Cyber security incidents can happen to any size of organisation and That’s why being ready is a key part of risk management. Tabletop exercises cyber security are an activity involving a simulated cyber security incident conducted in a topical discussion based environment, in which a team responses to an event, diverging from the actual live systems/ attack. Participants sound out a scenario and discuss working through it.
A table-top exercise generally starts by choosing an appropriate scenario such as ransomware, a compromised account in connection with a phishing scam, data leakage, insider threat or some other disruption of critical systems. The scenario should be based on the operational environment of the organization and the cybersecurity risks it faces. A tabletop exercise can be comprehensive and involve staff from information technology, information assurance/cybersecurity management legal communication human resource and other departments.
One of the primary aims of a tabletop exercise that involves cyber security is definition of roles and responsibilities. During an incident, questions of who should be making decisions and talking to customers or other stakeholders can result in valuable time being lost. A tabletop exercise gives a forum for staff to review protocols and clarify roles and responsibilities.
Communication is also essential. They could talk about what the report of an incident should include, who should be notified, what information should be included and how the internal and external communications should be handle. This could identify missing entries in the contact lists, escalation procedures, communication channels, decision-making processes, etc.
Tabletop exercises are useful means of testing incident response plans. Workshops might reveal, for instance, that some plans were out of date, difficult to understand, or hard to implement in an actual incident. An organisation might realize, for example, that there are problems with access to backup systems, reporting an incident to authorities, working with third-party suppliers, compliance with regulation, or the continuity of business plans.
Such information should be recorded for future revision of response plans. The exercise is facilitated by a participant who will introduce the scenario and provide additional information as the exercise progresses. Participants are asked to clarify what they would do and why.
The “exercise” is not mainly to prove individuals’ performance but it is mainly for experienced teams and processes to investigate a integrated approach of teamsmanship in the simulated incident scenario. An examination or debrief can take place after the exercise. Participants can go over what went right, where they were unsure and what steps to take next.
The results can then be entered into an action plan with task assignments and deadlines. Tabletop exercises in cyber security can be beneficial to an organization by providing a reality check before a cyber security event occurs. With real-life scenarios, increased inter-departmental communication, hands-on review of response plans, and documentation of lessons learned, organizations can look at areas of weaknesses, practice coordination of responses, and then improve their overall incident response capabilities.