Incident Response

Tabletop exercises that test the plan before an attacker does.

A response plan is only as good as the last time you ran it. SubRosa facilitates realistic tabletop exercises that put your team through a live scenario, exposing the gaps in your plan, tooling, and decision-making while the stakes are still hypothetical.

Custom scenarios · Facilitated · Executive & technical · Gap analysis

Tabletop exercise, defined

What is an incident response tabletop exercise?

An incident response tabletop exercise is a facilitated, discussion-based simulation of a security incident. A facilitator walks your team through a realistic scenario, ransomware, a data breach, business email compromise, and the team works through how they would detect, decide, communicate, and respond. It surfaces the gaps in your plan, roles, and tooling, and builds the muscle memory that makes a real response faster and calmer.

What's included

A drill built around your real risks.

Every exercise is designed around the scenarios most likely to hit your organization.

Custom scenario development

Scenarios built from real attacks and tailored to your industry, environment, and threat model.

Expert facilitation

Experienced responders facilitate the exercise, injecting realistic twists and keeping the discussion sharp.

Executive & technical tracks

Sessions for both leadership (decisions, comms, legal) and technical teams (containment, forensics, recovery).

Gap analysis & follow-up

A clear report of the gaps the exercise revealed, with prioritized recommendations and follow-up training.

How the engagement runs

The exercise, and what comes after it.

A tabletop is only worth running if it changes something. The scenario design and the follow-up matter more than the session itself.

  1. 01

    Objective setting

    We agree what you are testing. A tabletop that tries to test everything tests nothing — a session focused on ransomware decision-making runs very differently from one testing regulatory notification timelines.

  2. 02

    Scenario development

    Scenarios are built around your environment, your systems and your actual threat profile, and injected in stages so participants respond to developing information rather than a summary. A generic scenario gets generic answers.

  3. 03

    Participant selection

    The value depends on who is in the room. Technical responders alone will not surface the legal, communications and executive decisions that dominate a real incident. We advise on who should attend and, where useful, run separate executive and technical tracks.

  4. 04

    Facilitated exercise

    A facilitator drives the scenario and injects complications — a system that will not restore, a journalist calling, a regulator's clock running. The role is to surface where decision authority is unclear, which is the most common real-world failure.

  5. 05

    Hot wash

    Immediately after, while it is fresh: what worked, what did not, what nobody knew. This session is consistently where the most valuable findings come out, and it depends on people being willing to say a plan did not work.

  6. 06

    Report and plan revisions

    You get a report of the gaps found and, more usefully, concrete revisions to your incident response plan and playbooks. An exercise that ends in a report nobody actions was an expensive meeting.

Why SubRosa

Facilitated by real responders.

Realistic scenarios

Our facilitators have run real incidents, so the scenarios and curveballs reflect how attacks actually unfold.

Actionable findings

You leave with a concrete list of gaps and fixes, not just a feeling that the session went well.

Whole-team value

Exercises engage executives, IT, legal, and comms together, because a real incident involves all of them.

Every gap the drill revealed.

From exercise to improvement.

Your tabletop findings land in Sable: the gaps the exercise exposed, the owners, and the follow-up actions, tracked to closed, so each drill measurably improves your response instead of being forgotten by Monday.

Exercises in Sable
TabletopScenario: ransomware
  • Detection & triage
    2 gaps
  • Escalation & decisions
    1 gap
  • Communications
    3 gaps
  • Containment & recovery
    No gaps
6 gaps foundFixes assigned

Common questions

What is an incident response tabletop exercise?
An incident response tabletop exercise is a facilitated, discussion-based simulation of a security incident. A facilitator walks your team through a realistic scenario, such as ransomware or business email compromise, and the team works through how they would detect, decide, communicate, and respond. It surfaces gaps in your plan, roles, and tooling, and builds the muscle memory that makes a real response faster and calmer.
How often should we run tabletop exercises?
Most organizations run a tabletop exercise at least annually, and after any major change to the team, environment, or threat landscape. Frameworks and cyber insurers increasingly expect regular exercises. SubRosa can run executive and technical sessions and provide a gap analysis after each.
Who should attend a tabletop exercise?
More than the security team. Real incidents are dominated by legal, communications and executive decisions — whether to pay, what to tell customers, when a regulator's clock starts — and none of those surface if only technical responders are in the room. Where the group is large or the decisions differ sharply, we run separate executive and technical tracks.
How long does an exercise take?
Typically two to four hours for the session itself, plus scenario development beforehand and a hot wash immediately after. The preparation and the follow-up are where most of the value is; the session is the part that surfaces it.
How often should we run one?
At least annually, and after any significant change to your environment, your team or your obligations. Several frameworks expect regular testing of the incident response plan, and a tabletop is the most practical way to evidence it.
What happens afterwards?
You get the gaps found and, more usefully, concrete revisions to your incident response plan and playbooks. An exercise that ends in a report nobody actions was an expensive meeting — the deliverable is the changed plan, not the observation.

Test your response on your terms.

Book a tabletop exercise and find the gaps in your incident response while the scenario is still hypothetical.