Free tabletop exercises you can actually run. Full scenario packs. Inject timelines, facilitator notes, after-action templates. No signup, no vendor pitch, no lead capture form.
I've run more than fifty of these. Almost everything out there is either locked behind a consulting engagement or it's one guy's meeting notes. This is what I'd hand somebody who has to facilitate one next week.
The Bad Guys Only Have to Be Right Once. We Have to Be Right Every Time. 99% is a failing grade.
Nobody can be right every time by themselves. A company where everybody has practiced once gets close. Security Is a Team Sport, and a tabletop is the cheapest practice you'll ever run.
Half the value is watching four people in the room realize they each thought somebody else had it. No One Is as Dumb as All of Us.
More in PRINCIPLES.md.
- Security leaders who need to run one and don't have vendor budget
- IR teams who'd rather practice than perform cold
- vCISOs and consultants who need a starting point to tailor
- Anybody who got told "we should do a tabletop" and has no idea where to start
Anybody looking for a red team or a technical simulation. This is people talking in a room.
And these aren't turnkey. Every scenario needs rewriting for your environment or people check out in the first ten minutes.
| Scenario | Who's in the room | Runtime |
|---|---|---|
ransomware-exfil/ |
Exec, IT, Legal, Comms | 2-3 hrs |
vendor-compromise/ |
Exec, IT, Procurement, Legal | 2 hrs |
insider-threat/ |
Exec, HR, Legal, IT | 2 hrs |
ot-plant-event/ |
Plant Ops, Engineering, IT, Exec | 3 hrs |
ai-agent-incident/ |
Exec, Engineering, Security, Legal | 2 hrs |
Want one that isn't here? Open an issue.
An agent with too much access does something destructive nobody asked for. Nobody can tell if it got compromised, got misconfigured, or did exactly what it was built to do.
I haven't seen this published anywhere. It's also the thing most companies are least ready for. Everybody deploying agents right now should run something like it. Almost nobody has thought about it. It pairs with the agent control checklist in ai-governance-kit, the rubric and that checklist are the same document at two altitudes.
Security-Lessons is 727 of them, and the real-incident collections are half-written tabletops already. Pick a story the room already knows and build the injects backward from it.
scenario-name/
├── README.md what it is, how to set up
├── facilitator-guide.md run sheet, where people get stuck, when to push
├── participant-brief.md what players see beforehand (not much, on purpose)
├── injects.md timed injects with delivery notes
├── roles.md who should be in the room
├── evaluation-rubric.md what good looks like at each decision
└── after-action-template.md
Two Weeks Out. Pick a scenario. Read the facilitator guide end to end. Rewrite the details to match your world. Real system names, real vendors, real people. Generic scenarios get generic engagement.
A Week Out. Send the participant brief. Book a room. No laptops. Confirm your exec sponsor is coming, because if they skip it everybody learns it was optional.
Day Of. Start on time. Read the scenario out loud. Run injects on the clock, not when the conversation gets quiet. Your job is keeping pressure on, not teaching.
Within 48 Hours. Write the after-action while it's fresh. Every gap gets a name and a date. An exercise with no follow-up is theater.
Don't Let It Turn Technical. The second two engineers start arguing about EDR config, you've lost it. Pull them back to decisions.
Silence Is Data. If nobody knows who declares an incident, that's your finding. Don't rescue them.
Watch for the Confident Wrong Answer. The guy who says "legal would handle that" with total certainty, when legal isn't in the room and has never been asked, just showed you a real gap.
Nobody Is Supposed to Pass. If your team sails through, it was too easy and you learned nothing. Make it hurt a little.
Training exercises. Not compliance evidence, not legal guidance, not a substitute for a tested IR plan. Running a tabletop doesn't make you ready. Fixing what it turns up does.
Nothing here comes from a client engagement. Everything is built from common patterns.
Scenarios welcome, especially from sectors that aren't well covered here. Healthcare, education, municipal, financial services.
Complete packs only. A scenario without injects and a facilitator guide isn't usable. Nothing client-identifiable. See CONTRIBUTING.md.
CC BY 4.0. Run these commercially, change them, build a service on them. Just say where you got them.
© 2026 Harrison Ward
Cyber risk and technology exec. 50 plus tabletops and IR readiness engagements across regulated and critical infrastructure. Former CTO. Most recently SVP in Kroll's Cyber Risk practice.
github.com/HarrisonWard · LinkedIn
Published under these principles. Security Shouldn't Be Paywalled.