Tabletop Exercise Scenarios Eight Ready-to-Run Examples
A tabletop exercise scenario is a realistic incident narrative that a facilitator walks a team through, step by step, to test how the organization would actually respond to a cyber attack. No systems are touched and nothing is taken offline: the exercise happens in a conference room, driven by discussion. The scenarios on this page are complete enough to run this quarter, each with an opening situation, timed injects that escalate the pressure, and the discussion questions that expose the gaps in your incident response plan before a real attacker does.
- A scenario is not a script. The narrative starts the conversation; the injects steer it. A good exercise measures decisions, not recitation of the incident response plan.
- Pick the scenario your business would actually face. A medical practice should rehearse a ransomware and HIPAA breach scenario before a nation-state one. A defense subcontractor should rehearse CUI spillage and the 72-hour DFARS reporting clock.
- Compliance frameworks expect this. CMMC and NIST 800-171 control 3.6.3 requires you to test your incident response capability, HIPAA requires security incident procedures, and cyber insurers increasingly ask for exercise evidence at renewal.
- Document everything. The after-action report is the deliverable: findings, decisions, gaps, and assigned corrective actions. An exercise without a written record proves nothing to an assessor.
- Run at least one per year, two if you handle regulated data. Rotate scenarios so the same muscle is not the only one tested.
What Makes a Tabletop Scenario Work
Every effective scenario has the same anatomy, whether it runs for 45 minutes with a leadership team or half a day with technical staff.
Four components do the work. The opening narrative establishes what participants know at minute zero, which is deliberately incomplete, because real incidents never announce themselves clearly. The injects are timed developments the facilitator introduces: a second alert, a ransom note, a journalist's phone call, a regulator's email. Each inject forces a new decision under changed conditions. The discussion questions convert the narrative into findings by asking who decides, who calls whom, and what the plan actually says. The after-action report captures what the exercise revealed and assigns owners and deadlines to every gap.
The facilitator's job is to keep the exercise honest. Participants naturally drift toward describing what should happen; a good facilitator asks what would happen at 2 AM on the Saturday of a holiday weekend when the IT manager is on a plane. That gap, between the documented plan and the real organization, is the entire reason tabletop exercises exist. It is also why our team pairs every scenario below with the specific failure pattern it is designed to surface.
Craig Petronella, MIT-certified cybersecurity professional, NC Licensed Digital Forensics Examiner (License# 604180-DFE), and author of the Amazon best-seller How Hackers Can Crush Your Business, has facilitated exercises drawn from incidents his team investigated forensically. That forensic grounding matters: the injects below mirror how real attacks unfolded, not how vendor marketing imagines them. If you would rather have Petronella Technology Group design and run the exercise for you, our cybersecurity tabletop exercise service handles facilitation, documentation, and the corrective-action roadmap end to end.
Eight Tabletop Exercise Scenarios You Can Run
Each scenario includes the opening narrative, three sample injects, and the discussion questions that separate a checkbox exercise from a useful one. Adapt names, systems, and timing to your environment.
1. Ransomware on a Friday Night
Opening narrative: At 6:40 PM Friday, a warehouse supervisor reports that shipping workstations show a full-screen note demanding payment in cryptocurrency. File shares are opening as gibberish. The IT manager is at a family event two hours away, and the managed backup job last reported success eleven days ago.
Injects: (1) The ransom note names your company and quotes your approximate annual revenue. (2) Your cyber insurance carrier's hotline asks whether you have preserved forensic images before any restoration. (3) Monday at 8 AM, a customer emails asking why their order data appeared on a leak site.
Discussion questions: Who has authority to disconnect production systems tonight, and does that person know it? Do we know, right now, whether our backups are usable and offline? Who is authorized to communicate with the threat actor, the carrier, and customers, and in what order? The preservation inject matters most: restoring systems before imaging them destroys the evidence a digital forensics investigation and an insurance claim both depend on.
2. Business Email Compromise and the Wire That Left
Opening narrative: Your controller receives a vendor email requesting updated banking details for an invoice due this week. The email thread looks continuous and the sender address is correct. The payment, $184,000 in the exercise, is released Tuesday. Thursday, the real vendor calls asking where their money is.
Injects: (1) Review of the mailbox shows a forwarding rule created three weeks ago, sending all invoices to an external address. (2) The bank says recall is possible only within a narrow window and requests a police report and FBI IC3 filing. (3) A second employee reports a similar email that they almost acted on.
Discussion questions: How fast can we get from discovery to bank recall request, in hours? Who owns the IC3 filing and law enforcement contact? What does our wire verification procedure require today, and would it have caught this? Speed is decisive in wire fraud, which is why we built a dedicated business email compromise recovery response. This scenario also tests whether finance and IT have ever practiced working the same incident together.
