Tabletop Exercise Workshop for Crisis Team and IT

SECURITY EXPERTISE SINCE 1978. FIELD-TESTED WORKSHOP MODEL.

Tabletop Exercise Workshop for Crisis Team and IT

Prevent weeks of operational downtime before it happens. We moderate industry-specific cyber scenarios for your management, crisis team, and IT leads. Structured, audit-ready, and documented, with a concrete improvement backlog at the end. SHE brings real crisis-team experience from actual incidents into every scenario.

What is a tabletop exercise?

A tabletop exercise is a moderated crisis simulation in which a realistic scenario is played through at the table. Participants include management, crisis team, IT leads, and where relevant external stakeholders such as data protection or communications. The scenario is presented in several waves, participants make decisions, and the moderator documents observations and gaps.

Difference from penetration testing. Penetration tests assess technical vulnerabilities. A tabletop exercise tests decision-making, communication, and escalation processes. Both formats complement each other, but neither replaces the other.

Difference from live drills. Live drills or red-team exercises are full technical simulations with real attacks. A tabletop is resource-efficient, focused on the human decision layer, and for most crisis teams the right starting point before technical drills are introduced.

Structure of a SHE tabletop exercise

We work in four phases. Three are remote, one is on site. Each phase delivers a clear result and builds the foundation for the next. This creates a fully documented, audit-ready exercise in four to eight weeks.

Phase 1: Intro and alignment Remote

Duration: 1 to 2 sessions of 60 minutes each

What happens: We get to know your organization, establish a common understanding of exercise goals, and review existing emergency concepts and manuals. We gather your requirements and define the scope together.

Your deliverable: Aligned exercise briefing with goals, participants, and framework conditions.

Phase 2: Preparation and planning Remote

Duration: 2 to 3 weeks

What happens: We review your emergency concepts and manuals, clarify responsibilities and processes, identify weaknesses and critical assets. Based on this, we design an individual exercise scenario tailored to your industry, maturity, and regulatory requirements.

Your deliverable: Exercise script with phases, decision points, and expected role profiles.

Phase 3: TTX workshop and simulation On site

Duration: Half a day to a full day

What happens: The exercise takes place on site at your premises. The moderator presents the scenario in several waves. Participants handle the incident together, make role-based decisions, and simulate measures, communication, and tool usage. An observer systematically documents response times, decisions, and gaps.

Your deliverable: Exercise protocol with timestamps, decision logbook, and observations per phase.

Phase 4:  Analysis and documentation Remote

Duration: 1 to 2 weeks

What happens: We conduct a final review with you, discuss actions taken, and identify technical, process, and human gaps. From this, we document concrete improvement actions and define next steps.

Your deliverable: Lessons-learned report with observations, risk rating per gap, prioritized improvement backlog, and implementation recommendations.

Why SHE for tabletop exercises

Cyber crisis experience from real incidents.

We have supported crisis teams during real cyber incidents. This experience shapes our exercise scenarios. You train with scripts derived from real attack patterns, not from purely theoretical playbooks.

Compliant with ISO 22301 and ISO 27001.

Our tabletop exercises meet the requirements of ISO 22301 clause 8.5 and ISO 27001 Annex A.5.30. They are audit-ready and serve as compliance evidence for NIS2 section 30 BSIG and your cyber insurance.

German-language moderation from Ludwigshafen.

Our moderators speak the language of your management, understand German authority structures and legal escalation paths. On request, we also moderate in English or Romanian.

Who needs tabletop exercises?

Companies subject to NIS2. Section 30 BSIG requires regular testing of security and emergency measures. A documented tabletop exercise is direct evidence in audits.

ISO 22301-certified companies. Clause 8.5 requires regular testing of the business continuity plan. A documented tabletop is a standard proof of fulfillment.

ISO 27001-certified companies. Annex A.5.24 and A.5.30 require a tested incident response and continuity process. A tabletop covers both requirements in one exercise.

Cyber-insured companies. For higher coverage amounts, cyber insurers increasingly ask for crisis exercise evidence. A documented tabletop protocol is a strong proof point.

Companies after real incidents. If you have experienced a cyber incident, you know how important trained processes are. A structured tabletop helps turn lessons learned into actionable improvements.

We adapt scenarios to your industry and maturity level. Six examples from our practice.

Ransomware with production shutdown

A ransomware attack hits the production network and multiple machines fail. The crisis team must decide between shutdown, ransom negotiation, and restart planning. Communication with employees, customers, and supervisory authorities is part of the scenario.

Data leak with GDPR reporting obligation

A security incident is discovered and personal data is likely affected. The 72-hour deadline from GDPR Article 33 is running, the data protection authority must be informed, and possibly affected individuals as well.

Cyber extortion with pressure communication

Attackers threaten to publish sensitive data. The crisis team must decide on crisis communication, ransom strategy, and escalation to law enforcement.

Supplier compromise

A key supplier reports a cyber incident, and your own systems may be affected. The crisis team coordinates immediate actions, contractual escalation, and customer communication.

Insider threat

An employee is suspected of exfiltrating data. The crisis team coordinates HR, IT forensics, and legal measures without jeopardizing evidence.

Ransomware mit Produktionsstopp

Ein Verschlüsselungs-Trojaner trifft das Produktions-Netz, mehrere Maschinen fallen aus. Der Krisenstab muss zwischen Stilllegung, Lösegeld-Verhandlung und Wiederanlauf entscheiden. Kommunikation an Mitarbeitende, Kunden und Aufsichtsbehörden gehört dazu.

Background

Ready for the next step?

Talk to our crisis lead in Ludwigshafen about your crisis team, exercise goals, and a fitting scenario. We listen first and then propose the format that fits you best.

Test your crisis team with a moderated tabletop workshop.

Required
Required
Required
Required
Required
Required
Ansprechpartner

Contact Person

Let’s talk about your project.

Book a free initial consultation with our team at
+49 621 5200-0.
 

FAQ

What is a tabletop exercise?

A tabletop exercise is a moderated crisis simulation where a realistic scenario is played through at the table. Participants make decisions in their roles, while a moderator documents observations and identifies gaps in crisis management.

How long does a tabletop exercise take?

The exercise itself takes half a day to a full day. Preparation and planning require two to three weeks, and evaluation with a lessons-learned report takes one to two weeks. Overall, plan five to eight weeks for a complete exercise cycle.

Who should participate?

Management, crisis team, IT leads, data protection officer, and where relevant external stakeholders such as communications or legal. The optimal size is 8 to 15 active participants plus observers.

How much does a tabletop exercise cost?

The effort depends on crisis team size, scenario depth, and the desired format. After an initial consultation, we provide an individual proposal with transparent effort estimates per phase.

Which scenarios do we run?

Typical scenarios include ransomware incidents, data leaks with GDPR reporting obligations, cyber extortion, supplier compromise, insider threats, and NIS2 reporting scenarios. We adapt the scenario to your industry and maturity level.

Does the exercise meet compliance requirements?

Yes. Our tabletop records meet exercise requirements from ISO 22301 clause 8.5, ISO 27001 Annex A.5.24 and A.5.30, and NIS2 section 30 BSIG. Cyber insurers typically accept the protocol as evidence.

How often should a tabletop exercise be repeated?

We recommend at least once a year; for critical industries or high threat levels, every six months. Scenario variation is important so your crisis team experiences different stress profiles.

What is the difference between a tabletop and a live drill?

A tabletop is a moderated discussion exercise that is resource-efficient and focused on decision and communication processes. A live drill is a full technical simulation, such as a red-team attack or backup-restore test. Both formats complement each other, and tabletop is usually the right starting point.

Can we run the exercise remotely?

Yes. We also moderate hybrid and fully remote tabletops. On-site exercises are usually more intensive because non-verbal communication and side conversations become visible. We determine the right format together in the initial consultation.