19.6 Interactive Tabletop Exercises and Scenarios
What a Tabletop Actually Trains
A tabletop exercise (TTX) is a discussion-based walkthrough of a fictional incident run against your real playbook, in a room or on a call, with no production system touched. In real incidents, technical muscle is rarely the first thing to fail — coordination is: unclear decision authority, communications channels that evaporate under stress, legal unsure what evidence to ask for before it is gone. The tabletop exists to surface exactly those failures while the cost of failing is zero.
Cast, Cards, and Injects
The structure is small and fixed. One facilitator drives the scenario from a prepared script and never answers "what should we do?" — solving the incident for the players defeats the exercise. A scribe records decisions and gaps. Role-players sit in their real seats: incident commander, technical/IR lead, comms, legal, executive sponsor. The scenario card sets the premise; injects are escalating fact cards dropped every fifteen to twenty minutes: "two more servers encrypted," "the backup repository is unreachable," "a journalist emails about leaked records," "the IR team's laptops are in the encrypted batch." Good injects break assumptions the team has quietly baked in — including that backups always work. Time compresses verbally: "three hours have passed."
The Hot Wash
As soon as the exercise ends — before people debrief themselves out of their excuses — run the hot wash, the immediate after-action review: what worked, what broke, who actually decided what, and where the playbook went silent. The scribe's list becomes the gap list that feeds the post-incident improvement loop from 19.5. Keep it no-fault; participants who feel humiliated in the exercise stop volunteering for the next one.
Scenarios That Hurt Less Than Reality
Rotate the scenario year to year: an enterprise ransomware outbreak, an acute session-token theft demanding mass SSO session invalidation, insider exfiltration, or a SaaS vendor compromise. Start small — sixty to ninety minutes, one department — before scaling to a full multi-team run. Avoid scenarios whose only correct answer is "escalate"; pick ones that force decisions on incomplete information, because that is the skill being paid for.
Architecture Diagram
Key Takeaways
- Tabletops train coordination and decision authority, not keyboard mechanics — keep hands off production systems.
- Fixed cast: a facilitator who injects pressure but never solves, a scribe, and role-players in real seats.
- Injects land every fifteen to twenty minutes, and the best ones break a comforting assumption like "backups always work."
- The hot-wash AAR happens immediately; its gap list flows straight into runbook updates and the next exercise.
- Rotate scenarios — ransomware, token theft, insider, vendor compromise — and grow duration and scope gradually.