Loading...
Loading...
A complete step-by-step guide to planning, executing, and analyzing cybersecurity tabletop exercises that actually improve your incident response capabilities.
A tabletop exercise (TTX) is a discussion-based training session where your team walks through a simulated incident scenario. Unlike live drills or penetration tests, tabletop exercises focus on decision-making, communication, and coordination—the human elements that often break down during real incidents.
Follow this proven methodology for effective exercises:
Instead of "Would you call the CISO?", ask "Who needs to be notified and when?"
Give people time to think. Don't fill every pause. Silence drives deeper thinking.
If someone says "We'd restore from backup," ask "How long would that take? Who approves it?"
When discussions drift to "we should buy tool X," note it but return to the scenario.
Have a scribe capturing decisions, gaps, and action items in real-time.
Focus on process and procedure gaps, not individual performance.
Breakpoint provides pre-built scenarios, AI-powered injects, and automated scoring so you can focus on facilitation—not preparation.