Tabletop and live simulations

Tabletop and live simulations let a team test its procedures, work its communication under pressure, and rehearse continuity before an incident forces the same rehearsal at a worse time.

Most incident exercises are polite performances: a few slides, a scripted scenario, and everyone back to email by lunch. That makes for tidy slide decks and thin preparedness. What builds operational resilience is messier rehearsal: live decisions, real trade-offs, communication friction, and the human stress that shows where a plan actually breaks.

The point of the format below is to turn plans on paper into practised habits. Tabletop games buy strategic clarity; live injections build process muscle; and the gap between what a team thinks it will do and what it actually does gets closed in contact.

Core principles

  • Practise, not preach. Learning happens through doing rather than slideware, so the exercises run on hands-on decision cycles and repeatable actions.

  • Safe realism. Scenarios are realistic and uncomfortable, and the room stays blame-free, so a team can learn without the finding being held against anyone.

  • Role clarity and communication. Incidents are mostly human problems, so the focus falls on who speaks when, which channels carry what, and how situational awareness survives contact.

  • Adaptable fidelity. The intensity scales from a 90-to-120-minute tabletop to a multi-hour, multi-team live injection.

  • Evidence for learning. Each exercise ends in concrete outputs: the decisions made, time-to-decision, and a short improvement backlog.

A modular structure

The exercise splits into parts, so the intensity and duration fit what the team can hold.

  1. Orientation (15 to 30 minutes). A quick primer on objectives, safety rules and timing; roles decided, incident commander, comms lead, technical lead, liaisons, observers; and the scope and “do not touch” constraints agreed, the systems the exercise will not disrupt.

  2. Tabletop (60 to 120 minutes). A short, sharp brief establishes the incident, a service outage, data exfiltration, ransomware, a supply-chain failure. Teams talk through decisions round by round while a facilitator introduces complications and new facts to surface dependencies. The focus is decision triggers, escalation thresholds, external communications, and cross-team coordination.

  3. Live injections (1 to 4 hours). Controlled, safe disruptions enter real workflows: a simulated alert, a fake press enquiry, a “compromised” account, a broken vendor API. Teams act in real time on their normal tools and channels while observers record timings, handoffs and friction. A parallel red team can raise the pressure where the culture can carry it.

  4. Comms rehearsal (30 to 60 minutes). Short internal messages and an external statement get drafted and delivered; hotlines, executive briefings and spokesperson handovers practised. The tension to hold is speed against accuracy: moving fast without releasing unverified detail.

  5. Rapid retrospective (30 to 45 minutes). What held, what surprised the team, and where escalation stalled, turned into a short prioritised list of fixes and playbook tweaks with owners and dates, plus a one-page after-action summary and a one-page playbook for the next seventy-two hours.

What a run leaves behind, a team-specific incident playbook, an owned improvement backlog, a recorded decision timeline, stays with the team and feeds the next round rather than settling into a report filed elsewhere.

Last updated: 3 July 2026