Cyber tabletop exercises · Australia

Cyber security tabletop exercises
that prepare you for the real thing.

Practise your response to ransomware, data breaches and supply chain attacks before they happen. Facilitated exercises for Australian boards, executives and technical teams.

What is a cyber security tabletop exercise?

A cyber security tabletop exercise is a facilitated, discussion-based simulation of a cyber incident. Your team sits around a table (or a video call) and works through a realistic scenario as it unfolds: a ransomware attack at 2am, customer data appearing online, a key supplier going dark.

Nothing is touched in your systems. What gets tested is far more important: who decides, how fast, with what information, and whether your incident response plan holds up under pressure. Most organisations discover gaps they would never find on paper.

  • 2 to 3 hoursper facilitated session
  • 6 scenariostailored to your organisation
  • Board-readyafter-action report
  • Australia-widein person or online

Exercise types

Executive and Board crisis exercise

Your leadership team works through a major cyber incident: decisions, regulator reporting, customer communications and when to brief the Board. Focused on judgement, not technology.

For: CEO, executives, Board members

Technical incident response tabletop

Your security and IT teams walk through detection, containment, evidence, recovery and escalation step by step, testing the playbooks they would actually use.

For: SOC, IT operations, security team

Ransomware simulation

The scenario most Australian organisations fear most: encryption, data theft and extortion, including the ransom decision and the 72-hour payment reporting rule.

For: Executives and technical leads together

Third-party and supply chain breach

A supplier holding your data or running a critical service is compromised. Tests contracts, notification paths and how quickly you can cut or keep the connection.

For: Procurement, risk, security, legal

Data breach and NDB notification

Personal information is exposed. Tests the Notifiable Data Breaches assessment, OAIC notification, customer messaging and media handling.

For: Privacy, legal, communications, executives

Critical infrastructure and OT incident

An attack spreads from IT towards operational technology. Tests SOCI incident reporting, safety decisions and recovery of essential services.

For: Operations, engineering, security, executives

Why Australian organisations run tabletop exercises

Reporting deadlines in Australia are short, and they start when you become aware of an incident, not when you are ready. A tested plan is the difference between meeting them calmly and missing them.

Beyond compliance, exercises build the muscle memory that matters at 2am: knowing who calls whom, who can approve what, and what to say to customers. Read cyber risk reporting for boards for how to turn the results into board-level insight.

How an exercise works

  1. 01

    Scope

    We agree objectives, participants and the plans to test: your incident response plan, business continuity plan and crisis communications.

  2. 02

    Design

    I build a realistic scenario around your environment and the current Australian threat landscape, with timed injects that escalate pressure.

  3. 03

    Facilitate

    A 2 to 3 hour session, in person or online. Teams make decisions in real time while I play attacker, regulator, journalist and customer.

  4. 04

    Report

    An after-action report with what worked, the gaps found, a prioritised improvement plan and a one-page summary for the Board.

Free tabletop exercise games · Updated for 2026

Five threats making headlines. Can you handle them?

Pick a scenario based on attacks hitting organisations right now: ransomware, deepfake fraud, help desk social engineering, rogue AI agents and fake remote IT workers. Timed decisions, a resilience rating and an expert debrief grounded in Australian obligations.

Incident --:-- Ready
Operations 60
Reputation 60
Compliance 60

Ransomware simulation · 6 decisions · about 3 minutes

It’s 2:07am.
Your phone is ringing.

You are the executive on call. Encryption is spreading and the attackers have your data. Contain it, report it and recover it without losing the organisation.

25 seconds per decision. Fictional scenario. Nothing you choose is stored or sent anywhere.

Frequently asked questions

What is a cyber security tabletop exercise?

A discussion-based exercise in which your team works through a realistic cyber incident scenario, such as ransomware or a data breach, to test plans, decisions and communication before a real incident happens. No systems are touched.

How often should we run a tabletop exercise?

At least once a year, and after major changes such as a new incident response plan, a restructure, a merger or a significant incident. Many organisations alternate an executive exercise and a technical exercise during the year.

Who should take part?

It depends on the exercise. Executive exercises involve the CEO, executives and often Board members; technical exercises involve security and IT teams. The most valuable exercises also include legal, communications, privacy and operations.

How long does a tabletop exercise take?

The session itself usually takes 2 to 3 hours. Preparation takes one to two weeks, and the after-action report is delivered shortly after the session.

Is a tabletop exercise the same as a penetration test or breach and attack simulation?

No. Penetration testing and breach and attack simulation tools test your technology. A tabletop exercise tests your people, plans and decisions. They complement each other.

Do Australian regulations require incident response testing?

Several frameworks expect it. APRA CPS 234 requires regulated entities to annually review and test their information security response plans, Systems of National Significance can be required to undertake cyber security exercises under the SOCI Act, and ISO 27001 expects incident response to be planned and prepared. Testing your plan is also the best way to meet short reporting deadlines in practice.

Ready to test your incident response?

Tell Sentinel about your organisation and the scenario you are most worried about. Muhammad will follow up with a tailored exercise plan.

Talk to AI Agent