The exercise should include the people responsible for incident decisions, a facilitator who can keep the scenario moving, and someone to document actions and gaps. Cross department participants are also valuable because breaches usually affect more than one team. For larger scenarios, leadership and compliance stakeholders should join so the organisation can test escalation, messaging, and accountability end to end.
Who should be in the room for a cybersecurity tabletop exercise?
tabletop exercise work best when you include the people who can make decisions, the people who will carry out response tasks, and the people who can surface cross-functional impacts. The right mix depends on the scenario, but the goal is the same: test decision-making, coordination, and escalation before a real incident forces it.
Decision-makers, responders, and facilitators all serve different roles
The core group should combine authority, execution, and structure. Decision-makers need enough context to approve containment, communications, or recovery choices; responders bring the operational reality of what can actually be done; and a facilitator keeps the pace moving without becoming part of the scenario. A scribe or note-taker is also important because decisions, gaps, and follow-up actions are easy to lose once discussion accelerates.
This mix matters because tabletop value comes from exposing where policy, process, and reality diverge. If the room has only managers, the exercise can become theoretical. If it has only operators, it can stall on missing authority. If it lacks a facilitator, the scenario often drifts into side discussions and never reaches the escalation points that matter most.
For many organisations, the most useful participants are the ones who sit at the boundary between teams: security operations, infrastructure, applications, identity, legal, communications, privacy, and business owners. Those functions often hold different pieces of the response, and a tabletop should show whether they can act as one team when time is short and information is incomplete.
Choose participants to match the scenario’s blast radius
The attendee list should be driven by the type of incident being tested. A ransomware scenario may need infrastructure, endpoint, backup, legal, and executive representation. A data exposure scenario may need privacy, legal, customer communications, and the business owner for the affected data. An identity compromise scenario may require IAM, help desk, cloud, and application teams because access decisions and account recovery are usually shared responsibilities.
That is why cross-department participation is not optional decoration. Real incidents rarely stay inside one team’s boundaries, and tabletop exercises should reveal where handoffs fail, where approval chains slow down action, and where one team assumes another already owns a task. The exercise is most useful when participants can see how their decisions affect upstream containment and downstream recovery.
For larger or more regulated organisations, include leadership and compliance stakeholders when the scenario is likely to trigger public messaging, customer notification, audit evidence, or regulatory review. Their presence helps test whether escalation paths are clear, whether legal review is built into the process, and whether accountability is assigned early enough to avoid confusion during the real event.
Participation should be broad enough to test coordination, not so broad that it dilutes the exercise
The right size is usually the smallest group that can still exercise the key decision paths. Too few people and you miss the interlocks between teams. Too many and the session turns into a passive briefing where only a handful of participants speak. The strongest exercises invite the functions that own actions, approvals, dependencies, and communications, then keep everyone focused on the specific scenario under test.
Senior leaders do not need to be in every tabletop, but they should be included when the exercise is meant to test authority, crisis communications, or business continuity decisions. Likewise, subject-matter experts should be invited when their domain is central to the scenario, but they should not dominate the session to the point that the rest of the team never has to make a decision.
Risk and Threat Considerations
Tabletop exercises can give a false sense of readiness if the wrong people are present, or if key decision-makers are absent when escalation choices need to be tested. The main risk is not simply that a scenario is discussed poorly, but that the organisation leaves the exercise without validating who can approve, who can execute, and who must be informed under pressure.
Failure mechanism: Exercises fail when attendance does not match the incident’s actual decision chain, when cross-functional dependencies are omitted, or when the facilitator cannot force the group through escalation, containment, and communications decisions. In practice, that produces gaps in authority, delayed handoffs, and untested assumptions about who owns which action.
Impact: The organisation can leave the tabletop with a flattering but misleading result, only to discover during a real incident that approvals are unclear, response tasks are fragmented, or leadership and compliance expectations were never tested end to end.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RR-01 — Roles, Responsibilities, and Authorities | Tabletops depend on clear incident roles and decision authority. |
| RS.CO-01 — Personnel know roles and order of operations for response coordination | The exercise checks whether responders and leaders can coordinate during an incident. | |
| Recommendation — Assign and test incident roles so escalation and response authority are explicit. Validate that participants understand who coordinates, decides, and communicates during response. | ||
| NIST SP 800-53 Rev 5 | IR-4 — Incident Handling | Tabletop exercises rehearse incident handling decisions and coordination paths. |
| Recommendation — Exercise incident handling procedures with the teams that will execute them. | ||
| ISO/IEC 27001:2022 | A.5.24 — Information security incident management planning and preparation | Tabletops are a preparation activity for incident management planning. |
| Recommendation — Use planned exercises to validate incident management readiness and coordination. | ||
| CIS Controls v8 | CIS-17 — Incident Response Management | The scenario tests whether response roles, communication, and recovery are coordinated. |
| Recommendation — Run exercises that verify incident response ownership, communications, and escalation. | ||
Practitioner Guidance
What to prioritise: Start with the incident path you want to test, then invite the people who own the decisions and handoffs on that path. A tabletop is most useful when each participant can answer or act on at least one material branch of the scenario.
What to verify: Confirm that the room includes someone who can approve action, someone who can perform it, and someone who can record the decision and any unresolved gap. If none of those roles are present, the exercise will probably surface discussion but not useful evidence of readiness.
What good looks like: The team moves through escalation, containment, communications, and recovery without stalling on ownership. The exercise produces clear follow-up items, not just a general sense that “everyone understood the scenario.”
Practitioner takeaway: The best tabletop roster is built around decision rights and dependency mapping, not job titles; if the right approvals and handoffs are not represented, the exercise will test familiarity, not readiness.
Related resources from NHI Mgmt Group
- How should organisations run their first cybersecurity tabletop exercise without overwhelming the team?
- What breaks when legal, communications, and business leaders are missing from a tabletop exercise?
- Who should own cybersecurity SLA accountability when multiple vendors are involved?
- What is the difference between a ransomware simulation, penetration testing, and a tabletop exercise?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org