Scenarios for Tabletop Exercises for Cyber Resilience at Boards

A tabletop exercise is not a compliance checkbox. It is the only mechanism that forces boards, legal counsel, communications leads, and operations teams to confront the same question at the same moment: what do we actually do when this happens?

The scenarios below are drawn from real attack patterns. Each one has claimed victims across industries. None requires a sophisticated adversary — most begin with a single human decision made under pressure, without adequate training or protocol. Leadership should use these scenarios to stress-test their organisation’s readiness, identify ownership gaps, and confirm that documented controls translate to practiced behaviour.

01
Business Email Compromise · Finance

Finance Team Under BEC Pressure

A mid-sized manufacturing company is in the final week of a financial quarter. The finance director receives an urgent email from the CEO requesting a same-day wire transfer to a new supplier. The email domain is one character different from the real domain. No one pauses to check.

Risk Trigger
No security awareness training delivered to finance staff in 18 months. No verification protocol exists for out-of-band payment requests.
Operational Impact
If approved, the transfer is irrecoverable within hours. Typical BEC losses range from tens of thousands to several million dollars in a single transaction.
What Good Response Looks Like
Finance staff trained in BEC scenarios immediately recognise the out-of-band request pattern and follow a verbal verification protocol before acting. The suspicious email is reported to the SOC within minutes.
Exercise Question
“Who in this room would have approved this transfer? What stopped them?”
Metric Leadership Should Ask For
Percentage of finance staff who have completed BEC-specific simulation in the past 90 days, and the current mean time to report suspicious payment requests.
02
Vishing · IT Support

Ransomware Entry Through a Helpdesk Agent

A helpdesk agent receives a call from someone claiming to be a regional manager locked out of their account while travelling. The caller provides enough personal information — name, department, approximate location — to appear convincingly credible. The agent wants to help.

Risk Trigger
The agent has not received training on social engineering via voice (vishing). There is no callback verification procedure in the helpdesk playbook.
Operational Impact
A password reset grants the attacker authenticated access. Within 72 hours, ransomware is deployed across six servers. ERP systems are offline for eleven days.
What Good Response Looks Like
The agent follows a mandatory identity verification callback to the employee’s registered mobile — not the number provided by the caller. The request is flagged to the security team for review.
Exercise Question
“Is our helpdesk playbook strong enough to stop a convincing caller? When was it last tested?”
Metric Leadership Should Ask For
Percentage of IT support staff who have completed vishing simulation in the past quarter, and whether callback verification is embedded in the helpdesk process.

Board Insight — Human Vectors Are the Entry Point

Scenarios 1 and 2 share a common thread: the attacker never touched a firewall. Both succeeded — or would have succeeded — because of an untrained human making a decision under time pressure. Boards should ask whether their controls address the human layer with the same rigour as technical infrastructure.

03
Deepfake Fraud · Executive Finance

Board-Level Deepfake Authorisation

A finance officer receives a short voice message — apparently from the CFO — authorising a large emergency transfer to an escrow account in connection with an acquisition. The voice is convincing. The context is plausible. No one has told the finance team that cloning an executive’s voice now takes minutes and a public audio sample.

Risk Trigger
No executive-level security awareness training has addressed voice-cloning and deepfake fraud. No authorisation protocol requires multi-channel verification for large transfers.
Operational Impact
The transfer is made. The acquisition is fictitious. Recovery requires legal action with an uncertain outcome.
What Good Response Looks Like
A policy exists: voice-only authorisation is never sufficient above a defined threshold. A confirmed written authorisation from a verified email address is required. Finance staff have been trained on this protocol and understand the deepfake risk context.
Exercise Question
“If someone rang one of our finance team today impersonating our CEO — what stops the transfer?”
Metric Leadership Should Ask For
Whether executive-level deepfake awareness has been delivered in the past 12 months, and whether a dual-channel authorisation policy exists and is tested.
04
Spear Phishing · Privileged Access

Cloud Administrator Targeted Through LinkedIn

A cloud infrastructure administrator is contacted on LinkedIn by someone claiming to represent a technology vendor. Over three weeks, a rapport is built through professional conversation. Eventually, a malicious link is shared as part of a “system integration document.” The administrator clicks because trust has been cultivated deliberately.

Risk Trigger
The administrator has elevated cloud privileges and has not received targeted spear-phishing simulation reflecting their role and external professional profile.
Operational Impact
The link deploys a credential harvester. Within 48 hours, the attacker has access to cloud tenancy administration with near-unlimited lateral movement capability.
What Good Response Looks Like
Role-specific simulation has prepared the administrator to treat unsolicited external documents with scepticism regardless of relationship context. The administrator reports the link before clicking.
Exercise Question
“Which of our highest-privilege staff are visible on LinkedIn? Have they received simulation that reflects that exposure?”
Metric Leadership Should Ask For
Whether cloud administrators are included in high-privilege simulation campaigns, and what the current report rate is for this population.

