; ;
Most SMEs have some form of cyber security tooling — but very few have practised what happens when something goes wrong. In a real incident, the technical work matters, but the decisions matter just as much: who leads, when you shut systems down, how you communicate, when you call insurers, and what you tell staff and customers. Under pressure, uncertainty is what causes delays and mistakes.
A tabletop exercise is a simple, structured practice session. No hacking, no “red team”, no drama — just a realistic scenario and a guided conversation that reveals gaps before an attacker does.
What a good SME tabletop exercise covers
1) A realistic scenario
Examples:
• compromised Microsoft 365 account
• ransomware on a key device
• supplier breach affecting your data
• suspicious email leading to payment fraud
2) Roles and responsibilities
• incident lead
• technical lead
• comms lead
• finance/approval authority
• liaison with insurer/legal (if applicable)
3) Decision points
• do we isolate devices?
• do we reset credentials company-wide?
• what is the priority service to restore?
• when do we notify customers/partners?
4) Communications rhythm
Internal updates, leadership updates, and customer messaging approach.
5) Outcomes and actions
The value is the action list:
• policy changes
• access tightening
• backup/restore testing
• comms templates
• training needs
Common mistakes
• inviting too many people (keep it focused)
• no facilitator, so it becomes a debate
• no action list afterwards
• choosing a scenario that’s too extreme to be useful
FAQ
How often should SMEs do tabletop exercises?
At least annually, and after major changes (new systems, office moves, leadership changes).
Do we need to involve the whole company?
No. Start with leadership and the people who would make decisions, then expand later if useful.
If you want to feel more in control of your Cyber Security during an incident, we can run a practical tabletop exercise and turn the outcomes into a clear, prioritised improvement plan.