We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Tabletop exercise
Cyber incident tabletop exercises, UAE

A good exercise is uncomfortable. If everybody left the room feeling reassured, the scenario was too kind.

A tabletop exercise puts the people who would actually respond in a room with a realistic scenario and no ability to look anything up afterwards. The output is not a score. It is a list of the specific things that would have gone wrong, found while they are still cheap to fix.

Book a tabletop exerciseSee how we run them
Cyber incident tabletop exercise facilitation for UAE organisations
  • The real teamNot only IT, and not deputies
  • Realistic scenarioBuilt from your estate and your sector
  • Correction listThe output, rather than a pass or fail
  • CIS Control 17Incident response management
How we run them

Seven things that separate a useful exercise from a workshop.

NIST published revision 3 of its incident response guidance in April 2025, framing incident response as a CSF 2.0 Community Profile with stated aims of helping organisations prepare, reduce incident frequency and impact, and improve the efficiency of detection, response and recovery. Preparation is where the exercise sits, and it is the part most organisations under-invest in.

The people who would actually respond, in the room

Not only IT. Whoever declares an incident, whoever authorises containment, whoever authorises emergency spend, whoever speaks externally, and representatives from the functions the incident would affect. An exercise attended only by technical staff tests the technical response and leaves every decision untested, which is the half that fails during real incidents.

A scenario built from your estate, not from a template

Using your actual systems, your actual suppliers, your actual regulatory position and a plausible entry route. Generic scenarios produce generic discussion. A scenario that names the system somebody in the room is responsible for, on a day of the week that matters to your business, produces the specific answers that expose the gaps.

Decisions forced rather than discussed

The facilitator role is to press for a decision rather than accept a description of a process. Who is disconnecting that system, now, and who authorised it. The discomfort in that moment is the exercise working, because the same discomfort in a real incident is measured in hours and the hours are where the damage accumulates.

Injects that change the situation partway through

A journalist calls. The attacker posts a sample publicly. A second system fails. The person who would decide is unreachable. Injects test whether the response adapts or whether it follows a script that assumes the situation stays as first described, which real incidents never do.

Written findings, captured as they happen

Every point at which the room could not answer a question, could not find a document, could not reach a person or could not make a decision. Captured at the moment rather than reconstructed afterwards, because the specific hesitation is the finding and it is forgotten within an hour of the exercise ending.

No score, and no pass

An exercise that produces a grade encourages the participants to perform rather than to think, and it encourages the facilitator to design a scenario the organisation can handle. The output is a correction list, and a long list from a first exercise is a success rather than a failure. It is also considerably cheaper than the alternative way of generating it.

A second exercise scheduled before the first one ends

One exercise finds gaps. A rhythm builds capability. Scheduling the next one before the first is over changes the status of the correction list from a report to a commitment, and it means the second exercise measures whether the corrections were made rather than starting from the same position.

What the exercise actually tests

Not whether people know what to do. Whether they can decide, find and reach.

Technical knowledge is rarely the constraint in a real incident. Three other things are, and all three are only testable by exercising.

  • Can they decide. Whether the person in the room believes they have the authority to disconnect a system, authorise spend or notify a regulator, without escalating to somebody who is asleep. That belief is what determines the speed of the first hour.
  • Can they find. Whether the plan, the contact list, the network diagram and the recovery runbook are reachable when the environment they are stored in may be unavailable or untrusted. This is the finding that appears in almost every first exercise.
  • Can they reach. Whether the phone numbers work, whether the insurer notification route is known, whether the retained responder answers, and whether the person named as the decision maker is contactable by a route that does not depend on corporate email.
  • None of the three is discoverable by reading the plan, and all three are discoverable in two hours in a room. That ratio is why exercising is the highest return activity in incident preparedness and why it is consistently the one that gets postponed.
Ask us to design a scenario for you
How we approach it

Four things that make an exercise produce corrections rather than reassurance.

Facilitating an exercise badly is easy and produces a room full of people agreeing that the plan looks fine. Every point below is about creating the conditions where the gaps actually surface.

We design the scenario to be difficult for you specifically

Using your systems, your suppliers, your regulatory position and a route that is plausible given your actual exposure. A scenario that names the system somebody in the room owns produces a different quality of answer from one about a fictional company, and it is the difference between discussion and discovery.

We press for decisions instead of accepting descriptions

The most common evasion is describing a process rather than making a call. The facilitator role is to keep asking who is doing that, now, and on whose authority, until somebody either makes the decision or says out loud that they cannot. Both outcomes are findings and the second one is the more valuable.

We test reachability rather than listing contacts

Where an exercise reaches a point of contacting the insurer, the retained responder or the regulator, we ask the participant to find the number and describe the route rather than assert that it exists. Contact lists are almost always stale, and the exercise is the cheapest possible place to discover it.

