Most Tabletop Exercises Are Theater. Here’s How to Tell, and What to Do Instead

    July 28, 20265 min read
    Most Tabletop Exercises Are Theater. Here’s How to Tell, and What to Do Instead

    Ask most security teams whether they run tabletop exercises, and the answer is usually yes. Ask what actually happened during the last one, and the answer gets a lot less confident. Somewhere between “we’re required to do this” and “this actually tests anything,” a lot of tabletop exercises quietly become theater, a scheduled meeting that satisfies a compliance checkbox without ever genuinely stress-testing how the organization would respond to a real incident.

    That gap matters more than it gets credit for, because a tabletop exercise is often the only place an organization discovers a real gap in its incident response plan before an actual incident forces the discovery instead.

    Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.

    What a Real Tabletop Exercise Is Supposed to Do

    A tabletop exercise walks a group of stakeholders through a simulated incident scenario, in real time, forcing them to make the same decisions they’d have to make during an actual event. Who gets notified, in what order. Who has the authority to take a system offline. What gets communicated externally, and who approves that language. Where the gaps are in a plan that looks complete on paper.

    Done well, this surfaces exactly the kind of problem that’s invisible until the pressure is real: two departments who both assumed the other one owned a decision, a communication plan that names someone who left the company eight months ago, an assumption that a specific system could be isolated quickly that turns out to be technically much harder than anyone realized.

    How Tabletop Exercises Quietly Become Theater

    The scenario is too easy. A tabletop that walks through a textbook phishing email gets clicked, credentials get reset, incident closed, doesn’t test anything meaningful. Real incidents are messy, ambiguous, and often involve conflicting information in the first hour. A scenario that resolves cleanly in thirty minutes isn’t stress-testing the plan, it’s performing confidence in it.

    The same people run it every time, and know the answers. If the incident response lead has run the exercise for three years straight, they already know exactly how it’s supposed to unfold, and often unconsciously steer the room toward the expected outcome rather than letting the scenario genuinely surprise anyone.

    Nobody plays a skeptic or an obstacle. Real incidents involve friction, a legal team that’s cautious about public statements, an executive who wants to downplay severity, a vendor who’s slow to respond. A tabletop with no one pushing back or complicating the scenario tests the happy path, not the actual conditions an incident creates.

    The findings don’t go anywhere. This is the most common failure. The exercise happens, a few gaps get identified, someone writes them down, and then the same gaps show up unaddressed in next year’s exercise. A tabletop that doesn’t feed real changes back into the incident response plan is documentation of a problem, not a fix for it.

    It only ever tests the technical team. A genuinely useful tabletop pulls in legal, communications, HR, and often an executive sponsor, since a real incident touches all of them. An exercise limited to the security team alone is testing only one piece of what actually happens during a real event.

    What Actually Makes a Tabletop Exercise Useful

    Build the scenario around ambiguity, not certainty. The best exercises start with incomplete, sometimes contradictory information, exactly like a real incident does, and force the room to make a decision without knowing everything yet.

    Rotate who facilitates, and bring in someone unfamiliar with the plan’s specifics to play devil’s advocate. A facilitator who doesn’t already know the intended outcome asks harder, more genuine questions.

    Include the non-technical stakeholders every time, not as an occasional special session. Legal, communications, and an executive sponsor should be default participants, not a once-a-year addition.

    Track findings the same way a real incident’s post-mortem gets tracked, with an owner and a deadline, and open the next exercise by reviewing whether last time’s findings actually got fixed. If the answer is consistently no, that’s a more important finding than anything the new scenario surfaces.

    Vary the scenario type meaningfully year over year. A ransomware scenario tests different decisions than a third-party vendor breach, which tests different decisions than an insider threat scenario. Running the same basic scenario with minor variations year after year eventually just tests how well the room remembers last year’s answers.

    Why This Is Worth Taking Seriously

    A tabletop exercise costs a few hours and some coordination. A real incident, discovered to have the exact same gap a tabletop would have surfaced months earlier, costs considerably more, in response time, in damage, and often in the exact regulatory and disclosure exposure that makes incident response leadership a genuinely high-stakes job right now.

    The organizations that treat tabletop exercises as a real diagnostic tool, uncomfortable questions included, tend to be the ones that respond to a real incident with something resembling composure. The ones running theater find out the difference at the worst possible time.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify