GlossarySOC and monitoring

Tabletop exercise

Short answer

A tabletop exercise is a discussion based simulation in which a team walks through a realistic security incident, such as a ransomware attack, to test its incident response plan, roles and decisions without touching real systems. It reveals gaps before a real incident does.

How it works

A facilitator presents a scenario in stages, adding new information as it unfolds: an alert, then encrypted servers, then a ransom note, then a journalist calling. Participants explain what they would do, who they would call and what they would decide. The exercise usually lasts two to four hours.

Who should take part

Not only IT. The most valuable exercises include management, legal, communications, operations and finance, because many critical decisions in an incident are business decisions: whether to shut down systems, what to tell customers, whether to notify authorities and when.

Common scenarios

Ransomware affecting core systems, a data breach with a 72 hour notification deadline, BEC fraud, a critical supplier going down, or the loss of a key cloud service.

What comes out of it

A short report with the gaps found, such as missing contacts, unclear authority, untested backups or unknown notification deadlines, and actions with owners and dates to update the incident response and business continuity plans. DORA requires financial entities to test their continuity and response plans, and exercises like this are a common way to show ISO 27001, ENS or NIS2 auditors that plans are tested.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub