Tabletop Exercises (TTX)
Most incident response plans have never been tested outside a slide deck. A Tabletop Exercise (TTX) puts yours through a realistic scenario, with your leadership and technical teams in the room, so you find the gaps before a real breach. No disruption, just a clear answer to “are we actually ready?”
100s of businesses continue to improve their cybersecurity with CloudGuard













You Have a Plan. Do You Actually Know It Works?
An incident response plan is only as good as its last rehearsal. If any of the below sound familiar, it’s worth finding out now, not mid-incident.
A phishing email nearly got through, or a supplier had an incident close to home. It didn’t hit this time, which is exactly why it’s worth finding out what happens when it does.
It was written, signed off, maybe even praised in an audit. But nobody in the business has actually walked through it since the day it was filed away.
Ask five people, who makes the call to notify customers? Or when to involve the board? You’ll likely get five different answers, until it’s too late.
Tested Against the Scenarios That Actually Matter to You
We cover the threats most likely to actually reach you, ransomware, data breach, phishing and account compromise, insider threats, business email compromise, API exploitation, supply-chain malware, and AI governance risk, each tested from first detection through to full recovery.
Â
These go beyond the technical response to what happens to the business itself, business continuity, supplier and third-party dependency failure, finance and supply chain impact, regulatory compliance, and multi-scenario resilience sessions testing decision-making under sustained pressure.
Each Tabletop Exercise is tailored to who’s in the room, this could be a leadership and board-level tabletop for strategic decision-making and governance, a technical deep dive for detection and containment mechanics, or a functional deep dive built around a specific team like finance or supply chain.
Here's Exactly How We Pressure-Test Your Plan
We keep this simple and low-friction, most of the work happens in a single facilitated session, with preparation and follow-up either side.
Phase 1: Scoping call
During the scoping call we aim to understand your business, your current IR plan (if one exists), your industry risk profile, and who needs to be in the room. This sets the foundation for a scenario that's relevant, not generic.
Phase 2: Scenario design
Select from 2 of 28 interactive rehearsal scenario's to update & improve IR effectiveness. We build a realistic incident scenario and injects, the twists that unfold live, matched to your environment and threat landscape. Nothing is shared with participants in advance.Â
Phase 3: Facilitated tabletop session
A half-day session where your team responds to the unfolding scenario in real time, guided by a CloudGuard facilitator. Decisions, gaps, and assumptions surface naturally under realistic pressure.
Phase 4: Debrief and findings report
We document what worked, where the plan broke down, and where roles or communication were unclear, translated into a prioritised, board-ready findings report.
Phase 5: Remediation roadmap
A practical follow-up plan for closing the gaps, whether that's updating the IR plan, clarifying ownership, or a follow-on engagement to accelerate the fixes.
Meet Your Incident Response Experts
Conor Mallon
Conor is Chief Operating Officer at CloudGuard, with a decade of frontline cybersecurity experience spanning SOC leadership, incident response and operational strategy. From analyst to XDR site lead, he has built and led high-performing teams, streamlined operations and driven resilience.
Matt Lovell
Matt is the Co-Founder and CEO of CloudGuard, with 30+ years of cybersecurity leadership. A recognised expert in incident response, he has guided organisations through major breaches, crafted bespoke response plans and led strategic tabletop exercises. Matt ensures rapid recovery, clear communication and minimal impact.
Built Around Your Business and What Happens Next
CloudGuard exercises are built around your specific business, your industry, and the threats most likely to actually reach you, not a recycled scenario template. A CloudGuard facilitator runs the session live, introducing pressure and unexpected turns as it unfolds, so what gets tested is judgement under pressure, not just familiarity with a document. And your technical responders and executive decision-makers take part in the same room, together, because a real incident involves both.
Readiness
We help surface the gaps in your plan before a real costly incident does.
Responsiveness
The findings harden your plan for next time, and each future exercise builds on what the last one uncovered.
Resilience
A prioritised roadmap that makes your environment progressively harder to compromise, recommendations that are risk-led, not product-led.Â
If these sound familiar, it's time to book a Tabletop Excercise
A Tabletop Exercise usually lands on the desk of a CISO or Head of Security, a CIO or IT Director, or a COO or Head of Operational Resilience. But unlike most technical assessments, it doesn’t stop there, board members and executive sponsors take part directly, as active participants working through the scenario alongside the technical team, not just as an audience receiving a report afterwards.
A near miss, a phishing email that almost landed, a supplier or industry peer that got hit, has made you wonder, calmly and seriously, what would actually happen if it were real. A tabletop exercise gives you the answer before an incident forces it.
A regulator, insurer, auditor, or major customer has asked for evidence that your incident response capability has actually been exercised, not just written down and signed off. A TTX gives you something concrete to point to.
Headcount, systems, and complexity have grown, but the response plan hasn’t kept pace, and nobody’s tested whether it still reflects how the business actually works today.
