Loading...
Loading...
Learn from incident response experts how to run tabletop exercises that actually improve your security posture.
Create a safe environment where participants can learn without fear of judgment or repercussions.
Use scenarios based on actual threats your organization faces, not generic templates.
Capture decisions, gaps, and insights in real-time. The debrief is only as good as your notes.
Identify action items during the exercise, assign owners, and track completion. Don't let insights go to waste.
Set your exercise up for success before you even start
How to run the exercise effectively
Instead of "Would you call the CISO?", ask "Who needs to be notified and when?"
Give people time to think. Don't fill every pause. Silence drives better discussions.
If someone says "We'd restore from backup," ask "How long would that take? Who has access?"
When discussions drift to "we should buy tool X," note it but return to the scenario.
Have a dedicated scribe capturing decisions, gaps, and action items in real-time.
Focus on process and procedure gaps, not individual performance.
Capture learnings and drive improvement
Immediately after the exercise, discuss what happened while it's fresh
What was unclear? What procedures broke down? What tools were missing?
Create specific action items with owners and deadlines
Follow up on action items. Re-test areas where gaps were found.
Running an exercise, identifying gaps, and then... doing nothing about them. The exercise only has value if you act on the findings.
Before ending the debrief, assign every gap or improvement area to a specific owner with a deadline. Schedule a follow-up meeting to review progress.
Read our comprehensive blog posts for more detailed best practices
Complete step-by-step guide to planning, executing, and analyzing tabletop exercises
Learn how to design realistic, engaging scenarios that test the right capabilities
Latest best practices for incident response planning and execution
Specific guidance for ransomware scenarios with decision frameworks
Different testing methodologies and when to use each approach
Understanding and implementing the NIST IR framework
Breakpoint makes it easy to implement these best practices with built-in templates, AI-powered recommendations, and automated documentation.