We write findings as corrections somebody owns

Not observations, and not a maturity rating. Each finding becomes a specific change with a named owner and a date, and where the change is to the plan text we draft the text rather than recommending that somebody does. A report that requires interpretation before it can be actioned tends not to be actioned.

How an exercise is delivered

Four phases, and the exercise itself is the shortest.

A two hour exercise takes rather more than two hours to deliver properly. The design determines whether it exposes anything, and the follow-up determines whether anything changes.
  1. 01
    Weeks 1 to 2

    Design the scenario around your organisation

    Understanding the estate, the critical systems, the suppliers, the regulatory position and what would genuinely be difficult. Then a scenario using real system names and a plausible entry route, with injects designed to test the specific decisions we expect to be unclear.

    • A scenario built from your estate rather than a template
    • Injects designed against the decisions likely to be unclear
    • Participant list agreed, including non-technical decision makers
    • Objectives agreed with whoever commissioned the exercise
  2. 02
    Exercise day

    Facilitate, press for decisions, and capture everything

    Two to three hours with the response team. The facilitator presses for decisions rather than descriptions, introduces injects to change the situation, and captures every hesitation, every document that could not be found and every person who could not be reached, as it happens.

    • A facilitated exercise with the real response team
    • Injects delivered to test adaptation rather than recall
    • Findings captured in the moment, not reconstructed after
    • A hot debrief in the room while it is fresh
  3. 03
    Week after

    Report as corrections, with owners

    A findings list rather than a score, each item written as a specific correction with a named owner and a target date. Where the finding is a gap in the plan, the plan text is drafted. Where it is a missing contact, the contact is identified. The report is meant to be worked, not filed.

    • A correction list with owners and dates
    • Plan amendments drafted rather than recommended
    • Contact pack gaps identified and filled
    • Findings mapped to incident response management as a control
  4. 04
    Next cycle

    Exercise again, and measure the difference

    The next exercise scheduled before this one closes, with a different scenario testing different decisions. The measure of success is whether the corrections from the first were made, which is the only way to distinguish a preparedness programme from an annual event that produces the same findings each time.

    • Next exercise scheduled and in diaries
    • Prior corrections verified at the start of it
    • A different scenario testing different decisions
    • A trend across exercises, reported upwards
Where this matters most

Six UAE situations where an exercise is worth scheduling now.

The best time is when there is no pressure, attention is available and nobody is recovering from anything. The second best time is immediately after somebody else in your sector has been attacked.

An organisation that has written a plan and never used it

The most common case, and the plan is usually good. What has never been tested is whether the people named in it believe they have the authority it gives them, whether they can find it if the environment is unavailable, and whether the contacts still work. All three are testable in one session.

A regulated firm with a notification obligation and a clock

Where an obligation starts a clock at the point of recognition, the exercise tests whether anybody in the room would have recognised it, who would have started the clock, and how the notification would actually be made. That sequence is unforgiving in a real incident and entirely learnable in a rehearsal.

An operator where containment means stopping production

The most valuable exercise for this profile, because containment is a genuine business decision rather than a technical one. Putting the operations director and the security lead in the same room, facing the same decision with a clock running, is where the authority question gets settled before it matters.

A firm that has just retained an incident response provider

A retainer is worth exercising, because the value depends on how quickly it can be invoked. Who calls them, what information they need immediately, what they will and will not do, and how the engagement is authorised commercially. Finding out during the incident wastes the first hours of the thing you bought.

A healthcare organisation where systems cannot simply be switched off

The containment trade-off is clinical rather than technical, and the exercise is where that gets worked through with clinical input present. What the fallback to manual process actually looks like, who authorises it, and how long the organisation can run that way are questions with answers that nobody should be deriving live.

An organisation whose response team has changed

People leave, roles change and new joiners inherit responsibilities described in a document they have never opened. A plan that worked with the previous team is untested with the current one, and the exercise is the mechanism that transfers the knowledge rather than the document.

Three positions

How UAE organisations prepare their people for an incident.

