CRISISTABLETOP

FACILITATOR FIELD GUIDE

How to run a tabletop exercise

A useful tabletop is a controlled decision laboratory. It reveals whether people can recognize a crisis, assemble the right team, exercise real authority, work from incomplete facts, meet legal obligations, preserve operations, and improve the plan afterward.

Choose an exerciseSee the 120-minute agenda

WHAT A TABLETOP IS

A discussion-based exercise with operational consequences

CISA describes a tabletop exercise as a facilitated discussion of a scripted scenario in an informal, stress-free environment. “Stress-free” does not mean consequence-free. The scenario should force participants to confront gaps in authority, information, communication, plans, vendors, tools, and time.

A tabletop does not prove that technology will work. It tests how people expect to use plans and capabilities. Pair it with functional exercises, technical simulations, backup restoration, communications tests, and other validation when the objective requires operational proof.

DESIGN & PREPARATION

Six steps from risk to an exercise the room can use

  1. 01

    Define the risk and two to four objectives

    Start with a credible threat to a critical business service, regulated data set, product, person, or obligation. Write observable objectives such as “validate who can suspend a customer platform” or “test whether legal receives facts needed for a 72-hour notice analysis.” Avoid objectives like “raise awareness” unless you define what evidence shows success.

  2. 02

    Build a small exercise design team

    Include the exercise owner, facilitator, scenario subject-matter experts, counsel when legal issues matter, and an evaluator or note-taker. Keep scenario details from players. Resolve in advance which assumptions are fixed, which facts can be requested, and what information the facilitator may release.

  3. 03

    Tailor a realistic scenario

    Use the organization’s actual services, vendors, geography, escalation paths, contracts, regulators, communications channels, recovery objectives, and business calendar. Change names and sensitive details where needed. A credible scenario should be plausible enough that “this cannot happen here” is not an easy escape.

  4. 04

    Write injects that create decisions

    Each inject should change the facts, raise the stakes, remove an easy option, expose a dependency, or create a deadline. Attach facilitator notes, discussion questions, expected decision owners, and optional private information for selected roles. Do not write a quiz with one hidden correct answer.

  5. 05

    Prepare the room and the participants

    Send scope, purpose, time, roles, ground rules, and preparation requests without revealing the plot. Confirm accessible copies of plans, contracts, regulator contacts, insurer instructions, vendor contacts, call trees, data maps, and out-of-band communications. Decide how remote participants and observers will join.

  6. 06

    Define evaluation before the exercise begins

    Create an observation sheet tied to the objectives. Capture decisions, authorities, facts requested, delays, workarounds, strengths, gaps, and disputed assumptions. Decide who owns the after-action report and how corrective actions will be tracked to closure.

PEOPLE IN THE ROOM

Separate exercise control from real-world decision ownership

FACILITATOR

Controls pace and tests reasoning

Releases injects, asks for decisions, prevents one function from dominating, separates known facts from assumptions, and keeps the group aligned to objectives.

PLAYERS

Act in their real roles

State what they would do, who has authority, what information they need, whom they would contact, what record they would create, and when they would escalate.

EVALUATOR / NOTE-TAKER

Captures observable evidence

Records decisions and gaps against objectives without turning the exercise into a performance review of individuals.

OBSERVERS

Watch without steering

Learn from the session and provide structured observations during the hotwash. They should not supply facts or rescue players.

SIMULATION CELL

Represents the outside world

Answers calls or messages as vendors, regulators, law enforcement, customers, attackers, employees, reporters, or other absent stakeholders.

EXERCISE DIRECTOR

Owns scope and safety

Approves objectives, resolves exercise-control issues, pauses the session when necessary, and ensures corrective actions receive executive sponsorship.

SAMPLE RUN OF SHOW

A 120-minute cross-functional tabletop

00:00–00:10
Welcome and ground rules

Objectives, assumptions, no-fault environment, exercise versus real-world communications, confidentiality, and how participants request facts.

00:10–00:25
Module 1: detection and escalation

Release the opening inject. Test incident thresholds, initial command, evidence, immediate containment, and who is missing.

00:25–00:50
Module 2: scope and operational impact

Add uncertainty, business interruption, affected data, a critical vendor, or conflicting technical indicators.

00:50–01:20
Module 3: decision pressure

Force materiality, notification, payment, shutdown, patient-safety, employment, customer, or public-communications decisions.

01:20–01:40
Module 4: recovery and scrutiny

Test trusted restoration, evidence of safety, regulator and customer follow-up, board reporting, and transition to normal governance.

01:40–02:00
Hotwash and commitments

Identify strengths, gaps, immediate safeguards, longer-term remediation, owners, due dates, and executive escalation.

For a board exercise, give management enough time to establish the facts and options before asking directors to exercise oversight. For a technical exercise, do not let tool-level discussion displace command, legal, continuity, and communications decisions.

