Tabletop: the committee faces the incident before it is real
We do not train employees. We facilitate a table exercise in which the board and the committee find what is missing in the response plan. The buyer is the CISO who needs the board in the room.
How we facilitate a table that actually decides
We write the incident with the industry, the systems and the role names — not personal names, if legal asks — that the plan already uses. A generic scenario does not surface useful gaps.
We convene whoever the plan names: board, legal, communications, operations, CISO. If a role is missing, the exercise logs it as a gap; one of our actors does not replace it.
Run the clock, inject turns, keep IT from monopolizing. The facilitator does not “win”. They make the committee decide and keep the decisions written down.
We return what was missing in the plan, who should own it and what can be shown to compliance. There is no score of “the board failed”.
Why the CISO cannot rehearse the board with an LMS
Because the board does not take a phishing course and because a response plan is not proven by attendance. It is proven when someone has to decide in twenty minutes whether to pay, to cut, to report. That muscle is not trained in the…
What you get
Governance evidence in front of an incident, written for the committee and for compliance, not for the roster.
Signed scenario
Incident, roles and table rules, aligned to the existing plan. Legal can strip proper names. The scenario is not recirculated as awareness content.
Facilitated session
Hours at the table with the real committee. One facilitator, one clock, injections. It is not a webinar and not an all-hands talk.
Decision and gap minutes
What was decided, what could not be decided, which role was missing. Plan language, not campaign language.
Bridge to compliance
What can be filed as a rehearsal of the plan and what remains as a task. An explicit link to compliance resources, not to the phishing builder.
What we need from you
That the CISO — or the buyer — can sit the committee. Without the board, or without someone who represents it with a mandate, the exercise degrades into an IT workshop and we do… Also a real agenda: a slot when those people are available, not a “whenever”. Communications and legal must know a simulated incident with system names will be discussed. This…
How it fits compliance and the program
The tabletop does not feed the click index. It feeds the plan. The awareness program stays on the platform; this session is governance. Gaps may trigger work in internal communications or an Advanced Attack, but they do…
Often contracted alongside this one
Questions about the tabletop
Is this a talk for employees?
Does it help with the auditor?
Do we have to take a system down?
Who buys?
Is there a published price?
Sit the committee in front of the incident
If the response plan was never rehearsed with the board, compliance does not have that evidence. Let’s talk about the table.
Full catalog on Services