Over the past month, nearly every client risk and cybersecurity steering committee I have facilitated has covered the same agenda items: business continuity, disaster recovery, and incident response. Even so, the reasons are not the same from one company to the next.
Some are responding to external pressure: A cyber liability underwriting form asked questions the team could not answer or asked for documented proof of a test. A regulator visit or an information technology (IT) audit is on the calendar. Or last year’s financial audit produced a finding in the review of Information Technology General Controls (ITGCs), and management wants it closed before this year’s audit.
Others are reacting to something they saw: A near miss. Something that happened to a competitor or to a friend’s business. Reporting on state-linked intrusions into U.S. institutions, prompting leadership to ask whether their own preparation would hold.
A few are simply on a schedule: Some committees put the conversation on the risk calendar at the same time every year, review the plans, test them through a tabletop exercise, and identify the risks that need mitigation dollars before budgeting season closes the window.
When the review is routine, the organization chooses what it funds and in what order. When it is triggered by an underwriter, an auditor, or an incident, someone else has already made that choice, usually on a shorter timeline and at a higher cost.
What A Tabletop Exercise Actually Tests
A tabletop exercise is a facilitated, discussion-based simulation in which leadership works through a realistic incident in real time, without touching live systems. Participants are given an opening situation, then asked what they would do, who they would call, what authority they hold, and what information they would need, with new complications introduced as the discussion unfolds.
The purpose is not to prepare for a single doomsday scenario, nor is it a technology test. It is testing whether the leadership team can make timely, legally sound decisions when a critical vendor goes dark, payroll cannot be processed, or client data is exposed. It’s also testing whether decisions have clear owners, whether the documentation is reachable, whether escalation paths and outside parties are understood, and whether the assumptions the organization has been carrying hold up when someone asks the obvious question.
The gaps that surface are almost always procedural rather than technical. Three patterns recur.
The plan is theoretical until it is tested.
A written incident response or business continuity plan describes intent. Walking through a disruption out loud is what exposes the single points of failure, such as stale contact lists, and dependencies the document quietly assumed away.
Handoffs are where response breaks down.
A real incident requires IT, Legal, Compliance, Communications, Human Resources, and executive leadership to move together within hours, often under considerable stress. The exercise settles who owns which decision and who holds authority to spend, disclose, or notify before the question is live.
Deciding on incomplete information is a skill.
In real life, executives get very little practice acting decisively on partial facts with legal and reputational consequences attached. Conducting this type of exercise, on the other hand, is the one setting where that practice is available at low cost.
A tabletop exercise is not a cybersecurity risk assessment, and it does not substitute for one. An assessment establishes which controls exist and where the gaps are. GBQ’s Business Technology Solutions team’s assessments are built primarily on the NIST Cybersecurity Framework (CSF) 2.0, include technical testing against those controls, and produce a risk register and a roadmap for improving security posture. A tabletop establishes something different: whether the people who depend on those controls can act when one of them fails. Most mid-market organizations should be doing both, conducting an annual assessment and then conducting an exercise to run against what the assessment finds.
The Gap Is Not Awareness
In the Spring 2026 Middle Market Indicator, the semiannual survey the National Center for the Middle Market conducts with Chubb, polling 1,000 CEOs, CFOs, and other financial decision-makers at companies between $10 million and $1 billion in revenue, cybersecurity was the top risk across the lower, core, and upper middle market segments. In the prior fielding, six months earlier, it ranked second behind supply chain risk.
Preparedness has not moved with it. That same mid-2025 fielding found that only 28% of mid-market companies work with a third party on business continuity planning, and only 8% engage in resilience-building services. Nationwide’s Agency Forward survey (February 2025, 400 mid-market business owners, self-reported) puts it more bluntly: 21% have no business continuity plan at all, 45% have no disaster preparedness plan, and only 54% feel highly protected against the risks they themselves named.
The events those plans exist for are not rare. Verizon’s 2026 Data Breach Investigations Report, 22,000 confirmed breaches across 145 countries covering incidents from November 2024 through October 2025, found ransomware present in 48% of breaches, up from 44% the year before. The finding most relevant to a tabletop exercise is the third-party one: breaches involving a third party rose 60% year over year and now account for 48% of the total. Nearly half of breaches arrive through someone else’s (e.g., a vendor, a managed service provider, a hosted application, an outsourced payroll system) environment.
That is the category a tabletop exercise is unusually good at surfacing, because the failure is rarely technical. It is that no one has settled who calls the vendor, who has the contract terms in front of them, who is authorized to speak to the client whose data sat in that vendor’s system, or whether the contract obligates the vendor to tell you anything at all on a timeline that helps you.
What The Cyber Liability Carrier Sees
For a growing number of organizations, this conversation starts at renewal, because carriers now treat tabletop testing as a maturity signal that affects coverage, pricing, and claims. They work from the assumption that most organizations will eventually have an incident, and they underwrite on the difference between the ones that have practiced a response and the ones that have not: shorter downtime, smaller claims, fewer regulatory penalties.
