Section outline
-
-
If you’ve ever sat down with a group of friends to play a board game, you understand the appeal of a tabletop exercise. For a few hours, you can focus on the gameplay in front of you, entirely absorbed in the world you’ve created.
A tabletop exercise is a lot like a board game among friends, except it takes place in the real world, includes your colleagues, and helps your organization stay safe. While tabletop exercises can take many different forms, they are all intended to provide a dedicated time and place where your team can explore how you would respond to a real-life risk facing your organization.
In this guide, we’ll walk you through how to set up an effective tabletop exercise in 8 key steps.
1. Determine what you would like to test.
Tabletop exercises provide your organization with a safe, non-judgmental space to think through your security posture. Running an exercise can help you proactively identify what's working and what's falling short in your current approach. But a single tabletop exercise can't encompass every risk your organization might face.
That's why, to get started, you'll need to determine exactly what you want to test. Be specific. For example, testing the security processes around your website is too broad for an effective tabletop exercise. Instead, you may want to consider testing how your organization responds if bad actors try to access your content management system.
Not sure what to test? Take a look at your security policy first. Are there areas of the policy that feel confusing, unclear, or outdated? Try testing those areas. Don’t have a security policy yet? You may have an incident or crisis response plan that you can test instead.
If you don’t have either of those documents, consider creating a risk matrix. With just a few questions, you can roughly measure the risks you face. Here's a simple risk matrix you can use to get started:
-
What risk has a low likelihood of occurring and a low consequence if it does occur?
-
What risk has a high likelihood of occurring and a low consequence if it does occur?
-
What risk has a high likelihood of occurring and a high consequence if it does occur?
-
What risk has a low likelihood of occurring and a high consequence if it does occur?
As you can see, you may want to prioritize testing your response to risks with a high consequence and a high likelihood. These are the challenges that your organization could realistically face in the near future and that your security program should focus on.
2. Designate a group leader to run the exercise.
If you’ve ever played a board game before, you know that gameplay always runs smoother when you have someone who knows the rules. The same is true of a tabletop exercise. You’ll want to designate a group leader to help facilitate the exercise.
The designated leader doesn’t need to be the most experienced member of your organization, nor do they need to know the most about cybersecurity. Instead, they should be able to carefully manage the group’s time, conversation flow, and interest level. If they notice some participants are disengaged, the leader should be able to steer them back into the conversation. On the other hand, if they notice that some participants are becoming heated, they should be able to lower the temperature of the conversation.
Other responsibilities of the group leader include narrating the storyline (discussed below) and designating a notetaker to help the group document the key lessons learned in the exercise.
3. Create a plausible storyline that includes the threat you want to handle.
What differentiates a tabletop exercise from a regular discussion is the use of a storyline that creates a realistic scenario for your team to explore. This ensures that your team fully walks through each step of their response.
How can you come up with storyline ideas? Here are a few techniques:
Identify weak points in your policies. There are likely areas in your existing security policies that feel vague or difficult to enforce in real life. You may want to explore ways to improve these areas through a tabletop exercise scenario.
Generate ideas from real life experience. If your organization has faced a cyberthreat in the past, you may want to create a fictionalized version to discuss.
Talk to colleagues at other organizations about what they have experienced. Other organizations in your field have probably gone through cybersecurity challenges. Ask if you can use an anonymized version of their experience in your exercise.
Use an online source. Can’t think of a storyline that fits your organization? Try an online resource like @badthingsdaily on Twitter or this guide from MITRE Corp.
Once you have a few storylines in mind, you can work with your team to determine which scenario gets picked.
4. Gather the staff that would be responsible for managing this threat, plus observers.
Ideally, you will want a diverse group of participants seated at the table (physical or virtual) for this tabletop exercise. Why should the exercise go beyond members of your IT or cybersecurity teams? The reality is that a potential cybersecurity risk will affect every aspect of your organization, not just your digital systems. It's important that members of your various teams—from communications to finance to operations to executive leadership—weigh in on their response, too.
In addition to the stakeholders at the table, you'll want to ask several observers to join, also. These team members will watch as the tabletop exercise takes place but will not participate. They can take notes and document the experience, focusing on key areas for discussion later.
5. State the goal of the exercise at the beginning.
Why are you running a tabletop exercise in the first place? It's important to answer this question with a response that fits your organization's risks and needs.
For example, you may be publishing a high-profile report in the coming months and are concerned about adversaries harassing your staff on social media. The goal of the exercise, then, would be to strengthen your response to online harassment as an organization.
It's also important to highlight that tabletop exercises should always deal with the reality of the situation as it stands currently. So, while you may wish that you have a robust social media monitoring system in place, you need to discuss what is most likely to happen given your current posture. This allows both participants and observers to clearly see existing gaps and determine ways to strengthen weak points.
Last, you should set the expectations for the exercise. Typically these exercises should last about 2-3 hours, including discussion, and can be led virtually or in-person.
6. Walk the staff through the scenario and ask for their responses, step by step.
There are many different ways to run tabletop exercises, from informal roundtable discussions to highly structured turn-based scenarios.
For most organizations running their first tabletop exercise, it's best to keep things simple. One variation you can use is to ask the representatives from different parts of the organization to take turns responding to the storyline prompt.
For example, in the case of a data breach, representatives from IT may respond first, followed by communications, followed by finance. Each person will play a different but no less critical role in the response.
This is why it's critical to keep tabletop exercises as neutral and non-judgmental as possible. These are intended to be learning experiences, not opportunities for criticism. There may even be moments when a team member from one department spots room for improvement in the process used by another department. Do your best to welcome those insights.
7. Document gaps, concerns, and weak points in the threat response.
One of the most important outcomes of any tabletop exercise is a list of areas that need improvement. No organization, no matter how robust their security policies, is without opportunities for growth. If you are running an effective tabletop exercise, you should come away with a list of troublesome areas to address.
A tabletop exercise is intended to test your organization's response to an unknown, harmful, or malicious event. This may be something unintentional, such as a staff member losing a work device, or something targeted, such as a bad actor breaking into your offices. Either way, keep an open mind and thoroughly document the results of the exercise.
8. Use the knowledge you've gained from the tabletop exercise to identify areas of concern and develop strategies to reduce those risks.
Once you’ve concluded the exercise, make time for a collaborative discussion about the areas of concern you identified during the meeting. Don’t skip the discussion session. If your team is exhausted after the exercise, reconvene a day later.
The discussion session should be focused on two different goals: identify the key areas of concern (at least your top five) and then begin to develop strategies to address those concerns. Note that you won’t be able to develop a comprehensive strategy for all these challenges in a single discussion. But make sure to document your insights while they are fresh from the exercise itself (ideally no more than 24 hours later). Some questions you may want to address in the discussion include:
-
What surprised us during the exercise?
-
What did not surprise us?
-
Where did we get lucky?
-
What areas of our organization are strongest?
-
What areas are weakest?
-
Are we allocating resources to the appropriate places?
-
Do our security policies accurately reflect the risks we face?
After you have had your discussion, it’s important to take steps to put your findings into practice. Consider checking in with your participants to review your discussion findings, convert them into action items, and decide on next steps. This will ensure that the valuable lessons learned during the exercise do not fall through the cracks.
The team leader should ensure that all vulnerabilities identified during the exercise lead to solutions. For example, if, during the exercise, you identify that your organization has no clear documentation on how to restore your data from a backup, the team leader should ensure that there are clear next steps on how to create that documentation.
Tabletop exercises should be engaging, interactive, and perhaps a little bit fun. While they do require a commitment of time and resources, the insights they offer are well worth the effort.
-
-