🎯 Tabletop Exercises (TTX)

Practice the Bad Dayβ€”Safely, Quickly, with Proof

Tabletop Exercises (TTX) are facilitated, no-impact rehearsals of incidents, outages, and crises.
SolveForce runs TTX as an engineering systemβ€”clear objectives, realistic injects, time-boxed facilitation, measurable SLOs, and exportable evidenceβ€”so your teams learn fast, fix gaps, and auditors see the receipts.

Connective tissue:
🚨 IR β†’ /incident-response β€’ πŸ“Š Evidence β†’ /siem-soar
πŸ’Ύ Continuity β†’ /cloud-backup β€’ /backup-immutability β€’ /draas
πŸ”’ Security β†’ /mdr-xdr β€’ /ndr β€’ /waf β€’ /ddos β€’ /dlp
☁️ Cloud β†’ /cloud β€’ πŸ”€ Network β†’ /sd-wan β€’ πŸ” Access β†’ /ztna β€’ /nac


🎯 Outcomes (Why run TTX with SolveForce)

  • Confidence β€” teams know who does what under pressure.
  • Speed β€” measurable improvements to MTTD/MTTC/RTO and comms timelines.
  • Clarity β€” roles, authorities, and escalation paths exercised & fixed.
  • Compliance β€” auditor-ready artifacts (agenda, injects, decisions, action items).
  • Continuity β€” backups/DR playbooks validated and gaps closed.

🧭 Scope (What we exercise)

  • Cyber β€” ransomware, data exfil, BEC, identity compromise, supply-chain / vendor breach, zero-day WAF patch.
  • Availability β€” region outage, network brownout, DNS/PKI failure, CI/CD compromise.
  • Business β€” fraud spikes, carding on checkout, insider misuse, critical vendor loss.
  • Vertical-specific β€” OT/ICS faults (energy/utilities), PACS/EHR (healthcare), trading venue dislocation (finance), POS outage (retail), airport/terminal ops (aviation/maritime).

We tailor injects to your stack (EDR/XDR, SIEM/SOAR, ZTNA/SASE, SD-WAN, WAF/DLP, KMS/HSM, cloud providers).


🧱 TTX Building Blocks

  • Objectives β€” e.g., contain ransomware in ≀ 30 minutes, publish exec comms in ≀ 2 hours, restore Tier-1 app in ≀ 60 minutes.
  • Roles β€” Incident Commander, Comms Lead, IR Lead, Forensics, IT Ops, App Owner, Legal/Privacy, HR, Executive Sponsor, Third-Party/Vendor.
  • Artifacts β€” run-of-show, inject deck, decision log, SLO board screenshots, evidence export, After-Action Report (AAR).
  • Injects β€” timed prompts (screenshots, tickets, β€œcustomer” emails, regulator calls) that force decisions and show gaps.
  • Rules of Engagement β€” no production changes; β€œassume data” only where realistic; facilitator keeps time & pressure.

🧭 Session Formats

Rapid 60-minute (quarterly):
1) 0–5 min: scope & roles β€’ 5–10: scenario brief β€’ 10–45: injects β€’ 45–55: scoring β€’ 55–60: next steps.

Deep-dive 120-minute (biannual):

  • Phase 1: detection/triage β€’ Phase 2: containment/eradication β€’ Phase 3: recovery/communiΒ­cations β€’ Phase 4: legal/regulatory.
  • Optional parallel track for exec comms & customer care.

🧩 Scenario Packs (examples)

  • Ransomware + exfil (double extortion) β†’ EDR isolate, NAC quarantine, SOAR blocklists, clean-point restore, press & regulator comms.
  • Cloud key leak β†’ revoke roles/keys (KMS), SCP lockdown, rotate secrets, forensics on IaC pipeline.
  • BEC / invoice fraud β†’ identity step-up, mail tenant purge, finance controls, vendor notification.
  • DDoS + bot surge β†’ WAF rules, rate/quotas, Anycast withdraw, SD-WAN reroute, status page comms.
  • Data egress from SaaS β†’ DLP quarantine, session control (SASE), legal notification matrix.
  • OT/ICS β†’ PRP/HSR failover, PTP timing alarms, vendor access via ZTNA + PAM, config restore from immutable backups.

πŸ“ SLO Guardrails (TTX success metrics)

Metric / SLOTarget (Recommended)
MTTD (Sev-1 simulated)≀ 5–10 min (SIEM correlation)
MTTC (containment start)≀ 15–30 min (EDR/NAC/SOAR actions)
Exec comms (initial brief)≀ 60–120 min
Legal/regulatory assessment ready≀ 2–4 h
DR decision & launch (Tier-1)≀ 30–60 min
Evidence pack completeness= 100% (agenda, injects, decisions, logs)
Action item closure (critical items)≀ 30 days

We publish before/after deltas per team and per control (WAF, ZTNA, EDR, DLP, DR).


πŸ§ͺ Scoring Rubric (maturity snapshot)

  • Detection (0–5) β€” alert quality, signal routing, SIEM rules.
  • Containment (0–5) β€” speed, approvals, SOAR efficacy, blast-radius control.
  • Eradication (0–5) β€” playbooks, forensics handoff, key/secret rotation.
  • Recovery (0–5) β€” clean-point identification, backup immutability, DR runbooks.
  • Comms (0–5) β€” internal & external cadence, regulator mapping, customer care.
  • Governance (0–5) β€” roles clarity, decision logs, evidence export, follow-through.

πŸ“„ After-Action Report (AAR) template

1) Scenario & objectives
2) Timeline & decisions (who/what/when/why)
3) SLO results (hit/miss, deltas)
4) Gaps & root causes (people/process/tech)
5) Action items (owner, due date, priority)
6) Control updates (playbooks, SOAR, policies, IaC)
7) Evidence bundle (links to SIEM exports, screenshots, artifacts)


🧰 What We Exercise (controls & runbooks)

  • IR playbooks β€” ransomware, BEC, exfil, key leak, DDoS, insider, OT. β†’ /incident-response
  • SOAR automations β€” isolate/kill/block, revoke/rotate, WAF patch, DR launch. β†’ /siem-soar
  • Backup/DR β€” Object-Lock verification, clean-point catalog, warm/hot DR tiers. β†’ /cloud-backup β€’ /backup-immutability β€’ /draas
  • Access β€” ZTNA/SASE attach times, NAC quarantine, PAM elevation/recording. β†’ /ztna β€’ /sase β€’ /nac β€’ /pam
  • Boundary β€” WAF/Bot rules, DDoS posture, API quotas. β†’ /waf β€’ /ddos

πŸ› οΈ Implementation Blueprint (No-Surprise Rollout)

1) Set objectives & scope (Sev level, systems, teams, regulators).
2) Collect inputs (org chart, runbooks, contact map, SLAs/SLOs).
3) Draft scenario & injects (aligned to your stack; include red-team or vendor calls).
4) Schedule & logistics (hybrid participants, war-room chat, timer, recorder).
5) Run TTX (facilitator cadence; decision & time logging; SLO scoring).
6) AAR & evidence pack (export to SIEM; executive summary).
7) Remediate & re-test (30/60/90-day closure; follow-up micro-TTX).


βœ… Pre-Exercise Checklist

  • 🎯 Objectives, success criteria, SLOs.
  • πŸ‘₯ Participants & backups; authority to decide.
  • 🧭 Systems in scope (apps, cloud, network, identity, data).
  • 🧰 Current playbooks & approver matrix (isolation, WAF patch, DR, comms).
  • πŸ” Keys/secrets posture (KMS/HSM), break-glass accounts, vault access.
  • ☁️ Backup/DR readiness (immutable sets, recent test-restore).
  • πŸ“Š SIEM/SOAR dashboards; logging completeness; evidence destinations.
  • πŸ—“οΈ Timebox, facilitator, scribe, observers; recording policy.

🧩 Industry Packs (add-ons)

  • Healthcare (HIPAA/42 CFR Part 2), Finance (PCI/SOX/SWIFT), Public sector (NIST/CJIS/FedRAMP), OT/ICS (NERC CIP/62443), Retail (CDE), Media (pre-release content), Logistics (yard/port), Aviation/Maritime (ICAO/IMO/TSA).

πŸ”„ Where TTX Fits (Recursive View)

1) Grammar β€” simulated decisions traverse your /connectivity & /networks-and-data-centers.
2) Syntax β€” executed across /cloud and security stack via /siem-soar.
3) Semantics β€” /cybersecurity playbooks preserve truth; backups/DR prove recoverability.
4) Pragmatics β€” /solveforce-ai analyzes outcomes and proposes safe improvements.
5) Foundation β€” consistent terms via /primacy-of-language.


πŸ“ž Schedule a High-Impact Tabletop (and get evidence you can hand to auditors)


- SolveForce -

πŸ—‚οΈ Quick Links

Home

Fiber Lookup Tool

Suppliers

Services

Technology

Quote Request

Contact

🌐 Solutions by Sector

Communications & Connectivity

Information Technology (IT)

Industry 4.0 & Automation

Cross-Industry Enabling Technologies

πŸ› οΈ Our Services

Managed IT Services

Cloud Services

Cybersecurity Solutions

Unified Communications (UCaaS)

Internet of Things (IoT)

πŸ” Technology Solutions

Cloud Computing

AI & Machine Learning

Edge Computing

Blockchain

VR/AR Solutions

πŸ’Ό Industries Served

Healthcare

Finance & Insurance

Manufacturing

Education

Retail & Consumer Goods

Energy & Utilities

🌍 Worldwide Coverage

North America

South America

Europe

Asia

Africa

Australia

Oceania

πŸ“š Resources

Blog & Articles

Case Studies

Industry Reports

Whitepapers

FAQs

🀝 Partnerships & Affiliations

Industry Partners

Technology Partners

Affiliations

Awards & Certifications

πŸ“„ Legal & Privacy

Privacy Policy

Terms of Service

Cookie Policy

Accessibility

Site Map


πŸ“ž Contact SolveForce
Toll-Free: (888) 765-8301
Email: support@solveforce.com

Follow Us: LinkedIn | Twitter/X | Facebook | YouTube