Skip to content
Aqvil

Tutorial1 min readPublished Sep 6, 2026

Tutorial 1 min read

What a tabletop incident response exercise actually looks like

A step-by-step walkthrough of the two-hour exercise we run with clients, including the scenario we use and where teams usually get stuck.

Published · Updated

A tabletop exercise is a rehearsal for a security incident that never leaves the meeting room: no systems are touched, nobody is paged for real. The value is finding out who does not know they are supposed to make a decision, before that gap matters.

The scenario we open with

We tell the room: it is 4:50pm on a Friday. Finance reports that a wire transfer to a new vendor account, approved last week by email, now looks fraudulent. The email approving it came from the CFO's real address. Go.

Where teams get stuck, in order

  1. Deciding who has the authority to freeze the transfer without the CFO, who is unreachable for the first 20 minutes of the exercise.

  2. Realizing nobody knows the bank's fraud reporting phone number, only a generic support line.

  3. Confusing 'informing the CFO' with 'getting authorization', which delays the freeze further.

  4. Debating whether this is a security incident or a finance problem, which wastes the most time of any step.

The two hours

The first 90 minutes is the scenario, paused every 10-15 minutes so we can ask what the room would actually do right now, not what the policy document says they would do. The last 30 minutes is a debrief where we write down every gap, assign an owner, and set a date to re-test.

What clients are usually surprised by

Almost nobody fails on technical detection. Almost everybody finds at least one authority or communication gap that would have cost real hours in an actual incident. That gap is the entire point of running this before you need it.

Continue exploring

Explore this topic

Cybersecurity

All Cybersecurity content

Related experts