Table-top exercise
Also known as: tabletop exercise, TTX
A practice session around a table where a team talks through a made-up crisis step by step to test its plans.
Draft - this entry has not been reviewed yet.
Formal
A discussion-based exercise in which an exercise leader feeds a fictional incident, stage by stage, to the people named in the plans, who state their decisions so gaps in roles and procedures show up without touching live systems.
In plain English
Like a football team walking through a set play on a board before trying it on the pitch.
In practice
A municipality's leadership team spends two hours on a scenario in which a ransom note has appeared on every screen; halfway through they discover nobody knows who may contact the police.
Why it matters
A plan that has never been practised usually fails on the first real day, and finding the flaws in a meeting room is cheap.
Technical deep dive
NIST SP 800-84 (2006), the guide to test, training and exercise programmes for IT plans, distinguishes tabletop exercises, which are discussion-based and conducted in a classroom setting, from functional exercises, in which participants perform their duties in a simulated operational environment. The US Homeland Security Exercise and Evaluation Program (HSEEP) uses the same split between discussion-based exercises (seminars, workshops, tabletop exercises and games) and operations-based exercises (drills, functional and full-scale exercises), and recommends progressing from the former to the latter as plans mature. ISO 22301:2019 clause 8.5 requires an exercise programme, and ISO 22398 gives guidelines for exercises.
A table-top exercise is built around a scenario and a master scenario events list (MSEL): a timed sequence of injects, each a piece of new information such as an alert from the SOC, a call from a journalist, a ransom note, a regulator's question or the discovery that backups are encrypted. The facilitator releases injects in stages, often compressing hours or days into minutes, and asks participants what they know, what they decide, who they inform and what they need. Objectives are defined beforehand and tied to specific plan elements, for example testing whether the 24-hour NIS2 early warning can be issued, whether decision authority for disconnecting from the internet is clear, or whether the communication plan works without email.
Roles are separated. The facilitator steers the discussion and keeps the scenario credible; evaluators or observers record gaps against the objectives; a scribe keeps a timeline; and players act in their real roles, ideally with deputies participating so that the plan is not tested only with the most experienced people. Scenarios should be plausible for the organisation, drawing on current threat assessments, and should contain deliberate complications rather than a smooth path. Sessions for executive groups are usually kept to a few hours.
The exercise ends with an immediate hot wash, where participants share impressions while fresh, followed by an after-action report and improvement plan that assigns owners and deadlines, which feeds the same corrective-action tracking as incident lessons learned. Table-top exercises do not test technical capability: they cannot show that a backup restores within its RTO, which requires a functional test. National and EU-level exercises such as ENISA's Cyber Europe series apply the same method at the scale of sectors and countries.
What to learn first
Everything this builds on, foundations first.
Relationships
- Causes
- Lessons learned
Sources & further reading
Standards & official texts
- NIST SP 800-84
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…