In this guide
A tabletop exercise is a discussion that tests how people would respond to an invented incident. It should reveal missing decisions and dependencies without changing live payroll, exposing real employee records or sending alarming messages to workers. Label the exercise clearly from the start.
The FTC’s data-breach response guide emphasizes response coordination, preserving evidence and accurate communications. This exercise uses those principles as context. It is not an incident-response service, a technical containment instruction or a determination of legal notification duties.
Set a bounded exercise
Choose one scenario, the participating roles and the decisions to test. Include payroll, HR, finance, security or IT, an authorized incident coordinator and appropriate legal/privacy support. Invite the provider’s designated contact only through your authorized relationship and agree whether its participation is a simulation or an actual service test.
Use invented people, record identifiers and amounts. State that no live access changes, payment actions or worker notifications are authorized by the exercise. Keep the facilitator’s materials separate from the operational incident channel so fictional facts cannot later be mistaken for a real report.
Stage one: a credible but incomplete report
Present this fictional prompt: “A payroll reviewer notices an unexpected payment-related change in an approved preview. The ordinary administrator says they did not make it. The next processing step is approaching.” Ask participants what they know, what they only suspect and who can verify the current status.
A strong discussion identifies the affected workflow, preserves the relevant references and brings the correct authority into the decision. A weak discussion jumps directly to blaming a person or announcing a breach. Neither the cause nor the full scope is established by the prompt.
Stage two: conflicting information
Add a second prompt: “The provider confirms receipt of a changed input, but the internal request log has no corresponding approved instruction.” Ask which party can supply change evidence, who can decide about the pending run and what protected channel should carry sensitive details.
Do not score the team on whether it guesses the fictional cause. Score whether it distinguishes facts from hypotheses and makes an accountable decision with the available evidence. The facilitator can note gaps such as an inaccessible contact list, unclear backup authority or no agreed route for urgent provider escalation.
| Record | Example prompt | Purpose |
|---|---|---|
| Verified fact | Which system or person confirmed this status? | Prevent rumor from becoming the operating record |
| Open question | What evidence would change the next decision? | Focus investigation on consequential uncertainty |
| Decision owner | Who can authorize the proposed action? | Separate coordination from approval |
| Communication | Who needs what accurate information now? | Avoid premature or misleading statements |
| Follow-up | What must be verified after the action? | Keep recovery from ending at the first reassuring message |
Stage three: recovery is not yet closure
For the final prompt, say the immediate processing issue has been handled through an authorized path. Ask what remains: reconcile the original and corrective records, establish affected scope, preserve evidence, review access, assess communications and determine whether the control defect recurs elsewhere.
The FTC guide warns against destroying evidence and notes that notification requirements depend on applicable law and the information involved. Have qualified responders decide preservation, containment and notification in a real event. A tabletop script must not become a universal legal deadline or an instruction to delete logs.
Turn findings into specific repairs
Record the gap, consequence, owner, proposed repair and proof that the repair works. “Improve communication” is not testable. “An authorized backup can retrieve the current provider escalation contact from the approved directory” is testable without creating a live incident.
Rehearse the repaired step after it changes. If the exercise revealed that only one person can access a critical report, adding a backup name to a document is insufficient; the backup must have approved access and know which evidence to retrieve.
Keep a short management summary
Summarize what was tested, the limits of the exercise, material gaps and completed repairs. Do not claim the exercise proves breach prevention or full operational resilience. A discussion can test decision-making; it does not automatically test bank processing, restoration or a provider’s real response time.
Use the funding exception playbook for a separate timing scenario and the access review for permissions revealed by the exercise. Revisit the scenario after a meaningful platform, personnel or workflow change, rather than relying indefinitely on an old rehearsal.