What is a tabletop exercise?

A tabletop exercise (TTX) is a discussion-based exercise in which key people work through a realistic scenario step by step and talk through how they would respond to an incident or crisis, without touching any systems or plant. A facilitator guides participants through the scenario and introduces new developments along the way, known as injects. This reveals whether the incident response plan actually works, whether everyone knows their role, and where decision making and communication break down. In OT environments, the tabletop exercise is the safest way to rehearse a cyber incident, because the running production environment is never put at risk.


🎯 Why run a tabletop exercise?

A plan that has never been rehearsed is an assumption. A tabletop exercise tests that assumption on four fronts:

  • The plan β€” are the procedures, contact lists and escalation paths in the incident response plan and the continuity plan correct and current?
  • The roles β€” do the operator, the OT engineer and the crisis manager know who takes which decision?
  • Decision making β€” who decides to shut the plant down, cut the link with the office network or switch to manual operation?
  • Communication β€” how do internal alerting, notification to the regulator and the crisis communication plan actually run under pressure?

There is also a learning effect. Participants from IT and OT get to know each other’s language, priorities and constraints before a real crisis forces them to cooperate.


πŸ”„ How does a tabletop exercise differ from other exercise types?

FEMA’s Homeland Security Exercise and Evaluation Program (HSEEP) in the US distinguishes discussion-based exercises from operations-based exercises. NIST SP 800-84, published in 2006, takes the same line for IT plans: a tabletop exercise deploys no equipment, while in a functional exercise participants perform their duties in a simulated operational environment. The tabletop exercise is the best-known form in the first group.

Type Category What happens? Effort Risk to OT
Tabletop exercise Discussion-based Scenario discussed around a table, no systems touched Low (a few hours) None
Drill Operations-based One procedure actually performed, such as a restore test Medium Low, if done in a test environment
Functional exercise Operations-based Teams perform their duties in a simulated environment High Low to medium
Full-scale exercise Operations-based Several organisations, real resources and staff Very high Medium, needs strict boundaries

Related technical exercises such as threat simulations and purple teaming mainly test detection. A tabletop exercise focuses on people, processes and decisions.


🏭 Which OT scenarios suit a tabletop exercise?

A good scenario is plausible, hits the core of the business and forces difficult choices. Five scenarios recur in industrial exercises:

Scenario Key question for participants
Ransomware spreading from IT to OT When do we cut the IT/OT link, and can we keep running without office systems?
Compromised vendor remote access How do we shut down remote access and who calls the supplier?
Manipulated setpoints How do operators notice that process settings have changed, and which values can be trusted?
Loss of view / loss of control Can we operate safely without the HMI, or must we shut down in a controlled way?
Unexpected SIS trip Is it a fault or an attack, and may the plant be restarted?

The ransomware scenario draws on incidents such as Colonial Pipeline in May 2021, where an attack on the business network led the operator to halt the pipeline as a precaution. Loss of control occurred in Ukraine in December 2015, when attackers took over operator workstations of regional distribution companies and more than 200,000 customers lost power.


🧱 Who takes part in a tabletop exercise?

An OT exercise only works if every discipline needed during a real incident has a seat at the table:

  • OT engineers and operators β€” know the process, the safety limits and the options for manual operation
  • IT and the SOC β€” detection, analysis, isolation and recovery of systems
  • Management and the crisis team β€” decide on shutdown, cost and priorities
  • Communications β€” internal messaging, press and customers
  • Legal and compliance β€” reporting obligations, liability and contact with the regulator
  • Vendors and system integrators β€” knowledge of the control system and contractual support arrangements

Besides the players, there is a facilitator, who steers the scenario, and observers, who record what goes well and where things get stuck.


πŸ› οΈ How do you organise a tabletop exercise step by step?

  1. Set objectives β€” choose three to five measurable objectives, for example β€œdecide within 30 minutes whether to disconnect the IT/OT link”.
  2. Write the scenario β€” base it on your own risk assessment and architecture rather than a generic story.
  3. Develop injects β€” plan new information for each phase: an alarm, a ransom note, a journalist on the phone, a vendor who cannot be reached.
  4. Appoint a facilitator and observers β€” a neutral facilitator keeps pace and focus; observers take notes using a fixed form.
  5. Run the exercise β€” allow two to four hours and create a safe atmosphere where mistakes are allowed.
  6. Hold a hot wash debrief β€” straight after the exercise, participants discuss what went well and what could improve while impressions are fresh.
  7. Write an after-action report β€” record strengths, weaknesses and findings per objective.
  8. Draw up an improvement plan β€” every finding gets an action, an owner and a deadline, and the next exercise checks whether the improvement works.

