Your first tabletop exercise
When we wrote about the first hour of an incident, the closing point was that nobody trains for that hour — and that the fix is a tabletop exercise: sit the team down, walk through an incident that has not happened, and find out what you would actually do. Several readers asked the obvious next question: how, exactly? What do we say at 2:00pm on the quiet Thursday we booked for this?
Fair question. A tabletop run badly is a meeting that makes everyone feel vaguely guilty. A tabletop run well is the single highest-return security hour a small team can spend — it costs nothing, touches no production systems, and reliably surfaces the gaps that would otherwise be discovered at 2:00am with customers watching. Here is a complete first exercise: the format, a scenario, and the traps.
What a tabletop is, and is not
A tabletop exercise is a structured conversation: a facilitator narrates a fictional incident in stages, and the people who would really respond say what they would really do — decisions, messages, commands — while someone writes down every gap between "what we assumed" and "what we found." Nothing is touched. No systems, no alerts, no theatrics.
It is not a test with a pass mark, and this needs saying out loud at the start: the exercise is designed to find gaps, so finding gaps is the exercise working. A tabletop that ends with "we were fine on everything" was too easy; run a harder one next quarter. A team that leaves feeling slightly embarrassed and holding six action items got their money's worth.
Who is in the room
Small enough to talk honestly, complete enough to hit the real handoffs — four to eight people. That usually means: whoever holds the pager or notices problems first; whoever can actually operate the affected systems; whoever would talk to customers; and — this one is skipped most often and matters most — whoever can spend money and approve downtime. At a small company that is the founder. If the founder is not in the room, the exercise will politely route around the most important question: who can say "take production down" or "pay for the forensics firm," and how fast can you reach them on a Saturday?
One person facilitates and does not play. One person scribes: every assumption, every "wait, who has access to that?", every action item.
The 60-minute format
Minutes 0–5 — set the frame. The facilitator states the rules: this is fiction, there are no wrong answers, we are hunting gaps not grading people, and everything answered must be answered specifically — not "we'd restore from backup" but "who restores, from where, how long does it take, when did we last test it?" Vague answers are where gaps hide.
Minutes 5–15 — inject one: the alert. Read the scenario's opening beat (one is provided below). Then the first-hour discipline from the earlier piece, applied: what kind of incident might this be, who is told, who leads, where do we talk, and what do we write down first? Before anyone speaks, have each person write their first three actions privately, then compare. The variance in those notes — five people, three different assumed leaders, two different chat channels — is the muscle-memory gap made visible. This two-minute trick is the single most revealing moment of a first tabletop.
Minutes 15–30 — inject two: it is real. Escalate: the suspicious thing is confirmed real and it is worse than it looked. Now the operational questions: can we actually see what is happening (do the logs exist? who can read them?), what is the containment move, and what would we not touch to preserve evidence? Push on specifics relentlessly: "the logs" is not an answer; "which system, who has access, how far back" is.
Minutes 30–45 — inject three: the outside world arrives. A customer notices, or the data looks personal, or both. Who decides whether a regulatory clock has started — and does anyone in the room know when the 72-hour clock actually starts? Who drafts the customer message, who approves it, and what does the first holding line say? At most first tabletops the room goes quiet here. That silence is a finding — communication gaps are the most common and most consequential discovery of a first exercise.
Minutes 45–60 — stop and harvest. Do not let the scenario expand to fill the hour. The scribe reads back every gap; the room turns each into an action item with an owner and a date. Six to twelve items is typical for a first run: "backup restore never tested — Sam, by the 15th," "no out-of-hours contact tree — Priya, this week," "nobody can approve customer comms on a weekend — founder to decide." One page, kept where the next exercise can find it.
A first scenario that earns its hour
Pick something that could plausibly happen to you — recognisability is what makes the room take it seriously. A reliable first choice for almost any small company:
Inject one: Monday 08:40 — a developer mentions in chat that a routine job failed overnight with authentication errors, and that a credential for a production service seems to have been changed. Nobody on the team changed it.
Inject two: 09:30 — sign-in logs show that credential used successfully at 03:12 from an unfamiliar network, followed by a large read of the customer database.
Inject three: 10:15 — a customer emails support: "Did something happen to your systems? We got a strange password-reset email overnight." The database contains names, emails, and billing addresses of customers in several countries.
Three beats, one hour, and it exercises detection, access control, evidence, backups, the regulatory question, and customer comms. Next quarter, rotate the type: a ransomware note on a Friday evening; a laptop stolen with a session still open; a researcher reporting a serious product flaw; a key vendor announcing their own breach.
The traps
Fixing the scenario instead of the process. Engineers will happily spend forty minutes debating how the credential leaked. Redirect: "assume it happened — what do we do?" The tabletop tests response, not prevention; prevention debates are for the follow-up.
The walkthrough that is actually a lecture. If the facilitator narrates what the plan says while everyone nods, nothing was tested. The value is in what people say they would do, unprompted.
Actions without owners. An exercise whose action list has no names and no dates was a conversation. The list is the deliverable — and reviewing last quarter's list is the first item of the next exercise.
Waiting until the plan is "ready." Running the tabletop before the documentation is polished is not cheating — it is the fastest way to find out what the documentation actually needs to say. A team that tabletops quarterly with an imperfect plan will outperform a team with a beautiful plan it has never spoken aloud.
When you want this ready to use
Sylvan Assurance's First 4 Hours toolkit ships the artefacts a tabletop exercises against — the first-hour runbook, the escalation tree, the incident log, and the pocket reference card — in editions for a solo practitioner, a designated incident commander running the room, or a software team facing EU Cyber Resilience Act reporting duties. Editions from $49. Print them, put them on the table, and let the exercise test the artefacts along with the team. The companion Sylvan Press field guide, The First 4 Hours, includes the same playbook run at four organisational sizes.
The free First 4 Hours triage at sylvanassurance.com/free/first-4-hours also makes a fine exercise companion: answer its five questions in character during inject two and compare its Battle-Card against what the room decided. It runs entirely in your browser. Your answers are never transmitted.
Prefer the long form? The companion Sylvan Press title, The First 4 Hours, covers the same ground in depth.
See where you stand
Want a preview of what your tabletop will find? The free triage asks five questions about a current or hypothetical incident and returns a tailored first-hours Battle-Card. It runs entirely in your browser — your answers never leave your device.