Trusted by Customers. Backed by Certifications. Proven in the Real World.
CloudGuard is embedded in the cybersecurity industry – recognised, accredited, and trusted to protect real organisations every day.
Frequently Asked Questions
What is a TableTop Exercise (TTX)?
A tabletop exercise (TTX) is a facilitated simulation where your team works through a realistic cyber incident scenario in a structured, discussion-based session, without touching live systems. It tests whether your incident response plan, roles, and decision-making actually hold up under pressure, rather than just existing on paper. Both technical and leadership teams typically take part together, since a real incident involves both.
How does CloudGuard’s TTX differ from other testing services?
CloudGuard’s TTX goes beyond standard testing by providing customised scenarios tailored to your business. We offer detailed feedback, expert guidance, and ongoing support to help you not only test but improve your overall response framework.
Who should participate in the TTX sessions?
Ideally both technical responders and business leadership, IT/security teams who’d manage the technical response, and executives or board members who’d make the calls around communication, legal exposure, and business continuity. Real incidents involve both groups, so an exercise that only includes one side never truly tests the plan.
How long does the TTX take?
Most CloudGuard tabletop exercises run as a single facilitated half-day session, once scoping and scenario design are complete. The scoping call and scenario build happen in advance, so the live session itself is focused and doesn’t demand more time from your team than necessary. Findings and a remediation roadmap follow shortly after.
What kind of cyber attack scenarios can be simulated?
CloudGuard offers 28 different scenarios, including phishing attacks, ransomware infections, insider threats, data breaches, and more. You can select two scenarios for each exercise, with the option to add more if needed.
- Phishing Attack: Deceptive emails trick employees into revealing sensitive information or credentials
- Ransomware Infection: Malicious software encrypts files, demanding ransom for data decryption
- Data Breach: Unauthorised access compromises sensitive customer or organisational information
- Insider Threat: Disgruntled employees sabotage or steal company data or systems
- DDoS Attack: Overwhelms network, rendering services inaccessible to legitimate users
- Supply Chain Attack: Trusted vendor compromise leads to organisational supply chain disruption
- Physical Security Breach: Unauthorised access or theft of physical assets compromises security protocols
- Zero-Day Exploit: Exploits unknown software vulnerabilities, bypassing traditional security measures
- Social Engineering Attack: Manipulates human psychology to gain unauthorised access to systems
- Regulatory Compliance Violation: Failure to meet legal or industry standards results in penalties
How often should we conduct TableTop Exercises?
Regular testing is essential to staying prepared. We recommend conducting TTX sessions at least annually or whenever there are significant changes to your Incident Response Plan or business environment.
Do we need an existing incident response plan before doing a TTX?
It helps, but it isn’t essential. If you already have a plan, the exercise tests it directly and shows you exactly where it holds up and where it doesn’t. If you don’t yet have one, we can run IR Planning workshops first to build it, then use the tabletop exercise to pressure-test it once it exists.
What kind of feedback will we receive after the exercise?
After the TTX, you’ll receive a comprehensive report detailing key findings, strengths, weaknesses, and actionable recommendations for improving your Incident Response Plan. We also offer ongoing support for remediation efforts.
Will this exercise help us meet regulatory compliance?
Yes. CloudGuard’s TTX is designed to ensure your response plan meets industry regulations and compliance standards. The exercise can help you identify any gaps in your compliance efforts and take steps to close them.
Are additional scenarios or custom scenarios available?
Absolutely. While the service includes two scenarios from our standard catalogue, we can customise scenarios to suit your organisation’s specific needs. Additional scenarios can be added, with pricing adjusted accordingly.
How much does CloudGuard's Tabletop Exercise cost?
CloudGuard’s TTX is offered as a fixed-cost engagement at ÂŁ3,360. Pricing is transparent from the outset rather than open-ended consulting time. This includes selection of 2 scenarios from a library of 28 real-world attack scenarios, delivered by CloudGuard’s IR experts.Â
Fixed Pricing, No Surprises
We’ve designed our hands-on tabletop exercise workshops to test the effectiveness of your current Incident Response Plans and identify areas for improvement under real conditions. Our IR experts help make sure you’re ready for whatever comes your way.
CloudGuard’s Tabletop Exercise (TTX) workshop costs ÂŁ3,360, fixed price. This includes a selection of 2 scenarios from a library of 28, hands-on with our expert Incident Response team.
Create: Work one-on-one with our IR experts to map out a clear, usable plan your team can follow under pressure.
Strengthen: Already got a plan? We’ll review it together, identify gaps and make sure it’s fit for the real world.
Discover how CloudGuard can turn gaps into strengths with our TableTop Exercises
Experience how tailored simulations and expert feedback can elevate your incident response capabilities. CloudGuard’s TableTop Exercises provide the actionable insights and practical training you need to address vulnerabilities, enhance team coordination, and ensure compliance, so you’re always prepared for any cyber threat.