APOLLOSEC

Cyber incident tabletop exercises

We devise realistic scenarios and run them with your leadership and technical teams. You learn whether the plan, the people and the phone tree hold up before you need them.

Most plans have never been used

Most incident response plans have never been tested. They name people who have since left, rely on systems that will be down in a real incident, and leave the hardest decisions, such as whether to pay a ransom or when to tell customers, until the moment they are needed.

A tabletop exercise is a rehearsal. We present an unfolding incident based on attacks happening to organisations like yours, and the team works through it in real time. The gaps show up in a meeting room rather than in a crisis.

What we exercise

  • Decision making

    Who decides, on what information, and how quickly.

  • Communication

    Internal escalation, and what you tell customers, regulators, insurers, the press and law enforcement.

  • Technical response

    Containment, evidence preservation and recovery, for technical teams.

  • Third parties

    Suppliers, managed service providers and any incident response retainer you hold.

  • Reporting deadlines

    Obligations such as the 72-hour personal data breach report to the ICO, and sector rules such as NIS2 and DORA.

  • Recovery

    Backups, business continuity, and how the business keeps running while systems are down.

How the engagement runs

  1. Discovery

    We read your incident response plan and talk to key people to understand your organisation and its concerns.

  2. Scenario design

    We write a scenario specific to you, drawn from current attacks on your sector, with injects that build pressure.

  3. The session

    A facilitated session, usually half a day, for leadership, technical teams, or both.

  4. Review

    A report on what worked and the gaps found, with changes to the plan and an action list.

What you get

  • A tailored scenario pack you can reuse.
  • A facilitated session run by people who test real attacks.
  • An after-action report with recommended changes to your plan and playbooks.

When to commission it

  • When an incident response plan is new or has been rewritten.
  • After a change of leadership, IT provider or major system.
  • When a regulator, insurer or customer asks for evidence that the plan has been tested.
  • At least yearly, using a different scenario each time.

Questions we get asked

Who should attend?

For a leadership exercise: the executive team, legal, communications and whoever leads IT or security. For a technical exercise: the people who would respond hands-on. Many clients run both using the same scenario.

How long is a session?

Usually half a day. Longer exercises with several phases can run across a full day.

Do you use our real plan?

Yes. The exercise tests your plan as it is written, which is the point. If you do not have one yet, we can run a session that helps you build it.

Can it be run remotely?

Yes, though in-person sessions generally work better for leadership teams. We run both.

Rehearse the incident before it happens.

Talk to us