The Value of Cybersecurity Tabletop Exercises

The Value of Cybersecurity Tabletop Exercises

Incident Response Plans Need Live Testing

Cybersecurity policies and incident response plans are mandatory for Australian Government agencies and critical infrastructure organisations. For regular organisations, insurers, business partners, and customers are increasingly viewing formal cybersecurity guidelines and incident response procedures as a shorthand for organisational reliability. Given the significant investment required to develop, implement, and maintain these instruments, organisations have a strong interest in ensuring they are effective and capable of supporting a coordinated response when faced with a cybersecurity incident. Tabletop exercises are a well stablished method to test and evaluate potential implementation gaps.

As defined by NIST (SP 800-84), tabletops are “discussion-based exercises where personnel meet in a classroom setting or in breakout groups to discuss their roles during an emergency and their responses to a particular emergency situation”. It is wort remembering that incident response plans are ultimately a set of assumptions. They reflect how an organisation expects its people, processes, and technologies would behave during a cybersecurity incident. However, until those assumptions are tested, there is no guarantee they will hold true under pressure.

The ability to identify gaps and highlight areas for improvement is one of the primary reasons tabletop exercises remain valuable. It can be argued that any live test that does not shed light on the limitations and improvement point of the process can hardly be considered a live test at all. With tabletops, organisations, and the individuals with responsibilities in them, are encouraged to test their preparedness in a controlled environment, experience the uncertainty and the unpleasantness of a cyber incident, and identify any weaknesses before a real incident does it for them. It is under live-like circumstances that roles which appear clearly assigned show overlapping responsibilities, established communication channels are missing key participants, escalation paths do not initiate as the information is incomplete, etc. . All these issues are often difficult to identify through policy reviews alone and only become visible when organisation members are required to apply processes under realistic conditions.

Experience Make Policies Meaningful

Whilst cybersecurity policies and written procedures are important, they are frequently consumed as documents rather than experienced as operational tools. Lack of practice makes diligent and experienced personnel to revert to instincts and previous experience, rather than recalling the policies and the incident response. Tabletop exercises address the implementation gap challenge by engaging the participants in simulations design to transform policies into actions. Participants are required to interpret information, assess options, communicate with stakeholders, and make decisions using the procedures available to them. Such simulations help the participants develop a practical understanding of their roles, responsibilities, decision-making authority and escalation pathways; elements that might otherwise remain abstract.

During the exercises, participants reinforce existing knowledge and connect established protocols with their own judgement in a context that is both meaningful and more memorable than a simple documentation review. As it is often the case,  experience often embeds learning more effectively than theory alone.

Responding to Uncertainty Is a Trainable Skill

One of the most challenging aspects of incident response is that important decisions frequently need to be made before all relevant information is available. Initial reports tend to be limited (e.g., missing the root cause, not accounting for all the users compromised, etc.) as security investigations take time, and the full scope of the incident almost always evolves with the emergence of new information. Well-designed tabletop exercises expose participants to some of this uncertainty in a controlled environment. They provide opportunities to experience the ambiguity and discomfort associated with incident response, without the potentially detrimental consequences of a genuine security event.

Being acquainted with uncertainty during cybersecurity incidents has practical value. Individuals who have previously navigated uncertain situations (simulated or otherwise) are often better prepared to make decisions, communicating risks and overall handling themselves and the processes better than people who are experiencing the lack of certainty for the first time.

Furthermore, even though cybersecurity incidents are often viewed as technical events, most of the response challenges are fundamentally organisational. Authority, accountability, collaboration, and decision-making are key in the effectiveness of the response to a cybersecurity incident. Tabletop exercises provide a unique space to address these questions, and the resulting governance discussions are among the most valuable outcomes of the exercise.

Not all Tabletops are Made Equal

The value of a tabletop exercise depends heavily on its design. Exercises that are overly scripted can encourage participants to identify the expected answer rather than work through the problem themselves. Conversely, exercises that pursue realism without restraint can become so complex that participants lose sight of the learning objectives.

The most effective exercises balance realism with practicality. They should be credible enough to create meaningful discussion while remaining structured enough to allow participants to experience a complete incident response cycle. Tabletop scenarios must also be appropriate for the organisation, since a routine phishing campaign is unlikely to justify a fully-fledged incident response, while the scenario of facing a highly sophisticated nation-state is beyond the realistic expectations for most organisations. It is paramount that the situations being simulated generate organisation-specific useful discussion and realistic decision-making.

Tabletops must be performed with support from expert and trustworthy practitioners who understand the organisation’s context, policies and know how to tailor the exercise accordingly. Off-the-shelf or poorly designed tabletop exercises can be highly counterproductive as they consume valuable time from leadership and technical teams and are likely to generate conflicts without providing a constructive resolution outlet. These unhelpful conflicts can even extend to operational staff and external stakeholders in unnecessarily complex. Without appropriate design and facilitation, tabletop exercises can reinforce incorrect assumptions, undermine participants’ confidence in the process, and make effective collaboration more difficult during a real cybersecurity incident.

Well-practiced incident response plans give organisations a fighting chance against cybersecurity incidents, as preparedness only emerges when people, processes, governance structures, and communication channels are used under in realistic incident conditions. Tabletop exercises, supported by leadership and facilitated by the right team, help organisations bridge the gap between planning for an incident and responding effectively in practice.

Ready to get started?

Find out how RightSec can help your organisation enhance
their cyber security resilience.

Mugshot of Ivan Minguez

Ivan Minguez - Author

GRC & SOC Enablement Specialist

Cyber Security Services

Illustration of a hacker device, representing cyber threats and the importance of cybersecurity defense mechanisms.

Cyber Strategy and Consulting

Expert guidance on how to safeguard your organisations valuable assets and reputation.

Icon representing domain registration, highlighting the importance of securing digital assets and online presence in cybersecurity.

Managed Security Services

RightSec's 24/7 managed security services will give your business the visibility and coverage needed.

Target icon symbolizing cybersecurity risk management and the identification of vulnerabilities in digital systems.

Penetration Testing and Red Teaming

Identify security weaknesses and take proactive measures to improve your security posture.

Cybersecurity flyer with key service offerings, promoting RightSec’s expertise in protecting businesses from digital threats and vulnerabilities.

Governance, Risk and Compliance

Assess your organisation's resources and validate the adequacy of your capabilities to manage Cyber Risk.

Startup icon symbolizing innovative cybersecurity solutions designed to protect new and growing businesses from digital threats.

Digital Forensics and Incident Response

RightSec’s IR team is available round the clock to provide immediate assistance to on-going incidents.

Business icon in black, representing professional cybersecurity services tailored to protect business operations and digital assets.

Team Augmentation

Augment your team with RightSec Cyber Security experts, to meet the growing demand of Cyber Security.

Small & Medium Business

Today’s threat actors know that small and medium businesses often have valuable data, trusted customer relationships, and fewer dedicated cyber security resources.

Customer-centricity icon illustrating a focus on client needs and personalized cybersecurity solutions to ensure business protection and success.

Auditing and Gap Analysis

We will help you evaluate your existing security controls and identify any vulnerabilities that may exist.

Reliability icon representing dependable cybersecurity services that ensure consistent protection and secure operations for businesses.

Security Awareness and Training

Our methodology leverages decades of experience in identifying and analysing threats, tailoring campaigns to educate stakeholders and users on threats an organisation may be facing.