All resources
// Resources

Cybersecurity Incident-Response Tabletop Worksheet

Published August 5, 2026

A tabletop exercises people, decisions, handoffs, and evidence paths through a plausible scenario. It does not prove production containment tooling will work, nor does it replace an incident response plan. NIST SP 800-61 frames preparation, detection, containment, eradication, recovery, and lessons learned. CISA recommends exercising an incident and communications plan, including ransomware and data-extortion scenarios.

Define exercise boundary

Name exercise sponsor, facilitator, scenario owner, participants, clock, and stop conditions. Use synthetic systems, names, and data. State what will not be tested: live isolation, customer notification, external reporting, ransom negotiation, or production restore. Those actions require separate authority. Give every participant a role card with delegated decisions and escalation contact; unknown authority is valid exercise finding.

Scenario: at 09:00, endpoint telemetry reports rapid file renames on finance workstation FIN-22. At 09:08, finance cannot access shared drive. At 09:15, security finds a privileged sign-in from an unusual network. Injects arrive only after participants describe evidence needed and decision owner.

Timed inject and decision log

Time / injectExpected decisionCompleted example and evidenceOwnerPass/failException or remediation
09:00 encryption alertdeclare investigation or false positiveincident IR-26-08, alert ID and host name preservedincident leadPassendpoint team notified
09:12 shared drive impactcontain host or preserve access firstlead approves network isolation; ticket timestamp retainedIT leadPassfinance continuity owner unavailable
09:20 suspected privilege useprotect identitiesadmin sessions revoked; identity log export requestedidentity ownerFailbreak-glass owner not named
09:35 possible data exposurebegin legal and communications assessmentcounsel receives fact sheet, no public statement issuedlegal leadPassnotification rule not decided
10:00 restore requestapprove recovery test orderfinance service marked priority twobusiness ownerOpenrestore objective missing

Log facts separately from assumptions. “Data was exfiltrated” is an assumption until supported by evidence. Record source, collector, collection time, storage location, and access restrictions for every log export, disk image, screenshot, or interview note. Preserve original evidence; work from copies where possible.

Decision points worth testing

Ask who can declare incident severity, isolate a critical service, disable privileged accounts, approve emergency change, contact supplier, approve recovery order, and approve external language. Ask what happens when that person is unavailable. Measure handoff latency and decision quality, not presentation skill. A handoff without named decision maker is a gap.

Use a communications inject: customer support receives a screenshot from social media. Participants must decide what facts can be confirmed, who approves holding language, and how support avoids speculation. Keep legal, contractual, and notification determinations with authorized legal and management reviewers; technical exercise notes cannot decide them.

Exercise scorecard

Score each objective against evidence: decision owner named, handoff timed, facts separated from assumptions, evidence custody recorded, and corrective action assigned. Example outcome: four of five objectives pass; identity escalation fails because break-glass owner is absent. Keep failed score visible until evidence proves correction in next exercise.

After-action record

Within agreed period, facilitator records what happened, what evidence was available, decisions, timing, gaps, and corrective actions. Each action has owner, due date, priority, acceptance evidence, and status. Example: identity owner must publish break-glass inventory and run a disable test by 2026-09-01; pass evidence is signed test log and reviewer acknowledgment. Mark incomplete actions as open, not complete by intent.

Repeatable scenario pack

Keep scenario facts, inject sequence, role cards, facilitator notes, scorecard, and after-action record together. Change one variable in next exercise: unavailable identity provider, supplier escalation delay, conflicting business priority, or incomplete logs. This reveals whether correction changed decision behavior rather than only document wording.

Closure drill

Facilitator closes one exercise objective only after a corrective action changes a repeatable decision. For the absent break-glass owner, next drill injects an unavailable identity administrator at 09:20. Pass evidence is published delegated authority, contact acknowledgement, timed escalation, and a recorded revocation decision; a revised role chart alone is insufficient. If exercise facts conflict, preserve both versions and assign fact verification rather than scoring a guessed answer. After-action owner reports closure only with this follow-up evidence.

Limits

A tabletop demonstrates discussion under exercise assumptions. It does not guarantee incident readiness, regulatory compliance, legal sufficiency, or recovery success. Test technical controls separately and obtain required authority before real containment, notification, or preservation actions.

Sources

Worked exercise output

Run scenario where supplier account exports customer records through legitimate API. Give participants incomplete facts, then timed injects for legal review, containment choice, communication, and evidence preservation. Expected behavior: team records decisions, owners, assumptions, not breach confirmation. Edge case: incident lead unavailable; deputy authority and escalation route work without improvised approval. Closure test: convert every lesson into owner, due date, verification evidence, and follow-up review.

Worked closure check

For supplier-account export exercise, retain scenario version, facilitation date, participant roster, inject timeline, delegated incident authority, and decision log. Output records behavior under exercise assumptions, not incident readiness, legal notification duty, compliance, or recovery assurance. Replace affected observations when role delegation or playbook changes before follow-up drill. An uninvolved facilitator samples one claimed handoff, matches it to timed inject and evidence request, then confirms corrective action owner and due date; unresolved authority gaps stay on scorecard.

Have a system that needs testing?