Cybersecurity Tabletop Exercises

Incident rehearsals built from real attack paths, run for executives and technical teams, and scored so every gap leaves with an owner and a date.
Contact us
Definition

What is a cybersecurity tabletop exercise?

A tabletop exercise is a facilitated rehearsal of a security incident. The team works through a realistic scenario, ransomware on a domain controller or a compromised vendor account, and makes the same decisions a real event would demand, at a table instead of at 2 a.m. The output is a decision log, a gaps register, and updated runbooks. SOC 2, ISO 27001, and HIPAA all expect incident response testing, and a well-run tabletop satisfies that requirement while actually improving the response.

Services

What do our tabletop exercises cover?

Ransomware scenarios
Business email compromise
Vendor compromise
Executive track
Technical track
Compliance evidence

Ransomware tabletop exercises

Encryption plus exfiltration, modeled on how ransomware operators actually move: initial access, privilege escalation, backup destruction, then the ransom note. The exercise forces the decisions that matter: isolate or watch, restore or negotiate, who calls the insurer, and what you tell customers on day one.

Business email compromise

A finance-team mailbox falls, payment instructions change, and money moves. The scenario tests wire recall windows, mailbox rule forensics, bank and law enforcement contacts, and the difficult customer call, against a clock measured in hours.

Vendor and supply chain compromise

Your SSO provider, MSP, or a critical SaaS vendor is breached. The exercise tests how fast you can answer the questions that follow: what data the vendor held, which integrations to sever, what your contracts require, and when your own customers must hear from you.

Executive track

Built for the CEO, CFO, general counsel, and communications lead. It tests decision authority, disclosure obligations, insurer and counsel engagement, and holding statements, in scenarios where legal and commercial pressures pull in different directions.

Technical track

Built for responders and infrastructure owners. It tests containment choices, forensic preservation, recovery order, and the moments where the runbook says one thing and the environment allows another.

Compliance evidence

SOC 2 CC7.4 and CC7.5, ISO 27001 Annex A 5.24 through 5.27, and HIPAA 164.308(a)(6) all expect tested incident procedures. The exercise produces dated evidence: agenda, attendance, scenario, decision log, and the corrective actions that followed.

Our approach

Our approach

01

Pick the decisions to test

The sponsor names the calls that worry them, whether to pay or restore, disclose or wait, sever or monitor, and the scenario is built to force exactly those decisions.

02

Design from your environment

Injects reference your actual identity provider, backup architecture, and vendor list, because the gaps live in the specifics.

03

Set tracks and roles

Executive and technical tracks, a facilitator, a scribe for the decision log, and observers who stay silent until the debrief.

04

Run with timed injects

Two to four hours per session. Pressure escalates on a clock, and the facilitator pushes on the decisions the sponsor flagged.

contact us

When did your team last rehearse an incident?

Speak with BD Emerson about scenarios, tracks, and a cadence that fits your audit calendar.

Our Advantage

Why BD Emerson for tabletop exercises

Facilitators from live response

The people who write your injects handle real incidents. Scenarios reflect how attacks actually unfold, including the parts that never make the news.

Auditor-grade artifacts

Decision logs, registers, and redlines are dated, attributed, and formatted the way assessors expect incident response testing to be evidenced.

Executive fluency

Facilitation that works in a boardroom: disclosure clocks, insurer dynamics, and counsel coordination, in plain language a director can act on.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What is a tabletop exercise in cybersecurity?

How long does a tabletop exercise take?

Who should attend a tabletop exercise?

Which scenario should we run first?

Does a tabletop satisfy SOC 2, ISO 27001, or HIPAA testing requirements?

How often should we run tabletop exercises?

What do we receive afterward?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners