Tutorial1 min readPublished Sep 6, 2026
What a tabletop incident response exercise actually looks like
A step-by-step walkthrough of the two-hour exercise we run with clients, including the scenario we use and where teams usually get stuck.
A tabletop exercise is a rehearsal for a security incident that never leaves the meeting room: no systems are touched, nobody is paged for real. The value is finding out who does not know they are supposed to make a decision, before that gap matters.
The scenario we open with
We tell the room: it is 4:50pm on a Friday. Finance reports that a wire transfer to a new vendor account, approved last week by email, now looks fraudulent. The email approving it came from the CFO's real address. Go.
Where teams get stuck, in order
Deciding who has the authority to freeze the transfer without the CFO, who is unreachable for the first 20 minutes of the exercise.
Realizing nobody knows the bank's fraud reporting phone number, only a generic support line.
Confusing 'informing the CFO' with 'getting authorization', which delays the freeze further.
Debating whether this is a security incident or a finance problem, which wastes the most time of any step.
The two hours
The first 90 minutes is the scenario, paused every 10-15 minutes so we can ask what the room would actually do right now, not what the policy document says they would do. The last 30 minutes is a debrief where we write down every gap, assign an owner, and set a date to re-test.
What clients are usually surprised by
Almost nobody fails on technical detection. Almost everybody finds at least one authority or communication gap that would have cost real hours in an actual incident. That gap is the entire point of running this before you need it.
Continue exploring
Detecting phishing before it reaches your employees
Most phishing that gets through is not sophisticated. It is fast. A practical layered setup for a 50-person company.
The five email security controls that stop 90% of incidents
Ranked by the incidents we have actually responded to, not by how they are usually marketed.
Why your MFA rollout probably has a gap
We have audited over 60 companies that believed MFA was fully enforced. Fewer than ten actually were.
The phishing simulation email that got the best (and worst) results
We ran the same simulation across 40 client companies. The results changed how we design every simulation since.
Explore this topic
Cybersecurity
Related experts
Sebastian Terri
Making Complex Technology Easier to Understand
1 article
