Tabletop: the committee faces the incident before it is real

We do not train employees. We facilitate a table exercise in which the board and the committee find what is missing in the response plan. The buyer is the CISO who needs the board in the room.

How it works

How we facilitate a table that actually decides

A scenario for that committee

We write the incident with the industry, the systems and the role names — not personal names, if legal asks — that the plan already uses. A generic scenario does not surface useful gaps.

Room and participants

We convene whoever the plan names: board, legal, communications, operations, CISO. If a role is missing, the exercise logs it as a gap; one of our actors does not replace it.

Facilitation

Run the clock, inject turns, keep IT from monopolizing. The facilitator does not “win”. They make the committee decide and keep the decisions written down.

Gap minutes

We return what was missing in the plan, who should own it and what can be shown to compliance. There is no score of “the board failed”.

Why it matters

Why the CISO cannot rehearse the board with an LMS

Because the board does not take a phishing course and because a response plan is not proven by attendance. It is proven when someone has to decide in twenty minutes whether to pay, to cut, to report. That muscle is not trained in the…

Why the CISO cannot rehearse the board with an LMS
Deliverables

What you get

Governance evidence in front of an incident, written for the committee and for compliance, not for the roster.

Signed scenario

Incident, roles and table rules, aligned to the existing plan. Legal can strip proper names. The scenario is not recirculated as awareness content.

Facilitated session

Hours at the table with the real committee. One facilitator, one clock, injections. It is not a webinar and not an all-hands talk.

Decision and gap minutes

What was decided, what could not be decided, which role was missing. Plan language, not campaign language.

Bridge to compliance

What can be filed as a rehearsal of the plan and what remains as a task. An explicit link to compliance resources, not to the phishing builder.

Requirements and timelines

What we need from you

  • That the CISO — or the buyer — can sit the committee. Without the board, or without someone who represents it with a mandate, the exercise degrades into an IT workshop and we do…
  • Also a real agenda: a slot when those people are available, not a “whenever”. Communications and legal must know a simulated incident with system names will be discussed. This…
The program

How it fits compliance and the program

The tabletop does not feed the click index. It feeds the plan. The awareness program stays on the platform; this session is governance. Gaps may trigger work in internal communications or an Advanced Attack, but they do…

How it fits compliance and the program
Questions

Questions about the tabletop

Is this a talk for employees?
No. It is the only service in this catalog that is not aimed at the roster. The audience is the committee and the board. Talks are another page.
Does it help with the auditor?
Rehearsal minutes and owned gaps are evidence that the plan was practiced. It is not a seal or a certificate. Compliance decides how to file it.
Do we have to take a system down?
No. It is a table exercise. The clock is decisions, not technical failover. A technical drill is discussed as a separate scope.
Who buys?
The CISO — or risk — who needs the board involved. If the buyer is awareness and the audience is the roster, this is not the page.
Is there a published price?
No. It depends on the committee, the length and the scenario. It is quoted.

Sit the committee in front of the incident

If the response plan was never rehearsed with the board, compliance does not have that evidence. Let’s talk about the table.

Full catalog on Services