Services / 06

Tabletop Exercises

Incident response, business continuity and disaster recovery exercises for executives and technical teams, scored against your own plans and run on RiskTrace.

IRBCPDR
Overview

What the practice does.

A plan that has never been exercised is a hypothesis. We design scenarios from your actual environment and threats, run them with the people who would be in the room on the day, and score the response against your own plans and playbooks.

Decisions, gaps and actions are captured as they happen in RiskTrace, so the output is a tracked improvement plan rather than a slide deck nobody opens again.

What you get

Deliverables.

Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.

01

Scenario design from your environment

Ransomware, business email compromise, vendor outage, data breach, insider action or a regional disaster. Built from your systems, suppliers and obligations, with injects timed to test specific decisions.

02

Executive and technical tracks

A board and leadership exercise focused on decisions, communication and legal obligations, and a technical exercise focused on detection, containment and recovery. Run together or separately.

03

Facilitation and scoring

An experienced facilitator runs the exercise. Observers score each phase against your plans and recognised frameworks.

04

After-action report

What worked, what did not, decisions that were slow or missing, and a prioritised action plan with owners and dates.

05

Tracking in RiskTrace

Actions, gaps and plan updates captured in RiskTrace, where you can track completion and show auditors and insurers that exercises happen and lead to change.

How it runs

The four steps, applied.

The method is the same for every practice. This is what each step means here.

01 / SCOPE

Objectives, participants, scenario theme, plans to be tested and the regulatory or contractual drivers, agreed in a planning call and a written exercise plan.

02 / TEST

The exercise itself: a facilitated session of two to four hours with timed injects, and a parallel technical track if required.

03 / VERIFY

Observer scores are reconciled against the plans and the record of the session before anything is written. Participants review the draft findings.

04 / REPORT

After-action report, action plan, updated playbook recommendations, and the exercise record in RiskTrace.

When to call us

The situations this is built for.

Your plan has never been tested

An IR plan, BCP or DR plan exists, on paper. Nobody knows whether the phone tree works or who can authorise a ransom decision.

An insurer, regulator or customer requires exercises

Cyber insurance applications and frameworks such as ISO 27001 and SOC 2 expect regular exercises with evidence.

Leadership has changed

New executives and directors have not been through an incident together. The first time should not be real.

Questions

Asked before most engagements.

How long is an exercise?

Executive exercises run two to three hours. Technical exercises run three to four. Full-day combined exercises are available for mature teams.

Do we need RiskTrace to run an exercise?

No. Exercises are run on RiskTrace and you receive the record and action plan whether or not you continue with the platform. Many clients keep using it to track actions and run their own follow-up exercises.

Can you include our vendors?

Yes. Supplier outages are among the most useful scenarios, and key vendors can join as participants or be simulated by the facilitator.

Request a quote

Tell us what you need tested, assessed or governed.

A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.

Start on Frontier Verify