Skip to main content
cyber tabletop exercises

01. How often should we run a cyber tabletop exercise?

At least once a year for most organizations. Regulated industries like healthcare and financial services often benefit from running exercises quarterly to keep pace with evolving requirements.

02. Who should participate in a tabletop exercise?

Anyone with a defined role in your incident response plan, plus executive leadership, legal counsel, communications, and HR. A cybersecurity tabletop exercise limited to the IT team only tests part of a real incident.

03. How long does a tabletop exercise take?

Anywhere from 15 minutes for a quick scenario check-in to three or four hours for a full, multi-module exercise covering several departments and decision points.

04. What is the difference between a tabletop exercise and a red team exercise?

A tabletop exercise is discussion-based and tests decisions and communication without touching live systems. A red team exercise actively attempts to breach systems to test technical controls. Most organizations benefit from tabletop exercises first, since they are lower cost and reveal process gaps that technical testing alone will not catch.

05. Do small businesses really need tabletop exercises?

Yes. Smaller organizations often have fewer people covering more roles during an incident, which makes clear decision-making even more important. A tabletop exercise costs far less than the confusion of an untested plan during a real event.

Joe Manis

Joe Manis is a Service Delivery Manager at DCG Technical Solutions with over 25 years of experience in IT services, infrastructure operations, and client-focused technical leadership. He specializes in incident and problem management, service optimization, and ensuring technology delivery aligns with business goals. Joe is passionate about helping organizations improve operational efficiency and achieve better outcomes through strategic IT management.