The best tabletop exercise is not the most dramatic. It is the one that exposes a decision your team assumed somebody else would make.

Test the operating system around the technology

A tabletop exercise is a guided discussion, not a live penetration test. Participants respond to a plausible scenario and examine how the organization would detect, decide, communicate, contain, continue, and recover.

Keep the scenario close to reality: a compromised account, unavailable collaboration platform, disrupted location, or suspicious vendor request. The purpose is to find ambiguity safely, not to grade individuals.

Use decision points, not plot twists

Give the group one new fact at a time. Ask what they know, what they need to know, who has authority, who must be notified, and what service must continue. Capture unanswered questions and conflicting assumptions in plain language.

  • Who can isolate a system or suspend an account?
  • Where are current provider and insurance contacts stored?
  • Which manual workaround is actually usable?
  • Who approves employee, customer, legal, or public communication?
  • What evidence is needed before restoration?

End with owners and dates

A long list of observations is not a plan. Convert the most important gaps into a short register with an owner, next action, dependency, and review date. Separate procedural gaps from technical controls and contract or provider questions.

No exercise, assessment, or product guarantees security or compliance. Used well, the exercise helps an organization understand its current readiness and prioritize practical improvements.

Talk through your situation

Every environment, contract, team, risk profile, and business priority is different. AMD can help clarify requirements, compare options, coordinate providers, and define a practical next step without forcing a predetermined product.