A tabletop exercise reveals gaps before a real incident hits. Here’s how SMEs run a simple ransomware/compromise scenario: roles, decisions, comms, and recovery.
Cyber Incident Tabletop Exercises for SMEs: The 90-Minute Session That Saves You in a Real Crisis
Most SMEs don’t fail during a cyber incident because they lack tools — they fail because they haven’t rehearsed decisions. Who shuts systems down? Who speaks to staff? Who calls the insurer? What do you tell customers? What’s the threshold for involving legal support? In the moment, uncertainty costs time, and time costs money. A tabletop exercise is a simple way to pressure-test your plan without any real downtime.
A tabletop isn’t a technical penetration test. It’s a structured conversation that walks through a realistic scenario (ransomware, email compromise, supplier breach, lost device) and forces clarity on roles, priorities, and communication. The best part is that it quickly reveals the “unknown unknowns” — missing contacts, unclear ownership, lack of restore confidence, or assumptions that don’t hold up.
Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester. In practice, a 60–90 minute tabletop session often produces a short, high-impact improvement list that meaningfully reduces risk.
In plain English: a tabletop exercise is a rehearsal where your team talks through a cyber incident step-by-step so you’re not making it up under pressure.
A simple 90-minute tabletop structure (SME-friendly)
1) Pick one scenario
Good starting points:
- ransomware on a key workstation
- compromised Microsoft 365 account
- supplier platform outage or breach
2) Define roles (before you start)
At minimum:
- incident lead (decision maker)
- IT lead (technical actions)
- comms lead (internal/external messaging)
- finance/ops (business impact and approvals)
3) Walk through the first hour
This is where most SMEs discover gaps:
- how do you confirm what’s happening?
- what do you isolate first?
- what evidence do you preserve?
- who do you notify?
4) Walk through the first day
- what systems must be restored first?
- what’s your plan if email is unavailable?
- what’s the customer communication approach?
5) Capture actions and owners
The output should be a short list:
- what to fix
- who owns it
- by when
- what “done” looks like
The most common gaps tabletop exercises reveal
- no clear incident leader
- missing insurer / legal / supplier contacts
- uncertainty about backups and restore time
- no alternative comms plan if email is compromised
- unclear decision thresholds (when to shut down, when to notify)
FAQ
Do we need a full incident response plan first?
No. A tabletop can help you build one quickly by exposing what’s missing.
How often should SMEs run a tabletop?
Annually is a good baseline, and after major changes (new systems, rapid growth, new suppliers).
Is this the same as Cyber Essentials Plus?
Not exactly, but it supports stronger operational security and resilience.
If you want a calm, practical incident plan instead of a document nobody reads, we can run a tabletop session with your leadership team and turn the output into a clear action list.
Get In Touch with us.