The middle column is the most common form of exercise and it is worth doing. It is also considerably less useful than it appears, because a walkthrough tests recall rather than decision-making.
Non-technical decision makers involved
Facilitated exercise with the real teamYes
A walkthrough of the planRarely
No exerciseNo
Scenario specific to the organisation
Facilitated exercise with the real teamYes
A walkthrough of the planGeneric
No exerciseNot applicable
Decisions forced rather than described
Facilitated exercise with the real teamYes
A walkthrough of the planNo
No exerciseNo
Situation changes partway through
Facilitated exercise with the real teamYes
A walkthrough of the planNo
No exerciseNot applicable
Contact reachability tested
Facilitated exercise with the real teamYes
A walkthrough of the planNo
No exerciseNo
Findings captured as they occur
Facilitated exercise with the real teamYes
A walkthrough of the planAfterwards
No exerciseNot applicable
Plan amended as a result
Facilitated exercise with the real teamYes
A walkthrough of the planSometimes
No exerciseNo
Next exercise scheduled
Facilitated exercise with the real teamYes
A walkthrough of the planNo
No exerciseNo
Improvement measurable between exercises
Facilitated exercise with the real teamYes
A walkthrough of the planNo
No exerciseNot applicable
Time required
Facilitated exercise with the real teamHalf a day
A walkthrough of the planAn hour
No exerciseNone
Feature
Facilitated exercise with the real team
A walkthrough of the plan
No exercise
Non-technical decision makers involved
YesRarelyNo
Scenario specific to the organisation
YesGenericNot applicable
Decisions forced rather than described
YesNoNo
Situation changes partway through
YesNoNot applicable
Contact reachability tested
YesNoNo
Findings captured as they occur
YesAfterwardsNot applicable
Plan amended as a result
YesSometimesNo
Next exercise scheduled
YesNoNo
Improvement measurable between exercises
YesNoNot applicable
Time required
Half a dayAn hourNone
The scenarios

Six scenarios, and what each is designed to expose.

We build the scenario around what would genuinely be difficult for your organisation. The right hand column is what each scenario is chosen to test, which is the reason to prefer one over another.
ScenarioWhat it exposes
Ransomware across multiple sitesContainment authority, the cost of disconnecting, and whether recovery has ever been measured
Business email compromise with a payment in flightSpeed of the finance and banking response, and who can instruct a recall
Data exfiltration discovered by a third partyNotification obligations, legal involvement, and what you can establish about what left
Compromise of a critical supplierWhether anybody owns the relationship, and whether you can sever the connection
Insider action by a privileged userEvidence preservation, HR and legal sequencing, and how privileged access is revoked
Loss of administrative access to the tenantWhether break-glass accounts work, which Microsoft recommends validating at least every 90 days
How an engagement runs

Five steps, and the exercise itself is half a day.

Typically three to four weeks from commissioning to the report. Design takes the longest, the exercise takes an afternoon, and the corrections take as long as the organisation gives them.
  1. 1

    Understand the organisation and agree the objectives

    The estate, the critical systems, the supplier dependencies, the regulatory position and any recent incidents. Then what the commissioner actually wants tested, which is frequently more specific than run an exercise and is worth surfacing before the scenario is designed rather than after.

  2. 2

    Design a scenario that would genuinely be difficult

    Real system names, a plausible entry route, a timeline that puts pressure on the decisions we expect to be unclear, and injects that change the situation partway through. Where the objective includes a specific decision, the scenario is built to make that decision unavoidable rather than incidental.

  3. 3

    Get the right people in the room

    Whoever declares, whoever authorises containment, whoever authorises spend, whoever speaks externally, and the affected business functions. Deputies attending in place of decision makers weakens the exercise substantially, because the point is to test whether the person who holds the authority believes they hold it.

  4. 4

    Facilitate the exercise and capture everything

    Two to three hours, pressing for decisions rather than descriptions, delivering injects, and recording every hesitation, unreachable person and unfindable document at the moment it occurs. Followed by a hot debrief in the room while the experience is fresh and people are still willing to say what was unclear.

  5. 5

    Report corrections and book the next one

    Findings written as specific changes with owners and dates, plan text drafted where the correction is textual, contact gaps filled by actually making the calls, and the next exercise scheduled with a different scenario. That last step is what turns a single exercise into a preparedness programme.

Straight answers

What organisations ask about tabletop exercises.

The people who would actually respond, which is more than IT. Whoever declares an incident, whoever authorises containment, whoever authorises emergency spend, whoever speaks externally, and representatives from the business functions the incident would affect. An exercise attended only by technical staff tests the technical response and leaves the decisions untested.

Two to three hours for the exercise itself, plus a hot debrief. The design work beforehand takes longer than the exercise, because a scenario built around your actual estate and your actual difficult decisions is what makes the session productive. A generic scenario delivered without preparation produces a generic conversation.

Tell them the exercise is happening, its purpose and roughly how long it will take. Do not tell them the scenario. Preparation for a specific scenario produces rehearsed answers, which is the opposite of what the exercise is for. The point is to observe how the group behaves when the situation is new, because that is how it will be.

Then it worked. A long correction list from a first exercise is a success, because every item on it is something that would otherwise have been discovered during a real incident at considerably greater cost. The exercise that should worry you is the one where everybody left feeling reassured, which usually means the scenario was too kind.

No, deliberately. A score encourages participants to perform rather than think, and it encourages the facilitator to design something the organisation can handle. The output is a correction list with owners and dates. Where a maturity view is genuinely needed for reporting, we provide it separately and after the corrections rather than as the headline.

