Define the objective, scope and scenario
A useful exercise starts with a clear question: which decision or collaboration capability should be tested? The scenario follows from that objective, not the other way around.
Affected business services, boundaries, assumptions and success criteria are agreed in advance. The scenario remains realistic without requiring an actual compromise or changes to production systems.
Bring the right roles into the exercise
Cyber incidents affect more than IT. Depending on the objective, OT, management, communications, privacy, legal, BCM and relevant suppliers should take part.
Observers, decision-makers and operational responders are clearly separated. Missing roles are a useful finding, but they should not appear only by accident during the session.
- Executive incident lead and specialist response lead
- Business and service owners
- Communications, privacy, legal and external interfaces
Use timed injects to create decision pressure
Technical indicators, operational impact, customer enquiries and regulatory deadlines are introduced progressively. This makes dependencies and trade-offs visible.
The exercise does not assess acting performance. Information flow, decision criteria, escalation, documentation and the treatment of uncertainty matter.
Evaluate observations systematically
Unclear roles, missing data, conflicting plans, blocked decisions and unreachable contacts are recorded in a traceable way.
The result should not be reduced to pass or fail. A prioritised view of capability, assumptions and concrete improvements is more useful.
Prioritise improvements and exercise again
Each material improvement receives an owner, target state, priority and due date. Playbooks, contact lists, communication templates and recovery assumptions are updated accordingly.
A later exercise tests whether the change works in context. Discussion-based exercises and technical tests complement one another; neither replaces the other.
- Immediate contact and role corrections
- Management decisions on priority and risk
- Technical tests for recovery, access and communications
Service boundary
A tabletop is a facilitated exercise, not a penetration test, live incident or independent assurance opinion. It does not replace technical testing or case-specific legal advice.