Skip to main content

Tabletop Exercises: Running One With a Non-Technical Team

Media Tabletop Exercises Running One With a Non-Technical Team

A cyber incident does not affect only the IT department.

When a mailbox is compromised, somebody may need to contact customers. If ransomware stops operations, managers must decide which services to prioritise. When fraudulent payment instructions are sent, finance may need to call the bank before the technical investigation is complete.

A tabletop exercise helps your team practise those decisions without causing a real outage.

It is a discussion-based exercise in which participants work through a realistic incident scenario, explain what they would do and identify gaps in the organisation’s response plan. No systems need to be switched off, and nobody needs advanced technical knowledge. NIST describes tabletop exercises as facilitated discussions used to validate plans, responsibilities and responses to an emergency scenario. 

For a non-technical team, the goal is not to test who understands cybersecurity terminology. It is to discover whether people can communicate, make decisions and protect the business under pressure.

What Is a Cybersecurity Tabletop Exercise?

A tabletop exercise is essentially a guided conversation around an unfolding cyber incident.

A facilitator presents a scenario in stages. After each update, participants discuss questions such as:

  • What do we know?
  • Who takes control?
  • What should happen immediately?
  • Who needs to be contacted?
  • What information is missing?
  • Which decisions require senior approval?

Unlike a live simulation, participants do not normally perform technical actions against real systems. The emphasis is on roles, decisions, escalation, communication and coordination. The UK National Cyber Security Centre distinguishes tabletop exercises from live-play exercises, where participants carry out simulated duties more actively and often in real time. 

This makes tabletop exercises particularly suitable for small businesses and non-technical teams.

Why Include Non-Technical Employees?

Cyber incidents quickly become business incidents.

A technical team may be able to disable an account or isolate a laptop, but it cannot make every decision alone.

A realistic exercise may require input from:

  • Senior management
  • Finance
  • Human resources
  • Operations
  • Communications
  • Legal or data protection
  • Customer service
  • External IT support

The NCSC recommends involving senior leaders and considering participation by partners or service providers, particularly when an incident may involve a supplier. 

Including non-technical employees helps test whether the organisation can answer practical questions:

  • Who contacts the bank?
  • Who approves shutting down a business system?
  • Who speaks to customers?
  • Who checks contractual notification requirements?
  • Who decides when normal operations can resume?
  • What happens when the usual decision-maker is unavailable?

These are not technical questions. They are operational ones.

Choose One Clear Objective

Do not attempt to test the company’s entire cybersecurity programme in one meeting.

Choose one or two specific objectives.

For example:

  • Test how quickly the business can respond to a compromised Microsoft 365 account.
  • Confirm who has authority to stop a suspicious payment.
  • Check whether emergency contact information is accurate.
  • Test communication during a ransomware outage.
  • Confirm how a lost company device would be handled.
  • Review the response to a compromised supplier.

CISA’s tabletop exercise packages use defined objectives, scenarios and discussion questions to keep exercises structured and focused. 

A clear objective also makes the final review more useful. You can measure whether the exercise answered the intended question rather than concluding vaguely that everyone “had a useful discussion.”

Select a Scenario People Can Understand

The scenario should be realistic for your organisation.

Good starting scenarios include:

  • A finance employee’s mailbox is compromised.
  • A director’s account sends fraudulent payment instructions.
  • Ransomware makes shared files unavailable.
  • An employee loses a company mobile phone.
  • Sensitive customer information is accidentally shared publicly.
  • A critical software supplier reports a breach.
  • A member of staff approves an unexpected MFA request.

The NCSC’s free Exercise in a Box service includes scenarios involving ransomware, stolen mobile phones, insider threats, remote working, supply-chain compromise and threatened data leaks. 

Avoid starting with an extremely complicated nation-state attack involving ten technical systems. A familiar scenario creates better discussion and gives less-confident participants room to contribute.

Keep the Exercise Short

For a first tabletop exercise, aim for approximately 60 to 90 minutes.

That is long enough to introduce the scenario, explore several decisions and agree on improvements without losing the room’s attention. The NCSC’s ransomware tabletop, for example, recommends allowing 60 to 90 minutes, while some smaller scenarios can be completed in 30 to 60 minutes. 

A simple structure is:

Time

Activity

10 minutes

Introduction and ground rules

40–50 minutes

Scenario discussion

15 minutes

Debrief

10 minutes

Agree actions and owners

Do not turn the exercise into a half-day presentation. The participants should do most of the talking.

Choose the Right Participants

A small exercise may need only six to ten people.

A practical group could include:

  • A senior decision-maker
  • An IT representative or provider
  • A finance representative
  • An operations or service-delivery manager
  • HR or communications
  • A note-taker
  • The facilitator

The NCSC suggests involving a senior leader, a cybersecurity or technical representative and potentially HR or communications, depending on the scenario. It also recommends assigning a facilitator to prepare, run and report on the exercise. 

Invite people because they would have a role during the incident—not because they hold the most senior job title.

Too many observers can make the discussion slow and formal. Keep the core group small enough that everyone participates.

Use a Neutral Facilitator

The facilitator controls the pace but should not dominate the answers.

Their job is to:

  • Introduce the scenario
  • Present new developments
  • Ask follow-up questions
  • Keep the discussion on track
  • Prevent one person from taking over
  • Note unresolved issues
  • Maintain a constructive atmosphere

The facilitator does not need to be the most technical person in the room. In fact, a facilitator who asks simple questions can help prevent the discussion from disappearing into jargon.

They should avoid correcting every imperfect answer immediately. Let the team explain its assumptions. Those assumptions are often where the most valuable gaps appear.

Explain That It Is Not a Test of Individuals

Some employees become nervous when they hear the word “exercise.”

Begin by explaining:

  • Nobody is being graded.
  • The scenario is fictional.
  • It is acceptable not to know an answer.
  • Finding a gap is a successful result.
  • The purpose is to improve the plan, not expose mistakes.

A tabletop exercise should create useful honesty.

When someone says, “I do not know who has the bank’s emergency fraud number,” you have discovered an actionable weakness before a real fraud occurs.

That is far more valuable than participants pretending the answer exists somewhere.

Build the Scenario in Stages

Do not reveal the entire incident at once.

Present it through a series of short updates, sometimes called injects.

Stage 1: The Initial Report

At 9:10 a.m., the finance manager receives calls from two suppliers. They have received messages from her genuine company mailbox requesting that future payments be sent to a new bank account.

Ask:

  • What is the first action?
  • Who needs to be told?
  • Should the account be blocked immediately?
  • How will the user be contacted safely?

Stage 2: The Situation Develops

Microsoft Entra sign-in logs show an unfamiliar successful sign-in overnight. An automatic external forwarding rule is discovered in the mailbox.

Ask:

  • What should IT preserve before removing it?
  • Could other accounts be affected?
  • Who decides whether customers must be warned?
  • Which communication channel is safe?

Stage 3: Business Impact Appears

One supplier has already sent a payment to the fraudulent account. The managing director is travelling and cannot be reached.

Ask:

  • Who contacts the bank?
  • Who has authority to make urgent decisions?
  • Does cyber insurance need to be notified?
  • Who records the timeline?

This staged format creates discussion without requiring participants to interpret a long technical briefing.

Ask Business Questions, Not Security-Trivia Questions

Avoid questions such as:

Which Microsoft Graph permission would the attacker require?

That may be relevant to the technical investigation, but it will exclude most of the room.

Instead ask:

  • What service is most important to protect?
  • What information would customers need?
  • How long can the business operate without this system?
  • Who can authorise emergency spending?
  • Which supplier contacts are stored outside Microsoft 365?
  • What happens if the normal incident lead is unavailable?
  • Which decisions should be documented?
  • When would legal advice be required?

The exercise should test the organisation, not the participants’ vocabulary.

Add Realistic Pressure Without Creating Chaos

A useful scenario should become gradually more difficult.

You might introduce:

  • A journalist requesting a comment
  • A customer threatening to leave
  • An unavailable manager
  • A supplier outage
  • Conflicting technical information
  • Social-media posts about the incident
  • A cyber-insurance notification deadline
  • A second employee reporting suspicious activity

Do not add twists merely for drama. Every development should help test one of the exercise objectives.

The aim is to create thoughtful pressure, not make the exercise feel like a competition.

Record Decisions and Gaps

Assign a dedicated note-taker.

They should capture:

  • Decisions made
  • Unanswered questions
  • Conflicting responsibilities
  • Missing contact details
  • Required technical improvements
  • Policy or approval gaps
  • Actions that took too long
  • Assumptions that need verification

CISA provides exercise resources including participant feedback forms and after-action report templates, which can help organisations structure the review and improvement process. 

Do not try to produce a perfect transcript. Focus on findings that should change the organisation’s plan.

Finish With an Honest Debrief

At the end, ask each participant:

  • What worked?
  • What caused confusion?
  • Which decision took too long?
  • What information was missing?
  • What should be changed before the next exercise?
  • What surprised you?

Keep the conversation constructive.

You may discover that:

  • Nobody knows who can contact the cyber insurer.
  • The bank fraud number is stored only in one person’s email.
  • The incident plan does not name a backup lead.
  • Customer communications require too many approvals.
  • IT cannot access logs for long enough.
  • Nobody is sure who owns a critical supplier relationship.

These are excellent results because they give you specific improvements to make.

Turn Findings Into Assigned Actions

An exercise is wasted if the notes are filed away and forgotten.

Create a short improvement list containing:

Action

Owner

Deadline

Update emergency contact sheet

Operations Manager

14 days

Create mailbox-compromise checklist

IT Provider

30 days

Confirm cyber-insurance reporting process

Finance Director

14 days

Store bank fraud contacts offline

Finance Manager

7 days

Nominate backup incident lead

Managing Director

14 days

NIST includes incident-response exercises and after-action planning among its recommended preparation resources. 

Review the actions at the next management or security meeting until they are complete.

How Often Should You Run a Tabletop Exercise?

For most small businesses, running at least one meaningful exercise each year is a sensible baseline.

Higher-risk organisations may benefit from shorter exercises every six months, particularly when:

  • Staff change frequently
  • New systems are introduced
  • The incident plan has been revised
  • A significant supplier changes
  • The business handles sensitive or regulated information
  • A real incident has recently occurred

The NCSC recommends regular tabletop exercises and simulations to test communication and response strategies and identify improvements. 

Use a different scenario each time, but revisit important weaknesses to confirm they were fixed.

Common Tabletop Exercise Mistakes

Making It Too Technical

Non-technical participants stop contributing and leave the response to IT.

Creating an Unrealistic Scenario

The team spends the exercise debating whether the incident could happen rather than discussing its response.

Inviting Too Many People

The session becomes a presentation rather than a conversation.

Letting the Most Senior Person Answer Everything

Other participants remain quiet, and real uncertainty stays hidden.

Trying to Catch People Out

Participants become defensive and avoid admitting what they do not know.

Producing No Improvement Plan

The organisation identifies the same gaps again at the next exercise.

Final Thoughts

A tabletop exercise does not need specialist software, a large budget or a room full of cybersecurity experts.

It needs:

  • A realistic scenario
  • A clear objective
  • The right people
  • A neutral facilitator
  • Structured questions
  • An honest review
  • Assigned follow-up actions

Keep the first exercise simple. Give non-technical employees permission to focus on customers, communications, payments, people and business continuity.

The purpose is not to prove that your incident response plan is perfect.

It is to discover what will fail while there is still time to fix it.

Need Help Running a Cybersecurity Tabletop Exercise?

Hamilton Group can help your organisation plan and facilitate a practical exercise that includes both technical and non-technical teams.

Our experts can help you:

  • Select a realistic cyber incident scenario
  • Define clear exercise objectives
  • Create staged scenario updates
  • Facilitate the discussion
  • Test Microsoft 365 incident procedures
  • Review communications and escalation
  • Identify missing contacts and responsibilities
  • Produce an improvement plan
  • Update your incident response documentation
  • Run follow-up exercises

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to test your response before a real incident puts it under pressure.