SOC

Tabletop Exercise

A tabletop exercise simulates a security incident to test roles, decisions, and communication in a real emergency.

A tabletop exercise is a discussion-based session where a team talks through a simulated security incident. It tests procedures, decision-making, and communication without affecting live systems.

How it works

A facilitator presents a scenario, such as a ransomware attack on a Friday evening. New information is introduced in several rounds. For example, servers are encrypted or data is offered on the darknet. Media outlets might also make enquiries. Participants decide on their actions and who is responsible for each step. Gaps and improvements are documented at the end.

For example, a management exercise reveals that nobody knows the cyber insurance provider's phone number. It is also unclear who decides on reporting an incident to the authorities. Both points are then added to the incident response plan. The next exercise a year later runs much more smoothly.

What to look out for

  • Choose a scenario that is realistic for your organisation.
  • Involve management, communications, legal, and HR, not just IT.
  • Limit the exercise to between two and four hours.
  • Document findings with clear owners and deadlines.
  • Repeat the exercise regularly, at least once a year.

Variants

Technical tabletop exercises are aimed at IT and the SOC. They go deeper into analysis and containment. Management exercises focus on decisions, communication, and business continuity. Both forms of exercise complement each other.

Switzerland and regulation

FINMA (Swiss Financial Market Supervisory Authority) expects financial institutions to test their resilience regularly. This includes testing against severe cyber scenarios. Tabletop exercises are a recognised method for this purpose. Annex A of ISO 27001 also requires plans for incidents and disruptions to be tested.

Typical mistakes

Scenarios are often made too easy so that the exercise runs smoothly. This means important gaps can remain hidden. A second common mistake is documenting findings without implementing them.

How we implement it

Findings from exercises are incorporated into the SOC's Detection Engineering.

How ANOMAL implements this