Sun Tzu says, "Plan for what is difficult while it is easy."
That’s why Incident Response tabletop exercises have been growing in popularity and are increasingly being required by compliance frameworks, such as ISO, NIST and others. Instead of writing security policies and procedures, hosting them on a shared document site and then hoping that everyone is “good enough” to successfully apply what they read in the heat of a real incident on the first try, companies are putting their teams and procedures to the test in safe and controlled ways.
Jump ahead
What are the benefits and limitations of cybersecurity tabletop exercises?
While “tabletop exercises” (TTX) may sound like an item out of a couple’s game night, these security incident response simulations (SIRS) are a legitimate method to test a security or business continuity incident without the hassle of actually disrupting operations.
Traditionally, these security training exercises often involve an impartial, third-party presenter armed with prepared slides and four to eight hours of time. They lead a roomful of executives and team managers across the business through a pre-approved scenario, such as ransomware on an employee desktop, malware on the internal network via a personal device or a power outage that disrupts cloud services.
The presenter will attempt to both present the scenario and keep notes on how well the cross-functional team is managing it and where gaps might exist in response capabilities. These notes usually culminate in a Scenario Report that identifies what went well and what didn’t during the exercise so the team can work on improving the process for the next exercise or, worst case, a real scenario.
The benefit of this type of exercise is that it familiarizes the team with the incident response process “while it is easy” and can help identify gaps or problems that weren’t thought about during the initial Incident Response process draft.
The downsides of these traditional types of exercises, though, are:
- The difficulty of making a theoretical, discussion-based scenario accurately reflect the business environment it is supposedly targeting and relevant to applicable stakeholders
- The imprecision of validating a technical process or capability while sitting around a conference table – no matter how many certification letters are after people’s names
- The amount of time it takes from people's day jobs (at minimum, half a day per exercise)
- The cost it takes to conduct them on a regular basis (often as high as $30,000 - $50,000 per exercise)
Add virtual labs to create real-world cybersecurity training simulations and scenarios and build confidence
Skillable’s hands-on lab environments are a natural solution to resolve these downsides while maintaining all of the benefits of Incident Response tabletop exercises. Here’s how we enable you to move from “potentially” identifying gaps and problems to concretely doing so with hands-on performance data.Scalable and flexible
Skillable’s virtual hands-on lab environments can easily handle as few or as many participants as the scenario requires. Instead of focusing on only one audience, the simulation can involve decision makers, managers and even the analysts and agents performing the hands-on work.
A dedicated lab environment can also accurately reflect an organization’s environment, complete with workstations, networks and even relevant and proprietary software.
Practical and hands-on
Once you have a mimicked environment, you can simulate real incidents in our lab environment as an active participant, instead of just talking about them over PowerPoint slides or watching videos as a spectator.
This method also allows the process to focus on practical skills, tools and actions as opposed to theoretical knowledge or role playing.
Role-based training
In a hands-on lab environment, different employees can be assigned different roles, just like in the corporate environment, and different levels of access or permissions can be configured.
As a result, the security training simulation can validate not only analysis and testing, but also communication and follow-up.
Customized and personal
Skillable’s hands-on lab environments include panels for instructions or other notes. For an incident response simulation, content creators can insert a team’s Incident Response process directly into these panels, allowing team members to follow along in the process and immediately identify gaps or mistakes as they implement the plan.
In addition, Skillable’s over-the-shoulder Instructor monitoring capabilities enable Instructors to watch and support participants on an individual basis, resulting in a more effective learning experience.
Data-driven insights
Instead of relying on a multitasking presenter, Skillable’s hands-on environments automatically collect detailed metrics and reporting on a team’s performance and response times providing two immediate benefits:
- Focus and efficiency – The presenter has more time to provide tangible value instead of manually reviewing performance.
- Company-specific value and insights – This data can be turned into metrics for data-driven decisions about improvement and success.
How do you build a program like this? You incorporate hands-on questions and interactive validation checks into the simulation. Learn more about skill validation, activity group scoring and scored labs.
Continuous learning opportunities and keeping skills sharp
Based on performances and previous data insights, the environment or scenario can be easily adjusted for further testing, making follow-up exercises efficient and cheaper while also enabling users to maintain their skill “muscle memory.”
In their 2024 Cost of a Data Breach report, IBM reported that two of the top four factors that decreased the cost of a data breach were employee training and Incident Response planning. Unfortunately, not all training or planning is the same, which is why Skillable is on a mission to connect “learning with work” in a meaningful and hands-on way.
4 Skillable Challenges to get started with hands-on security tabletop exercises
Some of our Skillable Challenges provide a foundation for getting started. These turnkey hands-on lab environments, while not full tabletop exercises, enable you to introduce a live practice environment to apply skills.
Depending on your needs, you can tailor or expand upon the scenarios to meet your requirements:
- CVAF-005 – Manage Incidents by Using Incident Response Tools
- SC200.2-005 – Can You Implement Comprehensive Security Management by Using Microsoft Defender and Microsoft Entra ID?
- SC200.2-008 – Advanced Threat Hunting with Microsoft 365 Defender
- SC200.2-013 – Incident Response with Microsoft Defender XDR
Don’t see what you need? With Skillable’s platform, you can build your own custom tabletop exercises, such as:
- Simulating a ransomware attack in a lab that mirrors your actual environment. Handle different scenarios such as ransomware on an employee workstation, your primary web server, or worst-case scenario, the domain controller itself.
- Simulating how a service outage, such as Teams, Outlook or a whole cloud environment, would affect your business and ability to communicate. Would your teams know an alternative workaround or would work grind to a halt?
- Simulating a phishing attack against an executive account. Using data-driven metrics, determine how quickly and effectively your security team can identify the attack, disable attacker access and block additional pivoting attempts.
It’s easier than you think, see it for yourself in a free 30-minute demo.
Who should use Skillable’s environment for tabletop exercises?
- Consultants who provide Incident Response training solutions and are looking to differentiate their offering
- Organizations that build cybersecurity simulations in-house and want to build and manage more realistic training environments with fewer headaches
Our hands-on labs enable you to deliver practical, hyper-realistic simulations and scenarios that really pack a punch.
Why trust Skillable for security labs?
We’re an authorized lab host for Microsoft, EC-Council, CompTIA, Check Point and many others. These same organizations use Skillable’s platform to build cybersecurity labs and certification exams thanks to our robust lab authoring tools, scalability, reliability and security. Still not sure? Here are 15 reasons why there’s no alternative to Skillable.
Nathaniel Shere
Product Security Engineer, Skillable
Nathaniel is a contributing author and cybersecurity professional with more than 11 years of hands-on experience in penetration testing, cybersecurity consulting and secure code development. He focuses on real-world strategies and hands-on learning to build safer products and stronger security programs.
Nathaniel Shere
Product Security Engineer, Skillable
Nathaniel is a contributing author and cybersecurity professional with more than 11 years of hands-on experience in penetration testing, cybersecurity consulting and secure code development. He focuses on real-world strategies and hands-on learning to build safer products and stronger security programs.
Less discussion. More doing.
Prove real-world incident response readiness with hands-on, live environment simulations.