Whichever would be genuinely difficult for you. Common ones are ransomware across multiple sites, business email compromise with a payment in flight, data exfiltration discovered by a third party, compromise of a critical supplier, insider action by a privileged user, and loss of administrative access to the tenant. Each tests a different set of decisions.

Events introduced partway through that change the situation. A journalist calls. The attacker publishes a sample. A second system fails. The person who would decide is unreachable. They test whether the response adapts or whether it follows a script written for the situation as first described, which is not how real incidents behave.

At least annually, and more often where the team changes or the risk profile is high. The frequency matters less than the discipline of scheduling the next one before the current one closes, because that single act converts the correction list from a report into a commitment measured on a known date.

It should, and it is a genuinely useful inclusion. Microsoft recommends validating emergency access accounts at least every 90 days, conducting drills to validate the accounts work and to confirm monitoring and alerting rules trigger, and making security monitoring staff aware the check is ongoing. Folding that into an exercise satisfies both objectives at once.

It frequently contributes to one, and whether it satisfies yours depends on the obligation. Many frameworks and insurer questionnaires ask whether the incident response plan has been exercised and when. A documented exercise with a findings list, owners and completed corrections is a considerably stronger answer than confirming a plan exists.

Three, and they recur almost universally. Nobody in the room is certain who can authorise disconnecting a production system. The plan is stored somewhere that would be unavailable in the scenario being discussed. And at least two contacts in the escalation list have left the organisation or changed roles.

Yes, and organisations that build the capability internally get more exercises for less money, which is the right outcome. The value of external facilitation is the willingness to press for uncomfortable decisions and to record findings without regard for whose area they fall in, which is harder for somebody who works there. We are happy to build the internal capability deliberately.

For the decisions that are theirs, yes, and it is usually the single change that most improves an exercise. Containment authority, emergency spend, external communication and regulatory notification are executive decisions. Running the exercise without them tests whether IT can describe those decisions rather than whether the organisation can make them.

A correction list where each finding is written as a specific change with a named owner and a target date, plan text drafted where the correction is textual, an updated contact pack where gaps were found, and the next exercise scheduled. Not a narrative report, because a narrative report requires interpretation before anybody can act on it.

We scope by the number of scenarios and participants and whether the design requires deep familiarity with a complex estate. A single scenario exercise is a short engagement. Where an organisation wants a programme, running several across a year and building the internal facilitation capability is usually better value than commissioning each one separately.
Getting the most from it

Fifteen things that determine whether the exercise is worth the time.

The first group is who attends, the second is scenario design, and the third is what happens afterwards, which is where most exercise programmes quietly stop.

Who attends

  • Is the incident declarer present?
    Not a deputy for the exercise.
  • Is somebody who can authorise containment present?
    The key decision.
  • Is somebody who can authorise spend present?
    External responders cost money.
  • Is communications or legal represented?
    They are needed within the hour.
  • Are affected business functions represented?
    They carry the consequence.

Scenario design

  • Does it use your real system names?
    Generic scenarios produce generic answers.
  • Is the entry route plausible for you?
    It should be recognisable.
  • Does it force an expensive decision?
    That is where the value is.
  • Are there injects?
    The situation must change.
  • Would it be uncomfortable?
    A comfortable scenario finds nothing.

Afterwards

  • Are findings written as corrections?
    With an owner and a date.
  • Is the plan actually amended?
    Drafted, not recommended.
  • Are contact gaps filled?
    By calling, not by listing.
  • Is the next exercise booked?
    Before this one closes.
  • Does anybody outside IT see the findings?
    They usually should.
Related reading

The pages around this one.

Incident response plan

The plan the exercise tests, and where the corrections land.

Learn more

Incident response

The reactive service, for when the exercise stops being an exercise.

Learn more

Emergency access accounts

The break-glass validation that fits naturally into an exercise cycle.

Learn more
Next step

Ask three people who can authorise disconnecting a production system. Compare the answers.

If they differ, or if anybody hesitates, you have the most common exercise finding without having run one. It is also the finding that costs the most hours during a real incident, and it is settled in a single conversation.

Book a tabletop exerciseCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Incident Response Plan

Written, exercised, and findable when the network is not

Learn more

Incident Response

24/7 incident response and forensics in Dubai

Learn more

Emergency Access Accounts

Break-glass admin that actually works on the day

Learn more

Business Continuity Planning

BCP, RPO/RTO design, and DR runbook authoring

Learn more

Disaster Recovery Audit

Measured recovery time, not the stated objective

Learn more

Ransomware Protection

Defender XDR and Sentinel-driven ransomware defense

Learn more

Security Awareness Training

Phishing simulation and behavior-change training

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy