A useful tabletop reveals where people pause, disagree, lack access, or depend on an unavailable system. Record those points as evidence and turn them into assigned corrective actions.
1. Set three useful objectives
Keep the session narrow enough to finish in 60 to 90 minutes. Choose objectives that can be observed during discussion rather than broad goals such as test cybersecurity.
For a first exercise, test whether the organization can recognize a material event, contain affected systems without losing decision authority, and begin recovery in business-priority order.
- Confirm who may isolate a device, disable an account, or shut down a system
- Test how leadership, IT, the MSP, insurance, legal, and communications contacts are reached
- Verify which business services must return first and who approves restoration
- Identify the evidence needed after the exercise to close each gap
2. Invite the people who own consequences
The session should include the roles that would make or support real decisions. A purely technical group cannot test business priorities, customer communication, insurance notification, or operational workarounds.
- Executive or business incident owner
- Internal IT and the managed service provider
- Operations leader for the affected workflow
- Communications, legal, privacy, or human resources as applicable
- Insurance broker or response contact when the policy and relationship allow
- A facilitator and a separate note taker
3. Prepare a believable scenario
Use a scenario close enough to the environment that participants can reason about actual systems and responsibilities. Do not include live credentials, sensitive logs, real employee data, or information that would turn the exercise document into a security risk.
Start with an ordinary sign of trouble, then add consequences in stages. Give the team time to state what it knows, what it assumes, who decides, and what action comes next.
Stage one: detection
A user reports inaccessible files and an endpoint alert appears on a remote laptop. Ask who validates the report, what is isolated, and how the business owner is notified.
Stage two: expansion
Shared files and a second device show suspicious activity. Email reliability is uncertain. Ask how the team coordinates out of band and who has containment authority.
Stage three: consequence
A critical business process is unavailable and a customer asks for an update. Ask who sets recovery priority, contacts insurance, preserves evidence, and approves external communication.
Stage four: recovery
The affected environment is contained. Ask which restore point is trusted, where restoration occurs, how access is validated, and what evidence supports returning the system to operation.
4. Ask decision questions
- What fact would make this event material, and who makes that determination?
- Which actions may IT or a provider take immediately, and which require approval?
- If company email is unavailable or monitored, what communication path remains?
- Which systems can be disconnected without creating a greater operational or safety consequence?
- Who contacts the insurer, counsel, law enforcement, customers, employees, or regulators when applicable?
- What must be true before restored systems reconnect?
- What evidence and timeline will be documented after the event?
5. Capture evidence while the discussion is fresh
The output is not a pass or fail score. It is a short record of decisions that worked, assumptions that need validation, unavailable information, unclear authority, and dependencies that could slow response or recovery.
- Decision or gap stated in plain language
- Business consequence if it remains unresolved
- Named owner—not a department
- Specific next action and due date
- Evidence that will demonstrate completion
- Date for a focused retest
6. Keep the boundaries clear
A tabletop is educational and directional. It does not prove that controls will operate during a real incident, replace technical testing, certify compliance, interpret insurance coverage, or provide legal advice.
Follow the exercise with targeted validation: test contact paths, verify endpoint isolation authority, restore representative data, review insurance requirements with qualified advisers, and confirm the response plan reflects what participants actually decided.
Official guidance reviewed
Tallgrass reviewed the following primary guidance while preparing this operational resource. Use the source publications for their full scope and limitations.
- #StopRansomware Guide — Cybersecurity and Infrastructure Security Agency
- Cybersecurity Scenarios and Tabletop Exercise Packages — Cybersecurity and Infrastructure Security Agency
- Ransomware Risk Management: A CSF 2.0 Community Profile — National Institute of Standards and Technology