Skip to content

Repository files navigation

Tabletop Library

Free tabletop exercises you can actually run. Full scenario packs. Inject timelines, facilitator notes, after-action templates. No signup, no vendor pitch, no lead capture form.

I've run more than fifty of these. Almost everything out there is either locked behind a consulting engagement or it's one guy's meeting notes. This is what I'd hand somebody who has to facilitate one next week.


Why We Do This

A hundred squares. Ninety-nine grey. One orange.

The Bad Guys Only Have to Be Right Once. We Have to Be Right Every Time. 99% is a failing grade.

Nobody can be right every time by themselves. A company where everybody has practiced once gets close. Security Is a Team Sport, and a tabletop is the cheapest practice you'll ever run.

Half the value is watching four people in the room realize they each thought somebody else had it. No One Is as Dumb as All of Us.

More in PRINCIPLES.md.


Who It's For

  • Security leaders who need to run one and don't have vendor budget
  • IR teams who'd rather practice than perform cold
  • vCISOs and consultants who need a starting point to tailor
  • Anybody who got told "we should do a tabletop" and has no idea where to start

Who It's Not For

Anybody looking for a red team or a technical simulation. This is people talking in a room.

And these aren't turnkey. Every scenario needs rewriting for your environment or people check out in the first ten minutes.


Scenarios

Scenario Who's in the room Runtime
ransomware-exfil/ Exec, IT, Legal, Comms 2-3 hrs
vendor-compromise/ Exec, IT, Procurement, Legal 2 hrs
insider-threat/ Exec, HR, Legal, IT 2 hrs
ot-plant-event/ Plant Ops, Engineering, IT, Exec 3 hrs
ai-agent-incident/ Exec, Engineering, Security, Legal 2 hrs

Want one that isn't here? Open an issue.

About the AI Agent One

An agent with too much access does something destructive nobody asked for. Nobody can tell if it got compromised, got misconfigured, or did exactly what it was built to do.

I haven't seen this published anywhere. It's also the thing most companies are least ready for. Everybody deploying agents right now should run something like it. Almost nobody has thought about it. It pairs with the agent control checklist in ai-governance-kit, the rubric and that checklist are the same document at two altitudes.

Need More Scenario Seeds

Security-Lessons is 727 of them, and the real-incident collections are half-written tabletops already. Pick a story the room already knows and build the injects backward from it.


What's in Each Pack

scenario-name/
├── README.md              what it is, how to set up
├── facilitator-guide.md   run sheet, where people get stuck, when to push
├── participant-brief.md   what players see beforehand (not much, on purpose)
├── injects.md             timed injects with delivery notes
├── roles.md               who should be in the room
├── evaluation-rubric.md   what good looks like at each decision
└── after-action-template.md

Running One

Two Weeks Out. Pick a scenario. Read the facilitator guide end to end. Rewrite the details to match your world. Real system names, real vendors, real people. Generic scenarios get generic engagement.

A Week Out. Send the participant brief. Book a room. No laptops. Confirm your exec sponsor is coming, because if they skip it everybody learns it was optional.

Day Of. Start on time. Read the scenario out loud. Run injects on the clock, not when the conversation gets quiet. Your job is keeping pressure on, not teaching.

Within 48 Hours. Write the after-action while it's fresh. Every gap gets a name and a date. An exercise with no follow-up is theater.


Facilitator Notes That Matter

Don't Let It Turn Technical. The second two engineers start arguing about EDR config, you've lost it. Pull them back to decisions.

Silence Is Data. If nobody knows who declares an incident, that's your finding. Don't rescue them.

Watch for the Confident Wrong Answer. The guy who says "legal would handle that" with total certainty, when legal isn't in the room and has never been asked, just showed you a real gap.

Nobody Is Supposed to Pass. If your team sails through, it was too easy and you learned nothing. Make it hurt a little.


What This Isn't

Training exercises. Not compliance evidence, not legal guidance, not a substitute for a tested IR plan. Running a tabletop doesn't make you ready. Fixing what it turns up does.

Nothing here comes from a client engagement. Everything is built from common patterns.


Contributing

Scenarios welcome, especially from sectors that aren't well covered here. Healthcare, education, municipal, financial services.

Complete packs only. A scenario without injects and a facilitator guide isn't usable. Nothing client-identifiable. See CONTRIBUTING.md.


License

CC BY 4.0. Run these commercially, change them, build a service on them. Just say where you got them.

© 2026 Harrison Ward


Me

Cyber risk and technology exec. 50 plus tabletops and IR readiness engagements across regulated and critical infrastructure. Former CTO. Most recently SVP in Kroll's Cyber Risk practice.

github.com/HarrisonWard · LinkedIn


Published under these principles. Security Shouldn't Be Paywalled.

About

Ready-to-run tabletop exercises: scenarios, injects, facilitation notes, and after-action templates. Practice the bad day before it happens.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors