Skip to content

We are only three people, how do we tabletop an incident?

A tabletop does not need ten participants. Three people works well: exec, IT lead, and someone from the business (finance or customer contact). 90 minutes, one scenario, no tech.

Try this first

  1. 1Pick a scenario that matches your risk. For most SMBs that is ransomware on the file server, BEC with an IBAN swap, or a data breach via lost laptop. Not all three at once.
  2. 2Write the scenario as a 4-hour timeline: minute 0 (first signal), minute 30 (first recovery attempt), hour 1 (external call needed), hour 2 (customer or board pressure), hour 3 (decision point).
  3. 3Play it around a table. Someone reads the scenario, the three participants react as they would in reality. No tech executed, just describe who does what.
  4. 4Keep a list of gaps. We do not know who calls cyber insurance. Our backups are on the same share. We have no second MFA account. That is the harvest, not the drill itself.
  5. 5Right after the tabletop: five action items on a sheet, with date and owner. Fewer than five is too soft, more than five and you will not finish in a quarter.

When to bring us in

If after the tabletop you cannot tell whether your approach is realistic, ask someone with IR experience to sit in for 90 minutes. An outside voice often sees in 10 minutes what you miss in 10 drills.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.