How to Run a Cybersecurity Tabletop Exercise in 60 Minutes (No Tech Skills Needed)

Ulises Paiz

Ulises Paiz is the owner and sole engineer at Ghosxt, a Salinas, CA managed IT and cybersecurity provider. He holds an M.S. in Cybersecurity and Information Assurance (WGU, 2026) and nine industry certifications including CompTIA SecurityX, CySA+, and Microsoft AZ-104, with prior DoD and federal contractor infrastructure experience. More about Ulises →

Most small businesses that have an incident response plan have never used it. It lives in a folder, written once, and the first real test happens at 7 a.m. on a Monday when the screens show a ransom note. That is the worst moment to find out the plan lists a phone number that no longer works.

A cybersecurity tabletop exercise fixes that. It is a structured conversation, no computers required, where your team walks through a fictional attack and says what they would do. It costs an hour and a pot of coffee, and it is one of the most effective security investments a small business can make.

What a tabletop exercise actually is

Think of a fire drill for your data. A facilitator describes an incident in stages, and the group answers a few simple questions at each stage: What do we do first? Who do we call? Who decides? What do we tell customers? Nobody touches a system, and nobody is graded. The goal is to find the places where the plan, or the people, are unclear.

If you do not yet have a written plan, start with our guide to building an incident response plan. A tabletop exercise is the step that proves the plan works. It also pairs well with a business continuity plan, since many of the questions overlap.

1. Pick a realistic scenario

Choose something that could plausibly happen to your business this year, not a movie plot. Three scenarios cover most small businesses:

  • Ransomware on the file server. A staff member finds files renamed and a note demanding payment. Backups may or may not be intact.
  • A compromised email account. Customers report strange messages from your owner or bookkeeper. See how business email compromise usually unfolds.
  • A fake payment request. A convincing message or deepfake voice call asks accounting to change bank details or send an urgent wire.

Write the scenario as a short story of three or four "injects," each revealing a bit more. For example: at 8:05 a.m. someone cannot open a spreadsheet; at 8:20 three more people report the same; at 9:00 a message appears demanding payment in cryptocurrency; at 10:00 a customer asks why they cannot reach you.

2. Run it out loud, in about an hour

Gather three to six people who would make decisions in a real incident: the owner, whoever manages IT or your IT provider, the person who handles money, and whoever speaks to customers. Then follow a simple agenda:

  • 5 minutes: explain the rules. This is a no-blame exercise, and "I don't know" is a useful answer.
  • 40 minutes: read each inject and ask the group the questions below.
  • 15 minutes: review what you learned and capture the fixes.

At every stage, ask the same handful of questions. Who is in charge right now? Who do we call first, and do we have their number saved somewhere that does not depend on the affected systems? Do we shut something off or keep working? Would we pay, and who decides? When do we tell customers, our insurer, or regulators? Our guide to the California breach notification law helps with that last one.

Resist the urge to solve everything in the room. Your job as facilitator is to surface gaps and write them down, not to fix them live.

3. Capture the gaps and fix them

The exercise only pays off if the findings turn into action. Use a simple scorecard with four columns: what went wrong or was unclear, the fix, the owner, and the due date. Typical findings from a first exercise include:

  • Nobody knew the cyber insurance claim number or that the policy requires calling the carrier before hiring a responder.
  • Backups exist, but nobody has ever tested a restore, so recovery time is a guess.
  • Only one person has the admin password, and they are on vacation.
  • No one is authorized to shut down the network or email without asking the owner.

Most of these fixes take minutes: print a one-page contact sheet, store an offline copy of key numbers, name a backup decision-maker. Keep a dated record of the exercise and the fixes. It becomes useful evidence for cyber insurance renewals and customer security reviews.

Common mistakes to avoid

  • Making the scenario too technical. Focus on decisions and communication, not malware names.
  • Letting the loudest person answer for everyone. Ask each role what they would do.
  • Skipping the follow-up. A list of findings with no owners changes nothing.
  • Running it once and never again. Repeat every six to twelve months, and after any major change in staff or systems.

The takeaway

You do not need an expensive consultant or a security team to find the weak spots in your response. One hour, one realistic scenario, and an honest conversation will show you what would slow you down in a real attack. Fix those few things now, and when an incident does happen, your team will have already done it once. October is Cybersecurity Awareness Month, which makes this a good week to put an hour on the calendar.

Frequently asked questions

How long does a cybersecurity tabletop exercise take?

A focused tabletop exercise for a small business takes about 60 minutes: 5 minutes to set the stage, 40 minutes to walk through the scenario, and 15 minutes to record what went wrong and who will fix it. Run it once or twice a year.

Do I need a consultant to run a tabletop exercise?

No. A first exercise works fine with the owner or office manager reading a scenario aloud while a few key people explain what they would do. A neutral outside facilitator helps once you have run a few, because they ask questions insiders forget to ask.

Who should attend a tabletop exercise?

Anyone who would make decisions or take action during an incident: the owner, whoever manages IT or your IT provider, the person who handles money, and whoever speaks to customers. Three to six people is plenty.

What is the difference between a tabletop exercise and a penetration test?

A penetration test attacks your systems to find technical weaknesses. A tabletop exercise tests your people and plan by talking through a made-up incident. They answer different questions, and the tabletop is far cheaper and quicker.

Does a tabletop exercise count for cyber insurance?

Many insurers and customer security questionnaires ask whether you test your incident response plan. A dated record of a tabletop exercise, with findings and fixes, is a simple way to answer yes with evidence. Check your own policy for exact requirements.

Want help running your first tabletop exercise?

Ghosxt facilitates tabletop exercises for small businesses, helps you turn the findings into a working incident response plan, and handles the fixes. You talk directly to the owner. See current pricing or our cybersecurity services.

Book your free assessment

Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.

Book free assessment Call (831) 204-0501