — and walk the team through it in stages, asking what they’d actually do at each point, who they’d call, and what decisions need to be made under time pressure. It’s deliberately conversational and low-stakes, since the goal is finding gaps, not testing individuals.

What these exercises usually surface

  • Nobody’s sure who has the authority to make the call to take a system offline
  • The "emergency contact list" is out of date, or nobody knows where to find it during an actual incident
  • Legal and communications aren’t looped in early enough in the plan
  • The plan assumes access to systems that would themselves be affected by the incident (a shared drive, an email system) with no fallback
  • Nobody has actually tested whether the backups referenced in the plan restore successfully

Why this matters more than the document itself

A real incident is stressful and time-compressed in a way a written plan doesn’t prepare anyone for on its own. A team that’s walked through the scenario once, even hypothetically, responds meaningfully faster and with less confusion than one reading a plan for the first time during an actual breach. We recommend running one of these at least annually, and after any major change to systems or team structure.

← All Blogs

Related reading

Dealing with something similar?

Tell us what's going on — active incidents get a same-day response, 24/7.