Documented proof of a recent test, typically an After-Action Report (AAR), has become a practical prerequisite for coverage with many carriers. An untested plan reads to an underwriter as an aspiration rather than a control. Organizations that can show a tested response capability are positioned for better pricing, broader terms, and higher limits.
Carriers also want counsel in the room. A major cyber incident is a legal event before it is an IT event, and underwriters look for evidence that the executive team knows how to engage outside incident response resources without stepping on attorney-client privilege.
If your renewal is more than a quarter out, that is the window in which testing is inexpensive and useful. Inside that window, it becomes a scramble to produce a document rather than an exercise anyone learns from.
Scenarios We Have Run (And Breaches We Have Responded To)
The following are drawn from exercises we have facilitated for clients and from real breach events our team has responded to. The lessons cost considerably less when they come from the exercise.
When the plan is inside the thing that failed.
A financial institution was hit by ransomware that encrypted its document and collaboration environment. The incident response handbook branch managers and department leaders rely on to perform their roles existed only inside that environment, and no one could reach it. Separately, a distribution company’s Enterprise Resource Planning (ERP) system was ransomed; management then discovered the subscription did not include data backup, and the vendor had no copy to restore from.
When the person you need is unreachable.
A medical device manufacturer was hit by ransomware detonated on Thanksgiving Day. The timing was deliberate: the Chief Information Officer (CIO) and the entire IT staff were unavailable, and the response began without them. A healthcare organization was hit while its CIO was on a backpacking trip, holding the only administrative credentials capable of restoring the network. A professional services employee with both local and network administrator rights fell for a phishing email over a long holiday weekend, exposing privileged credentials that were not discovered as compromised until staff returned the following week.
When you cannot prove what happened.
An engineering services firm received an extortion demand claiming theft of client project intellectual property covered under stewardship agreements. Systems remained fully operational, and there was no outage to respond to. The firm had to prove to its clients that the protected data never left its network and discovered it did not have the logging in place to demonstrate what had been accessed or exfiltrated. In another case, a software firm suffered a breach of personal client data, and senior management did not know how to engage the cyber liability carrier, when to notify regulators, or what to tell the customers whose end users were affected.
When you cannot tell an outage from an attack.
A multi-location restaurant operator’s point-of-sale and back-office systems went offline during dinner service for reasons no one could identify. Stores reverted to paper tickets and cash, and management had no way to determine whether it was an outage, an attack, or a vendor failure. In a separate matter, a routine collection call produced the answer that the invoice had been paid the previous month, but it was paid to a fraudulent account after an email inside the existing thread changed the remittance banking details. The evidence pointed to the customer’s email environment as the point of compromise; the customer refused to pay a second time, and neither party could prove where the thread was intercepted.
How The Exercise Runs
A GBQ-facilitated tabletop exercise has three phases.
1. Preparation and discovery.
We review your existing incident response and business continuity plans and interview key executives and IT leadership to map critical business processes, technology dependencies, third-party vendor relationships, and regulatory obligations. Document review usually surfaces initial gaps on its own. The primary purpose, though, is to build a scenario specific enough to your environment that no one in the room can dismiss it as someone else’s problem.
2. The simulation.
A facilitator runs the leadership team through an unfolding incident, introducing injects such as a vendor going offline, a legal constraint, or a media inquiry that forces the team to adapt mid-decision. Evaluators document how decisions actually get made and where communication stalls. The session closes with a hot wash: an immediate debrief while reactions are still fresh.
3. The After-Action Report and roadmap.
The AAR documents what surfaced, the operational risks identified, and prioritized mitigation steps with named owners. We include a risk register alongside it, the same artifact we deliver with every engagement, so whoever owns remediation tracks exercise findings and assessment findings in the same form. Together they function as a compliance artifact, which provides evidence to carriers, auditors, and regulators that the organization tests its resilience and acts on what the test found.
Where To Start
Most leadership teams will manage a serious disruption at some point. The variable is whether the first attempt happens in a conference room, with a facilitator and no customers watching, or in production with both.
If business continuity and incident response are already on your committee calendar this year, the exercise belongs in that same cycle while there is still budget available to act on what it finds.
To discuss a tabletop exercise scoped to your environment, contact GBQ’s Business Technology Solutions team today.
GBQ’s Business Technology Solutions practice serves mid-market organizations across risk management, cybersecurity, IT governance, artificial intelligence and automation, data and analytics, and business systems. For more information, schedule time with Doug Davidson, director of GBQ’s Business Technology Solutions practice. Or, contact him directly at ddavidson@gbq.com.

Net Effect is a biweekly column written by Doug Davidson, director of the firm's Business Technology Solutions, published in the firm's Bottomline newsletter. Email ddavidson@gbq.com to have your technology questions addressed in a future column.