Skip to content

WHT Cyber  /  Field Notes  /  Post-Incident

Post-Incident

Tabletop exercises: the 90-minute meeting that saves your business.

You'll find every gap in your incident response plan in one of two places: a 90-minute tabletop, or a live ransomware event at 2 AM. The tabletop is cheaper.

By WHT Cyber Engineering July 30, 2026 8 min read

Most 20-to-150-employee firms in North Carolina have an incident response plan. It's a PDF. It lives in a SharePoint folder. It has phone numbers in it that were current in 2023. The CEO has never read it. The controller has never read it. The IT lead skimmed it once. That's not a plan — that's a document.

A tabletop exercise is the cheapest way to convert a document into an actual plan. It takes 90 minutes, costs nothing but calendar time, and it will find between 6 and 12 gaps every single time. Here's how to run one properly for a small business.

What a tabletop is (and isn't)

A tabletop is a facilitated, discussion-based walkthrough of a hypothetical incident. You sit in a conference room, someone reads out a scenario in stages, and each person around the table says what they would do at each stage — what they'd look for, who they'd call, what decisions they'd make.

It is not a technical drill. Nobody is touching a keyboard. Nobody is restoring a backup for real. The value is entirely in the conversation — specifically, in the moments where someone says “wait, who does that?” or “we don't have that,” or “actually the plan says to call Jerry but Jerry left in April.”

CISA publishes free tabletop packages under their CTEP program if you want a reference format. NIST's SP 800-61 (Computer Security Incident Handling Guide) is the underlying framework most SMB tabletops map to.

Who needs to be in the room

The single biggest mistake we see is running a “tabletop” that's only IT people. Ransomware is not an IT problem. It's a business problem that has an IT trigger. The people who need to be in the room:

  • Executive decision-maker. CEO, president, or managing partner. Someone whose signature actually authorizes wires, notifications, and legal disclosures.
  • Finance / controller. They own wire-fraud response, payroll continuity, insurance claim initiation.
  • Operations lead. Whoever knows how the business actually runs when the systems are down.
  • IT lead (internal) or MSP contact. Technical response, backups, endpoint isolation.
  • Legal. Outside counsel is fine — they need to know they're on the roster.
  • HR. Employee communications, especially if operations pause.
  • Communications lead. Anyone client-facing. For a small firm this is often the CEO doubling up.

For a 20-person shop this might be 4-5 people. For 150, maybe 8. Keep it small enough that everyone speaks.

A 90-minute agenda you can run this week

Here is the exact agenda we run for small clients. Copy it, adapt the scenario to your industry, book the meeting.

Minutes 0-5 — Ground rules

  • This is a no-blame exercise. If we find a gap, we fix it. Nobody's job is on the line.
  • “I don't know” is the correct answer when it's true. Faking a plan we don't have is worse than admitting we don't have one.
  • Someone takes notes. Every gap becomes an action item with an owner and a due date.

Minutes 5-15 — Scenario Stage 1: The alert

Facilitator reads: “It's Tuesday 8:15 AM. An employee in accounting calls the front desk and says her laptop is showing a full-screen message that reads: Your files have been encrypted. Contact us within 72 hours or your data will be published. Three other employees are calling in with the same message. The shared drive is unreachable.”

Discussion questions:

  • Who does that first call actually reach? What do they do in the first 60 seconds?
  • Who declares this an incident? What's the trigger phrase?
  • Who is called first: MSP, MSSP, insurance carrier, legal, executive?
  • Do we have those phone numbers off the domain? (If the answer is “they're in Outlook” — and Outlook is down — you just found a gap.)

Minutes 15-30 — Scenario Stage 2: Containment

Facilitator reads: “It's 8:45 AM. IT confirms 40% of workstations are affected. The file server is encrypted. Backups appear reachable but not verified.”

Discussion questions:

  • What do we tell employees right now? Do they keep coming to the office? Do they stop touching workstations?
  • Who authorizes network isolation? Do we have the authority pre-delegated to the MSP/MSSP or does someone need to sign off?
  • What client-facing commitments are we going to miss today? Who calls those clients?
  • When do we notify the cyber insurance carrier? Most policies require notification within 24 hours — and use of unapproved forensics vendors can void the policy. This is the moment that matters.

Minutes 30-50 — Scenario Stage 3: Escalation

Facilitator reads: “It's Wednesday, 24 hours in. Attackers post a sample of stolen files on their leak site — client PII, an employee W-2, a contract with a partner. They demand $500,000 in Bitcoin, 48 hours.”

Discussion questions:

  • Who decides whether to engage the attackers at all? (Usually counsel + insurance + executive.)
  • Do we notify affected clients now, or wait for legal certainty? (For NC residents, NC's Identity Theft Protection Act (75-65) triggers notification obligations without unreasonable delay once you have reason to believe PII was accessed.)
  • Who owns the internal all-hands communication? What do we tell staff about their own W-2s if one is in the leak sample?
  • Do we pay? Who decides? Under what conditions? Most SMBs have never had this conversation before it's happening at 3 AM.

Minutes 50-70 — Scenario Stage 4: Recovery

Facilitator reads: “It's Friday, day 4. The forensics vendor says our immutable backups from Sunday night are clean. The MSP estimates 48-72 hours to rebuild. We are not paying.”

Discussion questions:

  • How does the business operate for the next 72 hours? Payroll runs Monday. Can we run it?
  • Who authorizes the rebuild sequence — DCs first, then file server, then endpoints? Or do we lift a specific workflow first?
  • What do we do about credentials? Every password in the environment should be considered compromised. Do we have a plan to force-reset the whole workforce?
  • Who signs off that we're “back to normal” and on what evidence? (Never a vibe check. Should be based on detection telemetry, log continuity, and a written go-live from the forensics vendor.)

Minutes 70-90 — Debrief and action items

  • Walk the notes list. Every gap identified becomes an action item.
  • Each action item gets an owner, a target date, and a way to verify it's done.
  • Book the next tabletop for 6 months out. This is not a once-and-done exercise.

The gaps we always find

Every SMB tabletop we've facilitated in the last year has surfaced at least most of these:

  • Nobody knows the insurance carrier's incident hotline off the top of their head. It's in a folder in Outlook. Outlook is encrypted.
  • No pre-authorized forensics vendor. The policy has an approved-vendor list, but nobody has read it, and picking the wrong vendor voids the claim.
  • The IR plan lists people who left the company 12+ months ago.
  • No documented process for isolating an endpoint. Everyone assumes “the MSP will handle it,” but the MSP requires ticket authorization that nobody knows how to submit.
  • No out-of-band communication plan. Everyone plans to reach each other on Teams or corporate email — both of which will be down.
  • Backup restore is untested. Everyone assumes backups exist. Nobody has restored one in the last 12 months to prove it.
  • No decision framework on ransom payment. The first time this gets discussed should not be during the crisis.

None of these are exotic. Every one of them is the kind of thing that turns a 3-day event into a 3-week event when you find it live.

What WHT recommends

  1. Schedule the first tabletop this quarter. Pick a date. Send the invite. If perfect is the enemy of good, the perfect tabletop is definitely the enemy of the tabletop that actually happens.
  2. Print an out-of-band contact card. Insurance hotline, MSP/MSSP after-hours line, outside counsel, backup key personnel. Laminate it. Put it in the CEO's wallet and the controller's wallet. When Outlook is encrypted, this piece of plastic is the plan.
  3. Test one backup restore per quarter. Not a check. A restore. Actually pull a file off tape or immutable storage into a sandbox and verify it opens.
  4. Write down the ransom-payment decision framework before you need it. Who authorizes, on what evidence, with what insurance-carrier coordination. One page.
  5. Repeat every 6 months. Rotate scenarios: ransomware, BEC/wire fraud, insider threat, cloud tenant compromise. Each scenario finds different gaps.

Want us to facilitate your first tabletop?

We'll run a 90-minute tabletop for your leadership team, produce a written gap-and-action report, and hand you a printable out-of-band contact card. Flat fee, no follow-on obligation.

Book a tabletop See all services →