A good exercise is uncomfortable. If everybody left the room feeling reassured, the scenario was too kind.
A tabletop exercise puts the people who would actually respond in a room with a realistic scenario and no ability to look anything up afterwards. The output is not a score. It is a list of the specific things that would have gone wrong, found while they are still cheap to fix.

- The real teamNot only IT, and not deputies
- Realistic scenarioBuilt from your estate and your sector
- Correction listThe output, rather than a pass or fail
- CIS Control 17Incident response management
Seven things that separate a useful exercise from a workshop.
The people who would actually respond, in the room
Not only IT. Whoever declares an incident, whoever authorises containment, whoever authorises emergency spend, whoever speaks externally, and representatives from the functions the incident would affect. An exercise attended only by technical staff tests the technical response and leaves every decision untested, which is the half that fails during real incidents.
A scenario built from your estate, not from a template
Using your actual systems, your actual suppliers, your actual regulatory position and a plausible entry route. Generic scenarios produce generic discussion. A scenario that names the system somebody in the room is responsible for, on a day of the week that matters to your business, produces the specific answers that expose the gaps.
Decisions forced rather than discussed
The facilitator role is to press for a decision rather than accept a description of a process. Who is disconnecting that system, now, and who authorised it. The discomfort in that moment is the exercise working, because the same discomfort in a real incident is measured in hours and the hours are where the damage accumulates.
Injects that change the situation partway through
A journalist calls. The attacker posts a sample publicly. A second system fails. The person who would decide is unreachable. Injects test whether the response adapts or whether it follows a script that assumes the situation stays as first described, which real incidents never do.
Written findings, captured as they happen
Every point at which the room could not answer a question, could not find a document, could not reach a person or could not make a decision. Captured at the moment rather than reconstructed afterwards, because the specific hesitation is the finding and it is forgotten within an hour of the exercise ending.
No score, and no pass
An exercise that produces a grade encourages the participants to perform rather than to think, and it encourages the facilitator to design a scenario the organisation can handle. The output is a correction list, and a long list from a first exercise is a success rather than a failure. It is also considerably cheaper than the alternative way of generating it.
A second exercise scheduled before the first one ends
One exercise finds gaps. A rhythm builds capability. Scheduling the next one before the first is over changes the status of the correction list from a report to a commitment, and it means the second exercise measures whether the corrections were made rather than starting from the same position.
Not whether people know what to do. Whether they can decide, find and reach.
Technical knowledge is rarely the constraint in a real incident. Three other things are, and all three are only testable by exercising.
- Can they decide. Whether the person in the room believes they have the authority to disconnect a system, authorise spend or notify a regulator, without escalating to somebody who is asleep. That belief is what determines the speed of the first hour.
- Can they find. Whether the plan, the contact list, the network diagram and the recovery runbook are reachable when the environment they are stored in may be unavailable or untrusted. This is the finding that appears in almost every first exercise.
- Can they reach. Whether the phone numbers work, whether the insurer notification route is known, whether the retained responder answers, and whether the person named as the decision maker is contactable by a route that does not depend on corporate email.
- None of the three is discoverable by reading the plan, and all three are discoverable in two hours in a room. That ratio is why exercising is the highest return activity in incident preparedness and why it is consistently the one that gets postponed.
Four things that make an exercise produce corrections rather than reassurance.
We design the scenario to be difficult for you specifically
Using your systems, your suppliers, your regulatory position and a route that is plausible given your actual exposure. A scenario that names the system somebody in the room owns produces a different quality of answer from one about a fictional company, and it is the difference between discussion and discovery.
We press for decisions instead of accepting descriptions
The most common evasion is describing a process rather than making a call. The facilitator role is to keep asking who is doing that, now, and on whose authority, until somebody either makes the decision or says out loud that they cannot. Both outcomes are findings and the second one is the more valuable.
We test reachability rather than listing contacts
Where an exercise reaches a point of contacting the insurer, the retained responder or the regulator, we ask the participant to find the number and describe the route rather than assert that it exists. Contact lists are almost always stale, and the exercise is the cheapest possible place to discover it.
We write findings as corrections somebody owns
Not observations, and not a maturity rating. Each finding becomes a specific change with a named owner and a date, and where the change is to the plan text we draft the text rather than recommending that somebody does. A report that requires interpretation before it can be actioned tends not to be actioned.
Four phases, and the exercise itself is the shortest.
- 01Weeks 1 to 2
Design the scenario around your organisation
Understanding the estate, the critical systems, the suppliers, the regulatory position and what would genuinely be difficult. Then a scenario using real system names and a plausible entry route, with injects designed to test the specific decisions we expect to be unclear.
- A scenario built from your estate rather than a template
- Injects designed against the decisions likely to be unclear
- Participant list agreed, including non-technical decision makers
- Objectives agreed with whoever commissioned the exercise
- 02Exercise day
Facilitate, press for decisions, and capture everything
Two to three hours with the response team. The facilitator presses for decisions rather than descriptions, introduces injects to change the situation, and captures every hesitation, every document that could not be found and every person who could not be reached, as it happens.
- A facilitated exercise with the real response team
- Injects delivered to test adaptation rather than recall
- Findings captured in the moment, not reconstructed after
- A hot debrief in the room while it is fresh
- 03Week after
Report as corrections, with owners
A findings list rather than a score, each item written as a specific correction with a named owner and a target date. Where the finding is a gap in the plan, the plan text is drafted. Where it is a missing contact, the contact is identified. The report is meant to be worked, not filed.
- A correction list with owners and dates
- Plan amendments drafted rather than recommended
- Contact pack gaps identified and filled
- Findings mapped to incident response management as a control
- 04Next cycle
Exercise again, and measure the difference
The next exercise scheduled before this one closes, with a different scenario testing different decisions. The measure of success is whether the corrections from the first were made, which is the only way to distinguish a preparedness programme from an annual event that produces the same findings each time.
- Next exercise scheduled and in diaries
- Prior corrections verified at the start of it
- A different scenario testing different decisions
- A trend across exercises, reported upwards
Six UAE situations where an exercise is worth scheduling now.
An organisation that has written a plan and never used it
The most common case, and the plan is usually good. What has never been tested is whether the people named in it believe they have the authority it gives them, whether they can find it if the environment is unavailable, and whether the contacts still work. All three are testable in one session.
A regulated firm with a notification obligation and a clock
Where an obligation starts a clock at the point of recognition, the exercise tests whether anybody in the room would have recognised it, who would have started the clock, and how the notification would actually be made. That sequence is unforgiving in a real incident and entirely learnable in a rehearsal.
An operator where containment means stopping production
The most valuable exercise for this profile, because containment is a genuine business decision rather than a technical one. Putting the operations director and the security lead in the same room, facing the same decision with a clock running, is where the authority question gets settled before it matters.
A firm that has just retained an incident response provider
A retainer is worth exercising, because the value depends on how quickly it can be invoked. Who calls them, what information they need immediately, what they will and will not do, and how the engagement is authorised commercially. Finding out during the incident wastes the first hours of the thing you bought.
A healthcare organisation where systems cannot simply be switched off
The containment trade-off is clinical rather than technical, and the exercise is where that gets worked through with clinical input present. What the fallback to manual process actually looks like, who authorises it, and how long the organisation can run that way are questions with answers that nobody should be deriving live.
An organisation whose response team has changed
People leave, roles change and new joiners inherit responsibilities described in a document they have never opened. A plan that worked with the previous team is untested with the current one, and the exercise is the mechanism that transfers the knowledge rather than the document.
