What a real tabletop exercise looks like
A real tabletop isn't a slide deck and a read-through of the IR plan. It's a facilitated scenario with live injects - 'your CFO just got a call from a journalist asking about the breach' - that force decisions in real time across every function. Our facilitators come from incident response backgrounds and have run hundreds of these, so the pressure is realistic but the environment is safe.
Common scenarios include ransomware with extortion, business email compromise with wire fraud, third-party / supply-chain breach (think MOVEit, SolarWinds), insider data theft, regulator notification under HIPAA // GDPR / state breach laws, and major cloud-provider outage.
- Ransomware + double-extortion scenarios
- Business email compromise (BEC) + wire fraud
- Third-party / supply-chain breach
- Insider data exfiltration
- Cloud-provider or SaaS outage
- Regulatory breach notification drills