Free starter material is available from CISA, whose CISA Tabletop Exercise Packages (CTEPs) offer more than a hundred customisable packages, including scenarios for ransomware, insider threats and compromise of industrial control systems. Each package contains template objectives, scenarios and discussion questions, plus templates for invitations, feedback forms and the after-action report.


πŸ” What role does the tabletop exercise play in the Cbw and IEC 62443?

Under the Dutch Cybersecurity Act (Cbw), the national transposition of NIS2, exercising is no longer an optional good habit. Article 9 of the Cybersecurity Decree requires entities to test their business continuity plan and recovery plan periodically, and to periodically test and exercise their crisis management plan. Article 18 also requires a periodic, documented evaluation of the effectiveness of the measures taken. A tabletop exercise with an after-action report delivers exactly that evidence.

A good scenario also rehearses incident reporting: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. That clock is easily forgotten in the heat of an incident.

IEC 62443-2-1, restructured into security program elements in its second edition of August 2024, covers incident handling in SPE 7 (event and incident management) and recovery in SPE 8 (system integrity and availability). Exercises are a common way for asset owners to demonstrate that these processes work in practice.

In the Netherlands, the NCSC and the NCTV also organise the national cyber exercise ISIDOOR. ISIDOOR IV, held from 13 to 15 November 2023, involved more than 3,000 participants from 120 organisations; the next edition is planned for the end of 2027 at the earliest.


⚠️ What are the common pitfalls?

  • Only IT at the table β€” without operators, physical consequences and process safety stay out of sight.
  • An over-optimistic scenario β€” if everything goes to plan, nobody learns anything.
  • No follow-up β€” an exercise without an improvement plan and named owners is just a pleasant afternoon.
  • Too technical β€” a tabletop exercise is about decisions, not forensic detail.
  • Too infrequent β€” a common minimum is one exercise per year, plus an extra one after major changes to the organisation or architecture.

❓ Frequently asked questions

What is the difference between a tabletop exercise and a simulation?

A tabletop exercise is a discussion around a table in which participants talk through how they would respond to a scenario, without touching any systems. A simulation or functional exercise has teams actually perform their tasks in a simulated environment. The tabletop exercise is cheaper and safer for OT, but it does not test technical execution.

How long does a tabletop exercise take?

A tabletop exercise usually lasts two to four hours, including a short hot wash immediately afterwards. Preparation of objectives, scenario and injects typically takes several weeks. The after-action report and improvement plan follow in the weeks after the exercise.

How often should you run a tabletop exercise?

The Dutch Cybersecurity Decree requires the crisis management plan to be tested and exercised periodically, without setting a fixed interval. In practice, at least one tabletop exercise per year is the common baseline. After major changes, such as a new OT architecture or a reorganisation, an additional tabletop exercise is advisable.

Is a tabletop exercise mandatory under NIS2 and the Cybersecurity Act?

The Dutch Cybersecurity Act does not name the tabletop exercise explicitly, but the Cybersecurity Decree obliges entities to test their continuity, recovery and crisis plans periodically. A tabletop exercise with a written after-action report is one of the simplest ways to demonstrate that. It can also help meet the evaluation duty in Article 18.

Where can you find free tabletop exercise scenarios?

CISA offers more than a hundred free, customisable CISA Tabletop Exercise Packages, including scenarios for ransomware and attacks on industrial control systems. Each package includes objectives, a scenario, discussion questions and templates. For an OT tabletop exercise, adapt the scenario to your own plant and processes.

What is an inject in a tabletop exercise?

An inject is a new development that the facilitator introduces during a tabletop exercise, such as an alarm, a ransom note or a call from the press. Injects keep the scenario realistic and force participants into new decisions. They are planned in advance for each phase of the incident.


πŸ“Œ In summary

A tabletop exercise lets IT, OT and management work through a realistic cyber incident around a table, exposing gaps in plans, roles and decision making before a real attack hits production. With clear objectives, OT-specific injects, a hot wash and an improvement plan with named owners, the exercise also becomes evidence for the testing and evaluation duties of the Cybersecurity Decree, and strengthens business continuity and incident response.