FACILITATION

Ask for a decision, then test what supports it

Use five follow-up questions

  1. Who owns that decision?
  2. What authority, policy, contract, or law supports it?
  3. What fact would change the decision?
  4. Who must be told, by whom, and by what deadline?
  5. What evidence or record will show what happened?

Keep the exercise moving

  • Time-box rabbit holes and record them as follow-up work.
  • Ask quieter functions first when their role is being assumed by others.
  • Release private injects to expose information asymmetry.
  • Distinguish “we would” from a named owner, action, and time.
  • Let plans fail. Do not repair them from the facilitator’s chair.
  • Pause immediately for a real incident or participant safety issue.

EVALUATION & IMPROVEMENT

The hotwash is the start of the work

WITHIN THE SESSION

Hotwash

Ask what worked, where authority or information was unclear, what assumption failed, and which immediate safeguard is necessary. Read back every proposed action.

WITHIN 10 BUSINESS DAYS

After-action report

Organize observations by objective. Separate facts from interpretations. Describe consequences, root causes, existing compensating controls, and the evidence supporting each finding.

UNTIL CLOSED

Improvement plan

Give every action one accountable owner, a due date, a priority, and a closure test. Track plan, policy, training, contract, architecture, tooling, staffing, and governance changes.

LEGAL, REGULATORY & STANDARDS MAP

Why legal, security, and privacy teams exercise together

No single framework covers every crisis decision. Use the authorities that apply to the organization’s sector, data, locations, contracts, listings, licenses, customers, and services.

CISA Tabletop Exercise Packages

Customizable cyber scenarios, objectives, discussion questions, planning materials, and after-action tools.

NIST SP 800-84

A structured method for designing, developing, conducting, and evaluating IT test, training, and exercise events.

NIST SP 800-61 Rev. 3

Current incident-response recommendations aligned to Cybersecurity Framework 2.0 and continuous improvement.

FEMA HSEEP

A common exercise cycle: program management, design and development, conduct, evaluation, and improvement planning.

SEC cyber disclosure rules

For public companies, test escalation to disclosure decision-makers, materiality analysis, documentation, and Form 8-K Item 1.05 timing.

FTC Safeguards Rule

Covered financial institutions need a written incident response plan with roles, communications, documentation, remediation, and postmortem processes.

HIPAA Security Rule

Healthcare teams should test security-incident procedures, contingency operations, restoration, documentation, and periodic safeguards evaluation.

HIPAA Audit Protocol

OCR examines incident response and periodic testing and revision of contingency plans, including backup and restoration evidence.

New York DFS Part 500

Covered financial-services entities should align exercises to incident response, business continuity, disaster recovery, governance, and reporting obligations.

GDPR Articles 33 and 34

Test awareness, risk assessment, documentation, supervisory-authority notice within 72 hours where required, and communication to affected people.

EU DORA

Covered financial entities must maintain and periodically test ICT business continuity and response-and-recovery plans, including third-party failures.

NIS2 Directive

Relevant entities should test management accountability, incident handling, business continuity, supply-chain security, and staged incident reporting.

PCI DSS

Requirement 12.10 addresses incident-response readiness. The plan and listed elements must be reviewed and tested at least annually.

ABA Formal Opinion 483

For lawyers, a data breach can implicate competence, confidentiality, communication, supervision, and post-breach obligations.

PRACTITIONER GUIDANCE

What experienced counsel and incident responders emphasize

COMMON QUESTIONS

Tabletop exercise FAQ

How long should a tabletop exercise last?

A focused cross-functional exercise usually needs two to three hours. A 60–90 minute session can validate one narrow decision path. Complex enterprise or board exercises may run in separate technical, business, and executive sessions.

Who should facilitate?

Use a neutral facilitator who understands the scenario and can press for decisions without answering for the players. The facilitator should not be the person whose plan or program is being tested.

Should outside counsel lead the exercise?

Counsel may design or lead an exercise when legal strategy, privilege, investigations, notification, enforcement, or litigation risk is central. Privilege is fact-specific and should never be assumed merely because a lawyer attends.

How often should teams run tabletop exercises?

Run them on a risk-based cadence and after material changes to systems, vendors, leadership, law, operations, or the incident plan. Some standards and contracts impose annual testing expectations. High-risk teams often exercise different scenarios throughout the year.

What makes a tabletop exercise fail?

Common failures include vague objectives, too many participants, unrealistic facts, revealing every answer in advance, letting technical debate consume the session, skipping decision authority, and ending without owners and due dates.

READY TO FACILITATE

Start with a complete scenario, then make it yours.

Every role, inject, decision path, discussion prompt, private message, deadline, and presentation theme can be adapted before the room opens.

Explore pre-built exercises →