How UAE organisations prepare their people for an incident.
| Feature | Facilitated exercise with the real team | A walkthrough of the plan | No exercise |
|---|---|---|---|
Non-technical decision makers involved | Yes | Rarely | No |
Scenario specific to the organisation | Yes | Generic | Not applicable |
Decisions forced rather than described | Yes | No | No |
Situation changes partway through | Yes | No | Not applicable |
Contact reachability tested | Yes | No | No |
Findings captured as they occur | Yes | Afterwards | Not applicable |
Plan amended as a result | Yes | Sometimes | No |
Next exercise scheduled | Yes | No | No |
Improvement measurable between exercises | Yes | No | Not applicable |
Time required | Half a day | An hour | None |
Six scenarios, and what each is designed to expose.
| Scenario | What it exposes | |
|---|---|---|
| Ransomware across multiple sites | Containment authority, the cost of disconnecting, and whether recovery has ever been measured | |
| Business email compromise with a payment in flight | Speed of the finance and banking response, and who can instruct a recall | |
| Data exfiltration discovered by a third party | Notification obligations, legal involvement, and what you can establish about what left | |
| Compromise of a critical supplier | Whether anybody owns the relationship, and whether you can sever the connection | |
| Insider action by a privileged user | Evidence preservation, HR and legal sequencing, and how privileged access is revoked | |
| Loss of administrative access to the tenant | Whether break-glass accounts work, which Microsoft recommends validating at least every 90 days |
Five steps, and the exercise itself is half a day.
- 1
Understand the organisation and agree the objectives
The estate, the critical systems, the supplier dependencies, the regulatory position and any recent incidents. Then what the commissioner actually wants tested, which is frequently more specific than run an exercise and is worth surfacing before the scenario is designed rather than after.
- 2
Design a scenario that would genuinely be difficult
Real system names, a plausible entry route, a timeline that puts pressure on the decisions we expect to be unclear, and injects that change the situation partway through. Where the objective includes a specific decision, the scenario is built to make that decision unavoidable rather than incidental.
- 3
Get the right people in the room
Whoever declares, whoever authorises containment, whoever authorises spend, whoever speaks externally, and the affected business functions. Deputies attending in place of decision makers weakens the exercise substantially, because the point is to test whether the person who holds the authority believes they hold it.
- 4
Facilitate the exercise and capture everything
Two to three hours, pressing for decisions rather than descriptions, delivering injects, and recording every hesitation, unreachable person and unfindable document at the moment it occurs. Followed by a hot debrief in the room while the experience is fresh and people are still willing to say what was unclear.
- 5
Report corrections and book the next one
Findings written as specific changes with owners and dates, plan text drafted where the correction is textual, contact gaps filled by actually making the calls, and the next exercise scheduled with a different scenario. That last step is what turns a single exercise into a preparedness programme.
What organisations ask about tabletop exercises.
Fifteen things that determine whether the exercise is worth the time.
Who attends
- Is the incident declarer present?Not a deputy for the exercise.
- Is somebody who can authorise containment present?The key decision.
- Is somebody who can authorise spend present?External responders cost money.
- Is communications or legal represented?They are needed within the hour.
- Are affected business functions represented?They carry the consequence.
Scenario design
- Does it use your real system names?Generic scenarios produce generic answers.
- Is the entry route plausible for you?It should be recognisable.
- Does it force an expensive decision?That is where the value is.
- Are there injects?The situation must change.
- Would it be uncomfortable?A comfortable scenario finds nothing.
Afterwards
- Are findings written as corrections?With an owner and a date.
- Is the plan actually amended?Drafted, not recommended.
- Are contact gaps filled?By calling, not by listing.
- Is the next exercise booked?Before this one closes.
- Does anybody outside IT see the findings?They usually should.
The pages around this one.
Ask three people who can authorise disconnecting a production system. Compare the answers.
If they differ, or if anybody hesitates, you have the most common exercise finding without having run one. It is also the finding that costs the most hours during a real incident, and it is settled in a single conversation.
Related Services
Explore more solutions that work great with this service
Incident Response Plan
Written, exercised, and findable when the network is not
Incident Response
24/7 incident response and forensics in Dubai
Emergency Access Accounts
Break-glass admin that actually works on the day
Business Continuity Planning
BCP, RPO/RTO design, and DR runbook authoring
Disaster Recovery Audit
Measured recovery time, not the stated objective
Ransomware Protection
Defender XDR and Sentinel-driven ransomware defense
Security Awareness Training
Phishing simulation and behavior-change training
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly