Article | October 1, 2026
Cyber readiness through tabletop exercises
by Gail Carr, Advisor, Americas Intelligent Cybersecurity Advisory Services, DXC Technology
In today’s threat landscape, cyber security incidents are no longer a question of if, but when. Organizations face an increasingly complex mix of cyber threats, operational dependencies and regulatory expectations as they become increasingly dependent on cloud services, third parties, interconnected platforms and AI-enabled technologies. More than ever before, a single cyber event can quickly escalate into a business crisis, disrupting operations, interrupting customer services, exposing sensitive data, affecting supply chains and causing significant reputational damage.
The ability to respond to threat actors effectively is no longer viewed as a technical capability alone. It has become a business imperative that directly impacts operational continuity, financial performance, regulatory compliance, customer trust and organizational reputation.
Readiness is critical
Many organizations have invested significantly in cybersecurity technologies and documented response plans. They’ve put resources into developing incident response, business continuity, crisis management and disaster recovery capabilities. Yet the true measure of preparedness is not whether a plan exists, but whether leaders and response teams can execute effectively when faced with a real cyber crisis.
Unfortunately, business’ plans may not fully reflect actual escalation paths, decision authorities, communication requirements or recovery complexities. Preparedness is not demonstrated through documentation alone. Readiness is proven through practice.
This Cybersecurity Awareness Month is a great time for organizations to take the opportunity to validate their ability to respond, coordinate, communicate and recover during a disruptive cyber event. They can attain the true measure of resilience — the ability to respond effectively, recover efficiently and continuously adapt to emerging threats.
Enter the tabletop exercise (TTX)
Without practical testing of response plans through tabletop exercises, assumptions made in planning often remain unchallenged until a real incident occurs.
Ask yourself the following questions about a single critical scenario to understand if your organization’s plans have moved beyond awareness to real-world readiness:
- How would your organization respond to a major ransomware event?
- Are executive decision authorities clearly understood?
- Could communications be effectively managed during a cyber crisis?
- Is recovery prioritized and coordinated across the business?
- Has your response capability ever been validated under realistic conditions?
If the answer to any of these questions is uncertain, a tabletop exercise can help provide clarity.
A tabletop exercise helps organizations answer critical questions to the ransomware scenario and many others — insider threats, third-party and supply chain compromises, cloud security incidents, data breaches, operational technology attacks, AI-enabled cyber threats — by providing a controlled environment for testing and interfacing before a real cyber incident places the organization under pressure.
When responding to a cyberattack of any kind, organizations must coordinate multiple functions simultaneously. This raises questions including:
- Who has authority to initiate containment actions?
- When should executive leadership be engaged?
- How are external communications managed and approved?
- What business services receive recovery priority?
- What third parties need to be involved?
- How will recovery efforts be validated before systems return to production?
- If/when do I need to inform the authorities?
Tabletop exercises provide a safe and structured environment for organizations to validate assumptions and make better assessments. By simulating realistic scenarios, participants can evaluate decision-making, communication, coordination and recovery processes while identifying opportunities for improvement before a real-world incident occurs.
Tabletop exercises are not one-size-fits-all. Different audiences have distinct roles during a cyber crisis, and each should be tested through scenarios tailored to their responsibilities. Exercises may focus on:
- Executive (C-suite and board) exercises emphasize strategic decision-making, business impact, regulatory obligations, stakeholder communications and organizational risk.
- Technical exercises focus on incident response, threat containment, forensic investigation, system recovery and operational restoration.
- Enterprise-wide exercises bring together executives, IT, security, legal, human resources, communications, business operations, third-party vendors and other stakeholders to validate end-to-end crisis management and organizational resilience.
By incorporating different threat scenarios, varying levels of complexity and diverse participant groups, exercises help ensure that strategic, operational and technical capabilities are all tested and strengthened.
How DXC supports tabletop exercises
Available through DXC Intelligent Cybersecurity Advisory Services, DXC Technology's Cyberattack Tabletop Exercise approach provides customized, business-relevant scenarios that enable participants to develop confidence in their response and recovery capabilities while uncovering gaps, dependencies, and opportunities for continuous improvement.
A DXC-facilitated tabletop exercise helps:
- Leaders gain experience making high-impact decisions involving ransomware, operational disruption, legal obligations, customer impact, business continuity and recovery.
- Security, IT, legal, communications, business operations, executive leadership and third-party stakeholders develop a common operating picture and strengthen collaboration.
- Organizations evaluate not only how to restore systems, but how to recover trusted business operations while reducing the risk of reinfection or recurring compromise.
- Enterprises find unclear responsibilities, communication bottlenecks, process weaknesses, recovery challenges and hidden operational dependencies.
- Organizations translate exercise observations into measurable improvements.
The Cyber Readiness Cycle: A Framework for Modern Resilience
Tabletop exercises provide organizations the greatest value when they are conducted as part of an ongoing, regularly tested and updated cyber resilience program — a continuous cycle of awareness, assessment, protection, exercise, recovery and improvement.
Each iteration strengthens an organization's ability to anticipate threats, coordinate response activities, restore trusted operations, measure progress over time, and adapt to an evolving threat landscape and increasingly complex decision-making challenges. And each ensures that strategic, operational and technical teams are prepared to respond effectively and work together during a significant cyber event.
Cyber resilience is ultimately a people, process and governance effort as much as it is a technology challenge. As such, you must prepare your teams to enact their incident response plans, making rapid decisions while operating in stressful and challenging environments with incomplete information, competing priorities, regulatory obligations, operational disruptions and increased scrutiny from customers, partners and stakeholders.
Recovery is more than restoring systems
One of the most important lessons organizations learn during a tabletop exercise is that restoring technology does not automatically mean the threat has been eliminated. Recovery is achieved when the organization can confidently resume trusted business operations, critical services and stakeholder commitments.
A tabletop exercise helps organizations understand how to coordinate critical recovery activities when business pressure is highest.
True Recovery Requires a Six-Step Approach
Organizations should be prepared to execute these activities in coordination:
- Prioritize critical business services — Understand which services are mission-critical and restore them in order of business importance, not technical convenience.
- Protect and preserve evidence — Ensure forensic evidence is collected and preserved for investigation and potential legal proceedings.
- Confirm data availability — Validate that restored data is complete, uncorrupted and usable.
- Coordinate recovery across multiple stakeholders — Manage recovery activities involving internal teams, third-party vendors, cloud providers, business units and external partners.
- Validate system integrity — Confirm that restored systems are clean, secure and functioning as intended.
- Reduce the likelihood of recurring compromise — Implement remediation to prevent attackers from re-entering the network using the same vulnerabilities.
Different perspectives, stronger readiness
Organizations frequently state that they already conduct tabletop exercises internally. While these efforts provide significant value — often excelling at validating existing processes and familiarizing teams with organizational procedures — cyber resilience is strengthened not only through continuous practice, but different threat scenarios, varying levels of complexity, different participant groups and diverse perspectives.
Different facilitators, such as DXC, bring unique experiences, industry insights and lessons learned from the real-world. They can provide an objective perspective by identifying hidden dependencies, governance gaps, communication challenges, recovery obstacles and risks that may have become normalized over time.
Always remember that your goal is to achieve the end game of cyber resilience. Cyber awareness builds understanding. Cyber readiness builds confidence. Cyber resilience is achieved when organizations continuously test, improve and validate their ability to respond, recover and adapt to evolving threats, with significant value gained from tabletop exercises.