Why Every Executive Team Should Run a Cyber Tabletop Exercise
What happens if your executive team is sitting around a conference table and someone says, “We’ve just been hit with ransomware”?
Systems are locked. Employees can’t log in. Customers are calling. Your operations are stalled. The clock is ticking.
In that moment, there are only two types of leadership teams: those who have practiced for this day — and those who are about to figure it out in real time.
That’s the difference a tabletop exercise makes.
What a Tabletop Exercise Really Is
A tabletop exercise is exactly what it sounds like. You gather your executive team around a table and walk through a realistic cybersecurity incident step by step. You exercise your incident response plan the same way a fire department runs drills.
It’s not theoretical. It’s not technical for the sake of being technical. It’s practical.
At the state of Michigan, when I served as CIO, our tabletop exercises were full-day sessions with FEMA, DHS, and multiple agencies involved. At La-Z-Boy, we ran half-day executive exercises. At SensCy, we facilitate what I call a “rapid tabletop” — 75 minutes, highly focused, executive-level.
The format may vary. The purpose does not.
You practice what you would do on a bad day — before that bad day arrives.
Cyber Incidents Aren’t IT Problems. They’re Business Problems.
One of the biggest misconceptions I see is that a cyber incident is an IT issue.
It’s not.
Fifteen years ago, maybe you could look at your CIO and say, “Take care of it.” That’s no longer reality. Today, a ransomware attack or major breach impacts every part of your organization.
Your CEO and COO need to make operational decisions.
Your legal counsel must guide communications and preserve privilege.
Your HR team understands policies and employee impact.
Your communications and marketing leaders manage external messaging.
Your supply chain leader assesses vendor exposure.
Your finance team works through insurance and financial impact.
When we run tabletop exercises, we want all those voices in the room.
Most executives know they have a written incident response plan. But many have never seen it. A tabletop puts that plan in their hands and asks a simple question:
“What do we do next?”
That question sparks one of the most important conversations a leadership team can have.
Practice Makes Better — and Faster
There’s a statistic that often surprises people: organizations without a well-exercised incident response plan can experience an average downtime of 21 days or more after a serious attack.
Twenty-one days.
Think about what that means for revenue, customers, employee morale, and brand reputation.
Without a plan, responding to a cyberattack is like being in the middle of a tornado. Everyone is reacting, moving fast, but not necessarily moving in a coordinated direction. It’s chaotic.
With a plan, you take it off the shelf. You follow step one. Step two. Step three.
Remediate the issue.
Call your cyber insurance provider — immediately. Why? Because they bring forensic experts, legal counsel, and communications support with them.
Engage the right stakeholders.
Control the narrative.
When you’ve practiced those steps, the response becomes coordinated. Focused. Faster.
I often say, “Train hard, fight easy.” Tabletop exercises are how you train.
What Actually Happens During a Tabletop Exercise?
When we facilitate a tabletop at SensCy, we build a scenario tailored to the organization. We know their environment — their systems, their vendors, their dependencies.
Then we present a realistic incident.
For example: a third-party vendor’s financial management system is compromised due to an unpatched vulnerability. The attacker moves laterally from that vendor into your organization through a trusted connection.
This isn’t hypothetical. We’re seeing more and more third-party and supply chain–driven attacks.
Or we simulate a social engineering call to your help desk. An employee gives up credentials. The attacker gains access and begins escalating privileges.
We walk through it together.
“What do we do?”
“Who’s responsible for that step?”
“Have we notified the right people?”
“Are we using the right language?”
Sometimes people sweat a little. That’s OK. A little pressure in a tabletop exercise is far better than full pressure during a live incident.
By the end of 75 minutes, we’ve uncovered gaps. We’ve clarified roles. We’ve identified communication improvements.
And I’ve never facilitated a tabletop that didn’t result in changes to the plan.
Never.
The Most Common Lessons from Tabletop Exercises
Every organization is different, but certain themes always emerge.
First, roles change. People leave. People get promoted. An incident response plan written two years ago may list the wrong individuals in critical roles.
Second, communication is almost always more complex than leaders expect. There’s a significant legal distinction between a “cyber incident” and a “cyber breach.” The words you use matter. Attorney-client privilege matters. Notification requirements vary by industry.
Third, executives gain clarity about their own responsibilities. Many leaders walk into a tabletop assuming it’s largely technical. They walk out understanding that they play a critical role in decision-making, communication, and business continuity.
Each exercise makes the plan better.
Practice doesn’t make perfect. Practice makes better.
Why Every Organization Should Run One Tabletop Annually
Cybersecurity isn’t static. Your organization isn’t static either.
Your people change.
Your vendors change.
Your technology stack evolves.
Threat actors get more sophisticated.
An incident response plan that sits untouched on a shelf is not a strategy.
Every organization should have a written incident response plan. And every organization should exercise it at least once a year.
Not because you expect disaster.
But because leadership means being ready for it.
On a bad day, you don’t want to be figuring out who calls the insurance carrier. Or who drafts the first customer communication. Or whether legal has reviewed the language being used.
You want clarity. Coordination. Confidence.
A tabletop exercise gives you that.
You may never face your worst-case scenario. But if you do, your organization will respond not with chaos — but with preparation.
And that preparation can make all the difference.

The SensCy Solution
We provide an affordable, easy-to-understand, sensible solution specifically tailored to each client. Our clients tell us that they are thrilled with the value that they derive for the price they pay. Schedule a consultation with one of our experts.

Your SensCy Score® is a good indication of your organization’s cyber hygiene and how prepared your organization is against cyber threats. We can generate your score in less than 30 minutes—at no cost to you!
Recent Posts
