Incident Readiness / FOCUSED SERVICE

Executive Tabletop Exercises

A facilitated, scenario-driven exercise that puts leadership through the decisions a serious incident forces, then records what has to change.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

Executive tabletops test the decisions only leadership can make: declaring an incident, engaging counsel and the forensic retainer, setting ransom posture, continuity choices, and what to tell customers, regulators, and the board. We pick a scenario from your exposure: ransomware with data theft, business email compromise and wire fraud, or cloud account compromise. The scenario runs in three to five modules with timed prompts: encryption found, an extortion note with proof of stolen data, a journalist inquiry, a slipping recovery estimate. In a discussion-based session without keyboards, the CEO, general counsel, CFO, CISO, communications, and HR work each prompt while we record decisions and gaps. You receive an after-action report and improvement plan plus redlines to the plan and templates. We frame the decisions; counsel decides on notification and materiality.

WHEN THIS IS THE RIGHT FIT

For executive teams and boards of companies that hold regulated data or carry public disclosure duties, and for leaders who signed a plan they have never had to use. Typical triggers: a board or audit committee request, a cyber insurance renewal, a peer’s public breach, or a new securities, financial regulator, or defense contract obligation.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Set objectives with counsel and sponsor

We agree three to five objectives written as observable decisions, for example leadership decides whether a public securities disclosure is required and documents its materiality reasoning. We confirm attendees, invite counsel and your broker or breach coach, and agree that no real customer or employee data is used and who receives the report.

Write the scenario and timed injects

The scenario is built from your exposure: regulators, customer contracts, cloud footprint, and payment flows. Injects arrive on a clock and force re-decisions: sanctions screening before any payment discussion, the short-fuse regulator filing that follows an extortion payment where it applies, and holding statements. Later injects add law-enforcement contact and a board update with incomplete facts.

Facilitate, hot wash, and report

The principal facilitates a two to four hour discussion with no keyboards, ending in a hot wash where participants name what surprised them. Afterward you receive the after-action report and improvement plan, redlines to the plan and communications templates, and a board-ready summary of what was exercised and what changes next.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Executive teams and boards at companies holding regulated data or public disclosure duties
  • Leaders who approved an incident response plan they have never had to use
  • Organizations where legal, communications, and finance have never rehearsed a crisis together
  • Public companies weighing materiality and Form 8-K timing under real time pressure
WHEN IT’S TIME TO ENGAGE
  • A board or audit committee asks whether leadership can actually handle a breach
  • An insurance renewal or customer due-diligence review expects evidence of exercises
  • A competitor or peer suffers a public breach that draws executive attention
  • A newly applicable SEC, NYDFS, or state disclosure duty raises the stakes
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Scenario selection from your actual exposure: ransomware with data theft, business email compromise and wire fraud, cloud account compromise, or vendor breach

  • Scenario script with three to five modules, timed injects, facilitator guide, and an evaluator sheet per objective

  • Decision points on activation, severity declaration, and engaging the breach coach and forensic retainer through counsel

  • Ransom posture, including sanctions screening and any extortion-payment filing your regulators require

  • Notification determinations, clock owners, holding statements, spokesperson, and customer and contract notices

  • Continuity choices on which systems come back first, board communication, and the securities materiality and disclosure process for public companies

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$3,000–$4,500

One 2-hour session for 5–8 leaders, standard scenario tailored to your business, held remotely

About 20–30 hours
Mid-size
$5,400–$7,500

Half-day session for 8–15 leaders, custom scenario with legal, insurer, and customer-notice decisions, held on-site

About 36–50 hours
Large
$8,400–$12,000

Half-day or longer with the board or several business units, multi-state or public-company disclosure decisions

About 56–80 hours
WHAT MOVES THE PRICE
  • Session length and number of participants
  • How custom the scenario is (standard template vs. built from your regulators, contracts, and systems)
  • Number of regulators and disclosure rules the exercise has to cover
  • On-site delivery and travel vs. remote
TYPICAL TIMELINE

2–4 weeks from kickoff to session, with the after-action report delivered 1–2 weeks after

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Scenario script, inject timeline, facilitator guide, and participant handout, reusable for the next exercise
  • Hot-wash notes and an After-Action Report and Improvement Plan with strengths, gaps, root causes, and owned corrective actions
  • Redlines to the plan, notification decision tree, and communications templates
  • Board-ready summary of what was exercised and what changes next

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Will this exercise embarrass our leadership team?

No. The exercise is discussion-based and runs under the rule that findings concern decisions and information flow, not individuals. Nobody is graded and nothing is executed. The report records where a decision stalled because the plan did not say who owned it, where information never reached the person who needed it, and where a template was missing. Those are fixes to documents and roles. You decide who attends, what is recorded, and who receives the After-Action Report before we write a word of the scenario.

Should our lawyer and insurance broker attend?

Yes, if at all possible. Counsel learns whether they want the forensic firm engaged through them under a separate letter, since courts have declined to protect breach investigation reports in several cases decided since 2020. Your broker or breach coach confirms whether your preferred forensic firm is on the carrier’s panel and whether the policy requires prior consent before you retain anyone. Both questions are cheaper to answer in a tabletop than on the first day of an incident. We frame the decision; counsel and the carrier make it.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security