- CISO-Led Security & Governance/
- Security Insights & Advisories/
- Cyber Crisis Tabletop Exercises for APAC Firms/
Cyber Crisis Tabletop Exercises for APAC Firms
Table of Contents
Every organisation has an incident response plan. Most of them have never been tested. The plan lives in a document management system, was written by someone who has since left, and has never survived contact with a real decision under time pressure. The first time it is exercised is the first time it matters, and that is exactly when untested plans fail.
A tabletop exercise fixes this cheaply: a facilitated, consequence-driven simulation of a cyber crisis, run against your real people, your real thresholds, and your real regulators.
Why plans fail on first contact #
Real incidents are not linear. They are ambiguous, noisy, and full of judgement calls no playbook can fully pre-script:
- When do we tell the board? Too early and you cry wolf; too late and you lose their trust.
- When do we notify the regulator? In Thailand, the Bank of Thailand and other regulators impose breach-notification timelines. Hesitation has legal consequences.
- Who speaks to the customer, and with what words? A badly worded first statement does more reputational damage than the incident itself.
- Who is authorised to shut down production? In a real crisis, the person with the authority is often not the person with the information.
These questions are decided by people, not process. A tabletop exposes where your decision-making stalls, long before an attacker does.
What a good exercise looks like #
A well-designed tabletop is threat-informed and tailored to your sector. It is not a generic “there has been a breach” script. It follows a realistic chain: say, a supply-chain compromise that starts with a vendor alert and escalates to ransomware on a critical system, and it forces the team through escalating decision points. Not all information is available upfront, and not all people are involved initially. You must work with the resources you have, and be prepared to adapt, improvise and overcome should new information become available.
In an enterprise environment where changes can take weeks or months, you must consider the impact of doing nothing during an incident. Delayed decisions or actions may lead to worse outcomes than an ’estimated’ or an ’emergency change' request.
The real value is in the debrief. Good exercises are judged on:
- Decision speed: how long from detection to a defensible decision?
- Escalation clarity: did anyone know who actually owns the call?
- Regulatory accuracy: would your notification timing have been compliant?
- Communication coherence: did internal and external messaging agree?
NIST SP 800-84 frames this as the core of any test, training, and exercise programme: exercises exist to reveal gaps and improve, not to prove you are ready.
The pattern most teams miss #
The biggest finding in almost every exercise is not technical. It is that the technical team and the executive team operate from different mental models of the same incident. Engineers think in terms of containment and root cause; executives think in terms of disclosure, liability, and customer trust. Neither is wrong, but if they meet for the first time during a crisis, the result is friction at the worst possible moment.
A tabletop forces that collision in a safe room, where the friction becomes a lesson instead of a liability.
Our Cyber Crisis Tabletop Exercises are facilitated half-day simulations tailored to your infrastructure and regulatory exposure, with a readiness report you can take to the board. Pair it with a DFIR Retainer so that when the exercise becomes reality, you are not improvising.