Board Insight — Privilege Is Proportional Risk

Scenarios 3 and 4 illustrate that the most dangerous targets are not random — they are chosen. Executives control financial authorisation. Cloud administrators control infrastructure. Boards should ask whether their highest-privilege population receives proportionally more rigorous and role-specific training, not a generic awareness module.

05
Regulatory Exposure · Breach Aftermath

Regulatory Inquiry Following a Breach

A bank reports a data breach involving customer account information. CERT-In issues a notice requiring the organisation to demonstrate that its employees received documented cybersecurity awareness training in the period leading up to the incident. The security team searches for evidence. There is none.

Risk Trigger
Training was delivered informally through team briefings with no documentation, no assessment records, and no simulation history.
Operational Impact
The organisation cannot produce evidence of a functioning human risk control. This compounds regulatory exposure beyond the breach itself, potentially affecting the licence review and triggering mandatory public disclosure.
What Good Response Looks Like
The organisation produces time-stamped training records, simulation campaign results, and a governance trail showing human risk was treated as a managed control with executive oversight. The regulatory narrative shifts from negligence to demonstrated good-faith effort.
Exercise Question
“If we received a CERT-In notice tomorrow, what documentation could we put in front of a regulator by end of day?”
Metric Leadership Should Ask For
Whether training documentation is audit-ready, whether simulation results are archived by date and department, and whether the programme has been reviewed by the audit committee in the past 12 months.
06
Crisis Management · Ownership Gaps

Tabletop Exercise Reveals a Critical Gap

A financial services firm conducts its first facilitated tabletop exercise simulating a ransomware attack. The scenario progresses from initial phishing entry to encrypted systems within 48 hours. Then comes the question that stops the room: who is responsible for notifying the regulator? The CISO assumes the CEO will lead crisis communication. The CEO assumed the CISO would handle it.

Risk Trigger
Legal, communications, HR, and operations teams have different assumptions about decision authority, regulatory notification responsibility, and customer communication ownership.
Operational Impact
In a real incident, this ownership ambiguity would result in regulatory notification delays — violating CERT-In’s 6-hour reporting requirement — inconsistent customer messaging, and decisions made under crisis pressure without a command structure.
What Good Response Looks Like
The exercise outputs a documented crisis response playbook with named owners, escalation thresholds, communication templates, and regulatory notification timelines. A follow-up exercise six months later validates the improvements.
Exercise Question
“On day one of a ransomware incident — who calls the regulator, who calls customers, and who makes the decision to pay or not pay?”
Metric Leadership Should Ask For
Whether a crisis command structure with named owners has been documented, tested, and reviewed by legal and compliance in the past 12 months.
07
Supply Chain Risk · Third Parties

Third-Party Staff Without Awareness Coverage

An organization relies heavily on an outsourced customer service vendor who operates with direct connections into internal CRM platforms. An outsourced agent clicks a malicious attachment on their personal email client while active on a company workstation endpoint. The infrastructure boundary fails to contain it.

Risk Trigger
Third-party operators and contractors with privileged access are entirely excluded from the enterprise’s continuous awareness training and phishing simulations.
Operational Impact
The endpoint compromise serves as a pivot point. Threat actors exfiltrate highly sensitive CRM records across 40,000 corporate identities, triggering severe regulatory review metrics.
What Good Response Looks Like
Vendor management policy mandates baseline simulation metrics for any third parties interacting with data environments. Third-party risk accounts for human susceptibility variables cleanly.
Exercise Question
“Are third-party agents who handle our data included in our security simulations? If not, why?”
Metric Leadership Should Ask For
The exact proportion of privileged vendors or external supply chain nodes that participate in active internal human baseline risk programs.

Board Insight — Your Perimeter Is Wider Than You Think

Scenarios 5, 6, and 7 share a common failure mode: the assumption that because something exists internally, it also extends externally. Documentation does not extend to vendors by itself. Ownership is not inherited — it must be assigned. Boards should ask whether the same governance standards applied to employees are contractually required of every privileged third party.
Ready to test your resilience?

Run a Cybersecurity Drill in Your Organisation

These scenarios are most powerful when they are live — when real decision-makers face them in real time, under facilitated conditions that surface the gaps that documents and policies cannot. Our experts design and facilitate bespoke tabletop exercises for boards and leadership teams across industries.

Scenarios tailored to your sector and risk profile
Board and C-suite facilitation experience
Actionable gap closure report post-exercise
Regulatory evidence documentation included

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top