
- 01A tabletop that produces a slide deck and a feel-good summary has not earned its time. The version that changes things treats the exercise as a real incident, captures every gap, and tracks each gap to closure.
- 02Structural elements: realistic scenario based on a credible threat to your environment, time pressure (real-time injects, not paused discussion), multidisciplinary participants (security, IT, legal, comms, executive), note-taker capturing decisions/gaps/questions, structured debrief immediately at the end, tracked remediation with named owners and dates, re-run the same scenario in 90 days.
- 03Injects that work: ambiguity early ('it might be ransomware, the team is not sure'), regulatory pressure mid-exercise ('the EU regulator wants 24-hour notification'), customer-facing question ('a journalist is asking; what do we say?'). Each forces decisions that pure technical scenarios skip.
- 04What the second run reveals: same gaps appearing means the program has not learned; new gaps appearing because the team can see further means the program is maturing. The delta between runs is the most honest measure of preparedness improvement.
A tabletop exercise that produces a slide deck and a feel-good summary has not earned its time. The version that changes things treats the exercise as a real incident, captures every gap, and tracks each gap to closure.
Structural elements
- 01Realistic scenario based on a credible threat to your environment
- 02Time pressure — real-time injects, not paused discussion
- 03Multidisciplinary participants — security, IT, legal, comms, executive
- 04Note-taker capturing decisions, gaps, and questions
- 05Structured debrief immediately at the end
- 06Tracked remediation with named owners and dates
- 07Re-run the same scenario in 90 days to verify improvement
The injects that work
Inject ambiguity early ('it might be ransomware, the team is not sure'). Inject regulatory pressure mid-exercise ('the EU regulator has heard about this and wants a 24-hour notification'). Inject a customer-facing question ('a journalist is asking; what do we say?'). Each forces decisions that pure technical scenarios skip.
What the second run reveals
If the same gaps appear in the re-run, the program has not learned. If new gaps appear because the team can now see further into the response, the program is maturing. Use the delta between runs as the most honest measure of preparedness improvement.


