How to Run Your First Tabletop Exercise: An SMB Walkthrough
How to Run Your First Tabletop Exercise: An SMB Walkthrough
Incident response plans fail on the first real incident because they were never rehearsed. A tabletop exercise is the rehearsal — 90 minutes, a room, and a scenario. ISO 27001:2022 expects exactly this practice, and an SMB can run its first one this month.
ISO/IEC 27001:2022 Annex A treats incident response as four controls that only work if they are exercised together. A.5.24 requires planning and preparation — defined processes, roles, responsibilities. A.5.25 requires assessing events and deciding whether they are incidents. A.5.26 requires responding per documented procedures. A.5.27 requires learning from incidents to strengthen controls. A binder that has never been opened under pressure satisfies none of these. A tabletop exercise tests all four in a single sitting, and it is the cheapest evidence you can produce that your incident response is real.
This article walks a one- to three-person IT team through running its first tabletop, with a ready-to-use ransomware scenario.
What a tabletop is — and is not
A tabletop is a discussion-driven simulation. There is no live system to fix, no packet to capture, no real recovery. The participants sit around a table (or a call), the facilitator reads a scenario in stages, and the team talks through what each person would do at each step. The output is gaps — places where the plan is silent, the contact is wrong, or the decision is unclear.
It is not a technical drill, a penetration test, or a red-team engagement. Those test the controls. A tabletop tests the plan and the people. Run the tabletop first; it is faster, cheaper, and surfaces the gaps that make a technical drill worthwhile later.
Who is in the room
For an SMB, four to six people:
- The facilitator — runs the scenario, asks questions, takes notes. Often the IT lead, though an outside facilitator adds objectivity.
- The incident lead — whoever would coordinate the response (usually the IT lead if not facilitating).
- The business owner — makes the risk-acceptance and communications decisions.
- A user representative — someone from operations who can speak to how the business actually runs.
- Optional: a representative from legal/PR if the organization has them, and the backup IT person.
Keep it small. More than six people turns a discussion into a meeting.
The scenario: ransomware on the file server
Use this scenario for the first exercise. It is common, concrete, and exercises the full A.5.24–A.5.27 chain.
Stage 1 — Detection (Tuesday 09:15). A user reports that files on the shared drive have odd extensions and will not open. Two more users report the same within ten minutes. The facilitator asks: Who does the user call? Where is that written down? How is the event logged? This tests A.5.25 (assessment and decision) — the path from event to "this is an incident."
Stage 2 — Assessment (09:30). The IT lead suspects ransomware. The facilitator asks: What confirms it? Who declares an incident? Is there a threshold? This tests whether A.5.25 has a defined decision point or whether "we’d know it when we see it" is the real policy.
Stage 3 — Containment (09:45). The ransomware is confirmed on the file server and may be spreading. The facilitator asks: What is disconnected first? Who has the authority to take the file server offline? Are backups isolated from the network? This tests A.5.26 (response per documented procedures) — and usually surfaces that the isolation step is documented but the authority to act is not.
Stage 4 — Communications (10:15). Customers may be affected; the owner needs to decide on notification. The facilitator asks: Who notifies customers? What is the message? Is there a regulatory clock (breach notification)? Who speaks to the press if called? This tests the communications plan, which is the most common gap.
Stage 5 — Recovery (10:30). The backup is clean, dated last night. The facilitator asks: Has the backup restore ever been tested? How long does a full restore take? Where is the recovery priority list — what comes back first? This tests whether A.5.26 includes a tested recovery path.
Stage 6 — Learning (10:45). The incident is closed. The facilitator asks: What did we learn? What control or plan changes? Who writes it up and by when? This is A.5.27 — and the answer is usually "we should do that," which is the gap the exercise was meant to find.
Running it: ground rules
- No fixing in the room. If someone spots a real gap mid-exercise, note it for the action list; do not pause to fix it.
- Write everything down. The notes are the evidence for A.5.24 (planning and preparation) and A.5.27 (learning). Date them, name the participants, keep them.
- Time-box each stage to 15 minutes. Pushing past that turns discussion into debate.
- The facilitator plays adversary lightly. Add a complication per stage ("the backup admin is on vacation") to test depth, but do not invent chaos the team cannot handle.
The output: an action list, not a pass/fail
A tabletop produces a list of gaps and owners. Typical first-exercise findings for an SMB:
- The reporting phone number is in the policy but not on a sticker or a contacts card.
- No one has explicit authority to take the file server offline during business hours.
- The backup restore has never been timed.
- The customer-notification message does not exist as a template.
- There is no breach-notification clock documented for the applicable regulation.
Each gap becomes an action with an owner and a date. That action list, with the exercise notes, is your A.5.24 evidence and the input to A.5.27 learning. Schedule the next exercise in six to twelve months, and track the actions to closure in between.
How this fits the series
A tabletop exercises the incident controls you recorded in your Statement of Applicability and the risks you scored in your risk assessment. It is also a checkpoint in the getting-started checklist — run one in the first year of the ISMS. If your top risk is ransomware, the patch cadence and the backup control are the two most-tested controls in the scenario.
What to do next
Schedule 90 minutes in the next two weeks, invite the four people above, and run the ransomware scenario exactly as written. Do not wait for the plan to be "finished" — the exercise is what finishes it. Bring the gap list to your next internal audit so the auditor can verify the actions closed.
Want a facilitator who has run SMB incident exercises before? Book a 30-min ISO 27001 readiness assessment — we facilitate your first tabletop, capture the gap list against A.5.24–A.5.27, and hand you the action items with owners. Bilingual EN/FR, no obligation. → /iso-27001-assessment/
Get Your Free Security Readiness Assessment
Map your controls, identify compliance gaps, and secure your systems before the audit.