The worst time to discover that no one knows who to call is during the breach. A tabletop exercise — an hour around a table, walking through a realistic incident — surfaces that gap while it's still cheap to fix.
How it works
Someone narrates a scenario: "an employee reports their laptop was stolen from a car, and it has saved passwords." The team then talks through what happens next, step by step. No systems are touched. The point is to find where the plan goes vague — who decides, who's notified, who has the authority to disconnect something at 9pm on a Friday.
What it reveals
- The decisions no one owns — "who actually declares an incident?"
- The contacts no one has — the cyber-insurer's hotline, outside counsel, the critical vendor.
- The assumptions that don't hold — "we'll just restore from backup" (have you tested that it works?).
A plan you've never rehearsed is a document, not a capability.
Run one a year, keep it to an hour, and write down what broke. The value isn't the scenario — it's the short list of gaps you leave with, and the calm that comes from having walked the path once before you ever have to run it.