The challenge behind the engagement.
Executive tabletops test the decisions only leadership can make: declaring an incident, engaging counsel and the forensic retainer, setting ransom posture, continuity choices, and what to tell customers, regulators, and the board. We pick a scenario from your exposure: ransomware with data theft, business email compromise and wire fraud, or cloud account compromise. The scenario runs in three to five modules with timed prompts: encryption found, an extortion note with proof of stolen data, a journalist inquiry, a slipping recovery estimate. In a discussion-based session without keyboards, the CEO, general counsel, CFO, CISO, communications, and HR work each prompt while we record decisions and gaps. You receive an after-action report and improvement plan plus redlines to the plan and templates. We frame the decisions; counsel decides on notification and materiality.
For executive teams and boards of companies that hold regulated data or carry public disclosure duties, and for leaders who signed a plan they have never had to use. Typical triggers: a board or audit committee request, a cyber insurance renewal, a peer’s public breach, or a new securities, financial regulator, or defense contract obligation.
What we do.
What you can use.
Set objectives with counsel and sponsor
We agree three to five objectives written as observable decisions, for example leadership decides whether a public securities disclosure is required and documents its materiality reasoning. We confirm attendees, invite counsel and your broker or breach coach, and agree that no real customer or employee data is used and who receives the report.
Write the scenario and timed injects
The scenario is built from your exposure: regulators, customer contracts, cloud footprint, and payment flows. Injects arrive on a clock and force re-decisions: sanctions screening before any payment discussion, the short-fuse regulator filing that follows an extortion payment where it applies, and holding statements. Later injects add law-enforcement contact and a board update with incomplete facts.
Facilitate, hot wash, and report
The principal facilitates a two to four hour discussion with no keyboards, ending in a hot wash where participants name what surprised them. Afterward you receive the after-action report and improvement plan, redlines to the plan and communications templates, and a board-ready summary of what was exercised and what changes next.
Who it’s for.
When you need it.
- Executive teams and boards at companies holding regulated data or public disclosure duties
- Leaders who approved an incident response plan they have never had to use
- Organizations where legal, communications, and finance have never rehearsed a crisis together
- Public companies weighing materiality and Form 8-K timing under real time pressure
- A board or audit committee asks whether leadership can actually handle a breach
- An insurance renewal or customer due-diligence review expects evidence of exercises
- A competitor or peer suffers a public breach that draws executive attention
- A newly applicable SEC, NYDFS, or state disclosure duty raises the stakes
What the scope can include.
- 01
Scenario selection from your actual exposure: ransomware with data theft, business email compromise and wire fraud, cloud account compromise, or vendor breach
- 02
Scenario script with three to five modules, timed injects, facilitator guide, and an evaluator sheet per objective
- 03
Decision points on activation, severity declaration, and engaging the breach coach and forensic retainer through counsel
- 04
Ransom posture, including sanctions screening and any extortion-payment filing your regulators require
- 05
Notification determinations, clock owners, holding statements, spokesperson, and customer and contract notices
- 06
Continuity choices on which systems come back first, board communication, and the securities materiality and disclosure process for public companies
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One 2-hour session for 5–8 leaders, standard scenario tailored to your business, held remotely
About 20–30 hoursHalf-day session for 8–15 leaders, custom scenario with legal, insurer, and customer-notice decisions, held on-site
About 36–50 hoursHalf-day or longer with the board or several business units, multi-state or public-company disclosure decisions
About 56–80 hours- Session length and number of participants
- How custom the scenario is (standard template vs. built from your regulators, contracts, and systems)
- Number of regulators and disclosure rules the exercise has to cover
- On-site delivery and travel vs. remote
2–4 weeks from kickoff to session, with the after-action report delivered 1–2 weeks after
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Scenario script, inject timeline, facilitator guide, and participant handout, reusable for the next exercise
- Hot-wash notes and an After-Action Report and Improvement Plan with strengths, gaps, root causes, and owned corrective actions
- Redlines to the plan, notification decision tree, and communications templates
- Board-ready summary of what was exercised and what changes next
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Will this exercise embarrass our leadership team?
No. The exercise is discussion-based and runs under the rule that findings concern decisions and information flow, not individuals. Nobody is graded and nothing is executed. The report records where a decision stalled because the plan did not say who owned it, where information never reached the person who needed it, and where a template was missing. Those are fixes to documents and roles. You decide who attends, what is recorded, and who receives the After-Action Report before we write a word of the scenario.
Should our lawyer and insurance broker attend?
Yes, if at all possible. Counsel learns whether they want the forensic firm engaged through them under a separate letter, since courts have declined to protect breach investigation reports in several cases decided since 2020. Your broker or breach coach confirms whether your preferred forensic firm is on the carrier’s panel and whether the policy requires prior consent before you retain anyone. Both questions are cheaper to answer in a tabletop than on the first day of an incident. We frame the decision; counsel and the carrier make it.
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
- NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
- NIST SP 800-184: Guide for Cybersecurity Event Recovery
- CISA Tabletop Exercise Packages
- #StopRansomware Guide
- Homeland Security Exercise and Evaluation Program (HSEEP)
- Technical Approaches to Uncovering and Remediating Malicious Activity (AA20-245A)
