ForgeAwareness
← Back to shop

Cyber Tabletop Exercise Kit

10 ready-to-run cyber incident tabletop exercises for security teams, executives, and boards. Each scenario includes facilitator script, staged discussion prompts, common failure modes, and after-action template.

Section 1 of 13~5 min read
Download raw ↗

Cyber Tabletop Exercise Kit

10 ready-to-run cyber incident tabletop exercises for security teams, executives, and boards. Each scenario includes facilitator script, discussion prompts, common failure modes, and after-action templates.


What's in the kit

FileScenarioAudienceDuration
01-ransomware-vendor.mdRansomware on a critical SaaS vendorExec/Board45–60 min
02-insider-exfiltration.mdInsider data exfiltration discovered post-departureExec45 min
03-deepfake-wire-fraud.mdAI deepfake wire fraud against financeFinance + Exec30–45 min
04-nation-state-vendor.mdSlow-burn nation-state compromise via vendorCISO + Board60 min
05-sec-disclosure-clock.mdSEC 4-day materiality decision under pressureExec + Legal45 min
06-bec-cfo-impersonation.mdCFO impersonation BEC during M&AFinance team30 min
07-ransomware-pay-decision.mdActive ransomware: pay-or-not decisionCISO + Board + Legal60 min
08-public-cloud-breach.mdCloud bucket exposure + customer dataEng + Comms + CISO45 min
09-ai-prompt-injection.mdAI assistant exploited by prompt injectionCISO + Eng45 min
10-supply-chain-dependency.mdMalicious dependency in production codeEngineering + CISO45 min

Plus:

  • 00-Facilitator-Guide.md — How to run any tabletop well
  • 99-After-Action-Template.md — Documentation template for every scenario

How to use this kit

Quarterly cadence (recommended)

Pick one scenario per quarter. Rotate through 4 different scenarios per year. Track decisions made, gaps found, and follow-up actions.

Annual minimum

If you can only do one tabletop per year, pick scenario #1 (Ransomware on Vendor) — most universal, most recognizable, most useful for boards. SEC Item 106 increasingly cites tabletop participation as evidence of board oversight.

Pre-incident readiness

Each scenario surfaces decisions you'd otherwise make in pressure. Practice produces better real decisions.


What every tabletop should produce

After each exercise:

  1. Decisions captured — what the team decided, what they deferred
  2. Gaps surfaced — what wasn't ready, what was unclear
  3. Action items — with owners and dates
  4. Updated IR plan — incorporating lessons

The 99-After-Action-Template.md provides this structure.


Licensing

Single-organization license. Modify scenarios freely with your company specifics. Tokenize with {{company}}, {{team}}, etc. for consistency. Don't redistribute externally.