## Purpose

Use this template to practice how the company would respond to a cybersecurity incident without disrupting real systems.

A tabletop exercise presents a realistic scenario and asks participants to explain what they would do, who they would contact, what decisions they would make, and what information they would need.

The goal is to identify gaps before a real emergency occurs.

## Exercise Information

Exercise ID: ____________________

Date: ____________________

Facilitator: ____________________

Participants: ____________________

Scenario: ____________________

Expected duration: ____________________

## Suggested Participants

**Depending on the scenario:**

- Leadership
- IT
- MSP
- Finance
- HR
- Legal
- Cybersecurity
- Communications
- Operations
- Relevant business owner

## Scenario Options

**Examples include:**

- Ransomware
- Business email compromise
- Supplier payment fraud
- Compromised executive mailbox
- Lost laptop containing sensitive information
- Cloud data exposure
- Critical SaaS outage
- Vendor compromise
- Insider misuse
- Website compromise
- Stolen administrator credentials

## Exercise Scenario

Initial situation:

---

Example:

“Finance reports that several employees cannot access shared files. IT identifies unusual file encryption activity on a server. The backup console is also showing unexpected administrative changes.”

## Stage 1: Detection

**Ask:**

- Who receives the initial report?
- Who decides whether this is an incident?
- Who becomes Incident Response Lead?
- Where is the incident recorded?
- Which communication channel is used?
- What evidence should be preserved?

Participant observations:

---

## Stage 2: Escalation

Introduce additional information:

---

**Example:**

“The MSP believes an administrator account may be compromised.”

**Ask:**

- Who must be notified?
- Does leadership need to be involved?
- Should the insurer be contacted?
- Is external incident response support available?
- Who has authority to take systems offline?

Observations:

---

## Stage 3: Containment

Introduce:

---

**Example:**

“Similar activity appears on two additional devices.”

**Ask:**

- Which accounts should be disabled?
- Which devices should be isolated?
- Should remote access be restricted?
- How will backups be protected?
- What business disruption will containment create?
- Who approves significant containment actions?

Observations:

---

## Stage 4: Business Impact

Introduce:

---

**Example:**

“Customer orders cannot currently be processed.”

**Ask:**

- Which business processes are most important?
- What workarounds are available?
- Who communicates with employees?
- Do customers or vendors need information?
- What should the company avoid saying before facts are confirmed?

Observations:

---

## Stage 5: Recovery

Introduce:

---

**Example:**

“A clean backup appears available, but the original entry point has not yet been fully confirmed.”

**Ask:**

- Should recovery begin?
- How will the company determine whether the restore point is trustworthy?
- What security changes are needed before restoration?
- Who validates restored systems?
- Who approves return to service?

Observations:

---

## Stage 6: After the Incident

**Ask:**

- What evidence should be retained?
- Who performs the post-incident review?
- What regulatory, contractual, insurance, or customer reporting may be required?
- How are improvement actions assigned?

Observations:

---

## Exercise Findings

### What Worked Well

---

### Responsibilities That Were Unclear

---

### Missing Information

---

### Missing Contacts

---

### Technical Gaps

---

### Process Gaps

---

### Training Gaps

---

### Recovery Gaps

---

## Improvement Actions

Action: ____________________

Owner: ____________________

Priority: ____________________

Due date: ____________________

Evidence required: ____________________

Repeat for each significant finding.

## Exercise Completion

Facilitator: ____________________

Leadership reviewer: ____________________

Exercise date: ____________________

Actions transferred to Improvement Action Tracker:

- Yes / No

Next exercise date: ____________________

Evidence location: ____________________

## Practical Rule

A tabletop exercise should expose confusion while the company still has time to fix it.

The most useful question is:

**“If this happened today, would everyone know what to do next?”**
