Test Your Plans Before You Need Them

Disaster Recovery & Cyber Incident Tabletop Exercises

Does your disaster recovery plan actually work? What about your incident response runbook? Find out before a real crisis hits. Expert-facilitated tabletop exercises that reveal gaps, test team coordination, and validate your procedures—all in a risk-free environment.

From £550
Transparent Pricing
Half/Full Day
Session Length
UK-Based
Expert Facilitators
Custom
Scenarios

What is a Tabletop Exercise?

A tabletop exercise (TTX) is a discussion-based session where your team walks through a simulated incident to test your response procedures, identify gaps, and practice coordination—without the pressure of a real emergency.

Risk-Free Testing

Practice your response to ransomware, data breaches, or infrastructure failures without actual consequences. Learn what works and what doesn't.

Team Coordination

See how your team actually communicates during a crisis. Identify communication breakdowns before they happen in a real incident.

Expert Facilitation

Led by experienced incident responders who inject realistic complications, ask tough questions, and ensure productive discussions.

Why This Matters

Most disaster recovery and incident response plans have never been tested. When a real incident hits, that's when you discover what doesn't work.

Without Testing

  • Confusion about roles and responsibilities
  • Outdated contact lists and procedures
  • Missing steps in your runbooks
  • Unrealistic recovery time assumptions
  • Panic and poor decisions under pressure

After a Tabletop Exercise

  • Clear understanding of who does what
  • Updated, validated procedures
  • Documented gaps with action plans
  • Realistic understanding of capabilities
  • Team confidence in their response

Did you know? Most organizations discover 5-10 critical gaps in their first tabletop exercise. Better to find them now than during a real incident.

Scenarios We Facilitate

We tailor each exercise to your specific environment, industry, and concerns. Here are the most common scenarios we run:

Ransomware Attack

Your systems are encrypted. Ransom note on screen. What do you do first? Who do you notify? When do you involve law enforcement? Test your incident response.

Data Center / Cloud Outage

Your primary infrastructure is down. How quickly can you failover? Who has access to backups? What about your RTO/RPO? Validate your DR procedures.

Key Personnel Unavailable

Your head of IT is unreachable. The person with the passwords is on holiday. Can your team still respond? Test your documentation and succession plans.

Data Breach / GDPR Incident

Customer data has been exposed. You have 72 hours to notify the ICO. What's your process? Who makes the call? Practice your breach response.

Supply Chain Disruption

A critical vendor has been compromised. Their services are offline. What's your contingency? Test your supplier risk management.

Custom Scenarios

Have a specific concern? We build custom scenarios based on your industry, threat landscape, and unique risks. From phishing to physical security.

How a Tabletop Exercise Works

Our proven four-phase approach ensures productive sessions and actionable outcomes.

1

Pre-Exercise Planning (1-2 weeks before)

We review your existing plans, understand your environment, and design a realistic scenario. We'll work with you to determine objectives, identify participants, and set the scope.

2

The Exercise Session (Half or Full Day)

Your team gathers (in-person or remote). Our facilitator introduces the scenario and injects complications as you work through your response. We observe, document, and guide the discussion—but your team makes the decisions.

3

Debrief & Hot Wash (Immediate)

Right after the exercise, we facilitate a candid discussion about what worked, what didn't, and what surprised people. This is where the real learning happens.

4

After-Action Report (Within 1 week)

We deliver a comprehensive report documenting gaps, recommendations, and a prioritized action plan. Not a novel—practical, actionable findings you can act on immediately.

Who Should Participate?

Tabletop exercises work best with cross-functional participation. Here's who we typically include:

Technical Team

  • • IT Manager / Director
  • • System Administrators
  • • Security Team
  • • DevOps / Infrastructure

Business Leadership

  • • CEO / Managing Director
  • • Operations Manager
  • • Finance / CFO
  • • Department Heads

Supporting Functions

  • • Communications / PR
  • • Legal / Compliance
  • • HR
  • • Customer Success

Typical group size: 6-15 participants. Smaller groups allow everyone to contribute; larger groups benefit from diverse perspectives.

Transparent, Fixed Pricing

No surprises, no hidden fees. You know exactly what you're paying for.

Half-Day Exercise

From £550

+ VAT

  • 2-4 hour facilitated session
  • Pre-exercise planning call
  • Custom scenario development
  • Expert facilitator
  • After-action report
  • Remote or in-person (UK)

Perfect for focused scenario testing

MOST POPULAR

Full-Day Exercise

From £1,250

+ VAT

  • Everything in half-day, plus:
  • 6-8 hour comprehensive session
  • Multiple scenario variations
  • In-depth debrief session
  • Detailed improvement roadmap
  • 90-day follow-up review

Comprehensive testing & team building

Custom Program

Let's Talk

Tailored to your needs

  • Multi-day exercises
  • Multiple scenarios
  • Annual testing programs
  • Board-level exercises
  • Industry-specific scenarios
  • Compliance requirement support

Enterprise & ongoing programs

What's included in all packages:

Pre-planning, custom scenario development, expert facilitation, comprehensive after-action report with prioritized recommendations, and unlimited email support for 30 days post-exercise. Pricing may vary based on group size and complexity—we'll provide a final quote after our planning call.

Book Your Tabletop Exercise

Tell us about your needs and we'll get back to you within 4 hours to discuss scheduling and scenario design.

No obligation · Fast response · Expert facilitators

We'll respond within 4 business hours to discuss your needs and schedule a planning call. No obligation, no sales pressure.

Common Questions

Do we need existing plans to run an exercise?

Not at all. If you don't have documented plans, we can still run a valuable exercise. The exercise will help you understand what plans you need and serve as the foundation for creating them.

How technical does my team need to be?

We tailor the exercise to your team's technical level. The focus is on decision-making and coordination, not technical deep-dives. Everyone participates regardless of technical background.

What's the difference between half-day and full-day?

Half-day focuses on one scenario and core decisions. Full-day allows deeper exploration, multiple scenario variations, more detailed debrief, and includes a follow-up review after 90 days. Full-day is better for comprehensive testing and team development.

Can we do this remotely?

Absolutely. We've facilitated dozens of remote exercises. They work excellently via video conference and actually test your remote coordination capabilities. In-person is also available across the UK.

How often should we run tabletop exercises?

Best practice is annually at minimum. Many organizations run them quarterly or after significant changes (new systems, org changes, etc.). We offer annual programs with recurring exercises.

Will this satisfy compliance requirements?

Yes. Many frameworks (ISO 27001, SOC 2, Cyber Essentials Plus, NIS2) require testing of incident response and business continuity plans. We provide documentation that demonstrates compliance.

Stop hoping your plans work. Test them.

Every organization we work with discovers gaps they didn't know existed. Better to find them in an exercise than during a real ransomware attack at 3am.

Book Your Exercise Ask Us Questions