3. The Departing Employee
Opening narrative: A senior engineer resigns to join a competitor. Two days before their last day, the file server logs show 4,200 documents copied to a personal cloud storage account, including customer lists and proposal pricing. HR has scheduled the exit interview for tomorrow morning.
Injects: (1) Legal asks whether the employee signed a confidentiality agreement and whether the evidence would survive scrutiny in court. (2) The employee's manager admits shared credentials were used on a lab system, muddying attribution. (3) Three weeks later, a customer mentions the competitor quoted a price exactly one percent under yours.
Discussion questions: Do we suspend access before, during, or after the exit interview, and who decides? Is our logging sufficient to prove who took what, or only that something was taken? When does this become a matter for licensed forensic examination rather than internal IT? Chain of custody is the trap here: evidence handled casually by IT staff may be worthless in litigation, which is where a licensed examiner and expert witness changes the outcome.
4. Vendor Compromise Upstream
Opening narrative: Your IT management platform vendor discloses that attackers pushed a malicious update to customers during a two-week window. Your environment installed the update. The vendor's advisory is vague, your monitoring shows nothing unusual, and the story is already on industry news sites.
Injects: (1) The vendor's second advisory narrows the affected versions, and yours is on the list. (2) A customer's security team sends a questionnaire demanding your exposure assessment within five business days. (3) Your endpoint agent flags an outbound connection from one server to an address on the published indicator list.
Discussion questions: Can we produce an inventory of every system running the affected software within one day? Who owns third-party risk communication when the incident is not our fault but is our problem? At what evidence threshold do we treat suspicion as an active incident? This scenario tests asset inventory, threat intelligence intake, and the discipline to investigate quietly before declaring either an all-clear or an emergency.
5. CUI Spillage and the 72-Hour Clock
Opening narrative: Your company machines parts for a defense prime. A project manager discovers that controlled unclassified information, drawings marked with distribution statements, has been sitting in a personal file-sharing account so a supplier could access it faster. The account has been shared with three external email addresses.
Injects: (1) One external address belongs to a former supplier employee who left six months ago. (2) Counsel asks whether this triggers the DFARS 252.204-7012 requirement to report cyber incidents to the Department of Defense within 72 hours, and who at your company has the DIBNet medium assurance certificate needed to file. (3) Your prime's supply chain team calls: they saw unusual sharing activity and want answers before Friday.
Discussion questions: When did the 72-hour clock start, at the event or at discovery? Can we even file a DIBNet report today? What does this do to our SPRS score and our standing with the prime? Defense contractors should run this exercise before an assessor or prime forces the question. Our CMMC incident response domain guide maps exactly what the framework expects, and control 3.6.3 makes testing your incident response capability an explicit requirement, not a suggestion.
6. Cloud Account Takeover
Opening narrative: An accounting employee approves a push notification on their phone at 11 PM, assuming IT was doing maintenance. By morning, attackers have registered their own authenticator device, created an application password, and downloaded the contents of the employee's mailbox and shared drives.
Injects: (1) Sign-in logs show successful authentications from two countries within the same hour, and a rule deleting security alerts from the mailbox. (2) The attacker emails four coworkers from the compromised account requesting gift card purchases, and one complies. (3) Review shows the downloaded shared drive contained employee Social Security numbers, raising state breach notification questions.
Discussion questions: Who can revoke sessions and reset authentication methods, and how fast? Does our alerting catch impossible travel and new-device registration, or did we learn about this from a coworker's suspicion? At what point does counsel determine notification obligations, and to whom? MFA fatigue attacks succeed against tired humans, not weak technology, which is why this scenario pairs naturally with security awareness training and a phishing-resistant authentication roadmap.
7. Ransomware at a Medical Practice
Opening narrative: A multi-provider clinic opens Monday to find its EHR system unreachable and appointment schedules encrypted. Patients are in the waiting room. The practice reverts to paper, but staff cannot see allergies, medication lists, or problem histories for today's patients.
Injects: (1) The EHR vendor confirms the compromise originated from a remote access tool installed for after-hours support. (2) The threat actor posts proof files containing patient records, converting an outage into a likely HIPAA breach with Office for Civil Rights notification obligations. (3) A local television station calls the front desk asking for comment.
Discussion questions: What is our clinical downtime procedure, and has the care team ever practiced it? Who performs the HIPAA breach risk assessment and starts the notification analysis for patients and regulators? Who speaks to media, and what do front desk staff say when the call reaches them first? As Craig Petronella details in How HIPAA Can Crush Your Medical Practice, the compliance failure after the incident frequently costs practices more than the incident itself. Healthcare teams should rehearse this one annually.
