Critical Question

Tabletop Exercises UK:
Test Your Incident Response

Most disaster recovery plans have never been tested. When a real incident hits, that's when you discover the gaps: the wrong phone numbers, the missing steps, the confusion about who makes decisions. Test your response before you need it.

41%
of UK businesses haven't tested their DR systems in the last 6 months or don't know when they last did
UK Business Reality Check
43%
UK businesses breached last year
UK Cyber Survey 2025
60%
SMBs attacked never recover
NCSA
<7%
Companies recover within a day
Sophos 2024
£800k+
Saved by containing breach in 30 days
IBM

Why Most DR Plans Fail When Tested

These aren't scare tactics. They're industry statistics. The companies that survive incidents are the ones who tested their response beforehand.

77%
of business leaders don't have a formal incident response plan applied consistently
Source: IBM Security
24.6
days average recovery time from a ransomware attack in 2025
£27B
annual cost of cybercrime to the UK economy
51%
of SMBs that suffered an attack in 2025 were offline for more than 10 days

Every organisation we work with discovers at least 1 critical gap in their first tabletop exercise. Better to find them now than during a real incident at 3am.

Test Your Plans

What is a Tabletop Exercise?

A tabletop exercise (TTX) is a discussion-based session where your team walks through a simulated incident to test your response procedures, identify gaps and practice coordination without the pressure of a real emergency.

No systems are affected. No real data is at risk. Just your team, a realistic scenario, and an expert facilitator asking the hard questions: "Who do you call first? What if they don't answer? Where's that documented?"

Risk-free testing - Practice your response without real consequences
Team coordination - See how your team actually communicates under pressure
Actionable report - Walk away with documented gaps and a prioritised action plan
Without Testing
After a TTX
Confusion about roles and responsibilities
Outdated contact lists and procedures
Missing steps in your runbooks
Unrealistic recovery time assumptions
Panic and poor decisions under pressure
Clear understanding of who does what
Updated, validated procedures
Documented gaps with action plans
Realistic understanding of capabilities
Team confidence in their response

Scenarios We Facilitate

Each exercise is tailored to your specific environment, industry and concerns. Here are the most common scenarios we run.

Ransomware Attack

Your systems are encrypted. Ransom note on screen. What do you do first? Who do you notify? When do you involve law enforcement?

"It's 6am Monday. Your file server is encrypted..."

Data Center / Cloud Outage

Your primary infrastructure is down. How quickly can you failover? Who has access to backups? (Need cloud resilience help?)

"Azure is reporting a major outage in UK South..."

Key Personnel Unavailable

Your IT Director is unreachable. The person with the passwords is on holiday. Can your team still respond? (Consider fractional IT leadership for resilience.)

"Sarah's phone goes straight to voicemail..."

Data Breach / GDPR Incident

Customer data has been exposed. You have 72 hours to notify the ICO. What's your process? Who makes the call? (Our fractional DPO service can help.)

"A customer emails: 'Why is my data on this website?'..."

Supply Chain Disruption

A critical vendor has been compromised. Their services are offline. What's your contingency?

"Your payroll provider emails: 'We've had a security incident'..."

Custom Scenarios

Have a specific concern? We build custom scenarios based on your industry, threat landscape and unique risks.

"What keeps you up at night? Let's test it."

How a Tabletop Exercise Works

Our proven four-phase approach ensures productive sessions and actionable outcomes.

1

Pre-Exercise Planning

1-2 weeks before

We review your existing plans (if any), understand your environment and design a realistic scenario. We'll work with you to determine objectives, identify participants and set the scope.

2

The Exercise Session

Half or Full Day

Your team gathers (in-person or remote). Our facilitator introduces the scenario and injects complications as you work through your response. We observe, document and guide the discussion. But your team makes the decisions.

3

Debrief & Hot Wash

Immediate

Right after the exercise, we facilitate a candid discussion about what worked, what didn't and what surprised people. This is where the real learning happens.

4

After-Action Report

Within 1 week

We deliver a comprehensive report documenting gaps, recommendations and a prioritised action plan. Not a novel. Practical, actionable findings you can act on immediately.

Fixed Pricing, No Surprises

You know exactly what you're paying for. No hidden fees, no scope creep.

Half-Day Exercise

£550 + VAT
  • 2-4 hour facilitated session
  • Pre-exercise planning call
  • Custom scenario development
  • Expert facilitator
  • After-action report
  • Remote or in-person (UK)
Get Started

Custom Program

Let's Talk Tailored to needs
  • Multi-day exercises
  • Multiple scenarios
  • Annual testing programs
  • Board-level exercises
  • Industry-specific scenarios
  • Compliance documentation
Contact Us

All packages include: Pre-planning, custom scenario development, expert facilitation, comprehensive after-action report with prioritised recommendations and unlimited email support for 30 days post-exercise. Pricing may vary based on group size and complexity. We'll provide a final quote after our planning call.

Request a Tabletop Exercise

Tell us about your needs and we'll get back to you within 4 hours to discuss scheduling and scenario design.

Jan Only

Book this month → 2nd session half price

We'll respond within 4 business hours to discuss your needs. No obligation, no sales pressure.

Frequently Asked Questions

Do we need existing plans to run an exercise?

Not at all. If you don't have documented plans, we can still run a valuable exercise. The exercise will help you understand what plans you need and serve as the foundation for creating them.

How technical does my team need to be?

We tailor the exercise to your team's technical level. The focus is on decision-making and coordination, not technical deep-dives. Everyone participates regardless of technical background.

What's the difference between half-day and full-day?

Half-day focuses on one scenario and core decisions. Full-day allows deeper exploration, multiple scenario variations, more detailed debrief and includes a 90-day follow-up review.

Can we do this remotely?

Absolutely. We've facilitated dozens of remote exercises via video conference. They work excellently and actually test your remote coordination capabilities. In-person is also available across the UK.

How often should we run tabletop exercises?

Best practice is annually at minimum. Many organisations run them quarterly or after significant changes (new systems, org changes, etc.). Regulations like NIS2 and DORA increasingly require regular testing.

Will this satisfy compliance requirements?

Yes. Many frameworks (ISO 27001, SOC 2, Cyber Essentials Plus, NIS2, DORA) require testing of incident response and business continuity plans. We provide documentation that demonstrates compliance. Need help with broader security compliance? We can help with that too.

Stop hoping your plans work.
Test them.

Every organisation we work with discovers gaps they didn't know existed. Better to find them in an exercise than during a real ransomware attack at 3am.