02/ TABLETOP EXERCISES
Rehearse the incident. Don’t improvise it.
A facilitated, scenario-based exercise where your leadership, and your MSP, walk through a realistic cyber incident together, out loud, before it’s real. Most teams don’t know where the handoffs between client and MSP break until they try to use them under pressure.
On this page
Why run a tabletop
Incident response plans are worth the paper they’re written on until you try to use them at 11pm on a Friday. A tabletop exercise surfaces the gaps while the stakes are still low: unclear decision rights between client and MSP, missing contact lists, assumptions on who calls whom that don’t survive first contact with a real crisis.
We run exercises that feel real, with your leadership and your MSP at the (virtual or physical) table. No script, no slideware, no gotchas, just both teams working a scenario under a facilitator’s pressure.
Scenarios we run
- Ransomware on core operational systems (with and without data exfiltration)
- Business email compromise and fraudulent wire transfer
- Third-party / SaaS provider outage or breach
- Insider threat — departing employee with access
- AI misuse or unauthorized data exposure through GenAI tools
- Non-profit-specific: donor data breach, grant-funded system compromise
How it works
Scope
We interview stakeholders and pick a scenario that matches your actual risk profile, not a generic template.
Design
Custom injects, realistic timelines, and decision points drawn from real incidents in your sector.
Facilitate
A 2–3 hour session with your leadership team, in person or virtual. We push, observe, and document.
Debrief
A hot wash immediately after, plus a written report with findings and prioritized remediation steps.
What you walk away with
A report with observed strengths, gaps and recommended fixes, mapped to your incident response plan. Plus a leadership team that has now actually been through the motions, together, before the real thing.
When did your team last rehearse a cyber incident?