8. The Deepfake Executive
Opening narrative: Your CFO receives a video call from what appears to be the CEO, traveling abroad, urgently requesting a confidential acquisition-related transfer. The face is right, the voice is right, and the mannerisms are close. A follow-up email from a lookalike domain arrives with wiring instructions minutes later.
Injects: (1) The CFO transfers a first tranche before growing suspicious of a second, larger request. (2) The real CEO, reached by text on a known number, has no idea what call the CFO is describing. (3) Reviewing recent activity, marketing confirms hours of the CEO's conference talks and podcast interviews are publicly available, ample training data for voice and video cloning.
Discussion questions: Does any payment above a threshold require verification through a second, independent channel, with no exceptions for urgency or seniority? What is our procedure when the person asking you to break procedure appears to be the person who wrote it? How do we brief executives without making them paranoid about legitimate urgent requests? AI-enabled fraud collapses the old advice of trust your eyes and ears; only out-of-band verification procedures survive it.
Arm the Exercise Before You Run It
A tabletop works best when the plan it tests actually exists. Start with our free incident response plan template, then measure your team's phishing exposure to pick your first scenario.
How to Run the Exercise in Six Steps
The mechanics matter as much as the scenario. This is the sequence Petronella Technology Group uses in facilitated engagements, compressed for teams running their own.
Set objectives: pick 3 to 5 specific capabilities to test, not "response" generally
Cast the room: decision-makers and doers, 6 to 12 people, plus a scribe who only records
Brief the rules: no wrong answers, no blame, phones down, the plan may be consulted
Run the narrative: deliver injects on a timer and force decisions before the next one lands
Hot wash: 15 minutes at the end for what worked, what broke, what surprised everyone
After-action report: findings, owners, deadlines, and a date for the retest
Two facilitation rules keep the exercise honest. First, when a participant says "we would call our IT provider," make them name the person and the phone number; if the room cannot, that is a finding. Second, never let the most senior person answer first, because everyone else will agree with them and you will learn nothing. The scribe's raw notes, not anyone's memory, feed the after-action report, and the report is what an assessor, an insurer, or your board will actually ask to see.
Where Tabletop Exercises Are Required
If you operate under a compliance framework, exercising your incident response capability is not optional enrichment. It is a control with an audit trail.
For organizations juggling several of these at once, the ComplianceArmor® platform generates and organizes the documentation layer, so the exercise you ran actually shows up as evidence where each framework expects it, alongside your policies, plans, and assessment records.
Running It Yourself vs. Bringing a Facilitator
The scenarios above are free to use, and a self-run exercise beats no exercise. Here is an honest accounting of the difference.
The facilitator is also a participant
Whoever runs the exercise, usually the IT lead, cannot simultaneously respond as themselves. Their seat, often the most critical one, goes untested.
Injects lose their teeth
Colleagues soften the pressure on each other. The uncomfortable follow-up question, the one that exposes the gap, rarely gets asked across a desk you share every day.
Findings drift into a drawer
Without an external report and a retest date, after-action items compete with daily work and usually lose.
Forensics-informed scenario design
Exercises are shaped by what a licensed digital forensics examiner has actually seen fail during 24+ years of investigations, tuned to your industry and compliance obligations.
Every seat plays
Your whole team responds while we drive the narrative, escalate the injects, and press the questions a colleague will not.
Assessor-ready documentation
You receive a written after-action report mapped to CMMC, HIPAA, or SOC 2 evidence requirements, with corrective actions, owners, and a scheduled retest.
One verified client review captures the standard we hold facilitation to: "Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises." (GB Entrainement, TrustIndex verified review; Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews.)
Tabletop Exercise Questions, Answered
How long should a tabletop exercise take?
Who should be in the room for a tabletop exercise?
How often should we run tabletop exercises?
Do tabletop exercises satisfy CMMC requirement 3.6.3?
What is the difference between a tabletop exercise and a functional exercise?
What makes a good tabletop exercise scenario?
Can a small business run a tabletop exercise without a security team?
Build the Response Capability Behind the Exercise
Find the Gaps Before an Attacker Does
Petronella Technology Group has been securing regulated businesses since 2002 (BBB A+ since 2003, CyberAB RPO #1449). We will design the scenario, run the room, and hand you an assessor-ready after-action report. Call 919-348-4912 or schedule a consultation.
Last Updated: August 25, 2026 · Reviewed by Craig Petronella, CMMC-RP, NC Licensed Digital Forensics Examiner (License# 604180-DFE)