Countermove

Insights

What is a tabletop exercise?

A tabletop exercise tests how you respond to a serious IT incident around a table, without touching a single system. Who takes part, how a session runs round by round, and what you get out of it.

Published

A tabletop exercise is a session in which the people who would handle a serious IT incident sit down together and work through it, decision by decision, before it happens for real. No system is touched. What gets tested is your plan, your roles and the decisions you make under pressure.

What a tabletop exercise is - and what it isn't

It starts from a realistic scenario: ransomware on the production servers in the middle of the night, a data breach, a virtualisation failure or the loss of Active Directory. A facilitator describes what is happening, and the team decides what to do. Who needs to be woken up? Who has the authority to isolate systems? Which backup can you trust?

It is not a technical test. No servers are shut down, no backups are restored, and no attacker is let loose on the network. That also means a tabletop exercise cannot prove that a restore works technically. What it can show is whether you know what to do, who does it, and whether the plan holds up when decisions have to be made quickly and on incomplete information.

Nor is it an exam for individuals. The point is to find the gaps in the plan and in how people work together, while they are still cheap to close.

Who takes part?

The people who would actually be dealing with the incident. That is usually a mix of IT operations, security and management, ideally including whoever has to make the business decisions when things go wrong. Who needs to be in the room depends on the scenario.

In the Countermove sample report, six people took part: the CTO as DR lead, the Head of Infrastructure, the Lead DBA, the CISO, an Engineering Manager and the COO. Keep the group small enough that everyone gets a say, but make sure the people who own the key decisions are there.

How a session runs, round by round

A session usually takes 2–3 hours and is built up in rounds. Each round opens with a situation: what has happened, what you know, and what you don't know yet. The team discusses it and decides what to do. The facilitator then moves on, and the next development depends on what you decided - exactly as in a real incident.

Time in the scenario does not follow the clock in the meeting room. One round may take place at 02:17, the next an hour later, and the last ones several days on, when the work is about returning to normal operations and following up. That is how a couple of hours can cover an incident from the first alert, through escalation and containment, to recovery and follow-up. The exercise in the sample report ran for nine rounds.

Along the way it becomes clear where the plan carries you and where the team is improvising. Small things surface: a key person with no named deputy, a deadline nobody owns, or a backup job that is paused during the incident and never started again.

What you get out of it

What is said around the table fades quickly unless it is written down. With Countermove, an exercise ends in a written report, reviewed before it reaches you and usually delivered within five working days. It contains:

  • an executive summary written for decision-makers, not for engineers
  • key takeaways and prioritised actions, each rated high, medium or low
  • a readiness scorecard scored by a transparent, weighted method, so you can measure progress from one exercise to the next
  • an assessment of your own plan, both as a document and of how closely the team followed it
  • a round-by-round record: every situation, every decision, and how it was judged.

The prioritised actions are, in practice, your improvement plan. In the sample report, one of the high-priority actions is to name deputies for key people in the plan and have them confirm they can take on the role.

Because the method and the scorecard stay the same each time, the next exercise can show whether the actions worked, instead of starting from scratch.

How it differs from a penetration test or a full-scale exercise

The three answer different questions.

Penetration test

A penetration test is technical. Specialists try to break into your systems to find vulnerabilities before an attacker does. It answers the question: can someone get in? It says little about what happens inside the organisation once someone has.

Full-scale crisis exercise

A full-scale exercise plays out the incident as realistically as possible, often over a full day or more, with many participants, role players and sometimes real technical actions such as a failover. It gives the most lifelike picture, but it takes a lot of planning, ties up many people and can affect operations.

Tabletop exercise

A tabletop exercise sits in between. It tests decisions, roles and the plan without touching systems or taking the organisation out for a day, which makes it easy to repeat. The three do not rule each other out: a penetration test finds the holes in your defences, and a tabletop exercise shows whether you can cope when those defences fail anyway.

How to prepare

The participants don't need to prepare. That is part of the point: a real incident doesn't come with notice either. The preparation sits with whoever organises the exercise:

  • Choose the type: incident response, from the first alert to recovery, or disaster recovery, which tests your recovery plan.
  • Dig out the plan. If you have an incident response or recovery plan, the exercise is assessed against it. It doesn't have to be perfect - finding the gaps is exactly what the exercise is for.
  • Describe the organisation. Before the exercise, we build a profile of your technology, critical systems, regulatory obligations, on-call arrangements and suppliers.
  • Pick the participants and block the time. Book 2–3 hours with the right people, and make sure nobody has to leave halfway.
  • Agree beforehand who receives the report and who owns the actions afterwards. Otherwise the findings end up in a folder.

Try a round

On the front page you can try a round, a heavily simplified taste of how an exercise runs. And if you want to see what comes out of it, download the sample report (PDF): a fictional company, but a real report from a nine-round Disaster Recovery exercise. Read more about Countermove's incident response and disaster recovery tabletop exercises.

Want to see how your team would handle it?

We'll gladly show you an exercise and work out whether it fits.

Book a demo