Pospíšil Petr | CyberPOPE Independent Consultant | Cybersecurity Architect & vCISO

Tabletop
Exercises

A simulated cyber incident, played out in one afternoon. Your team makes the decisions - the gaps surface now, not during a breach.

2-4 h session · 4-12 per team · CZ / EN · from €2,000

This exercise is available on its own - the better path is the Retained Security Partner retainer, where you get it automatically once your security maturity is ready.

The Problem

An incident plan nobody has rehearsed

  • Nobody is sure who declares the incident, who calls the lawyer, who tells customers.
  • Escalation lives in one person's head. Decisions that need minutes take hours.
  • "Do we pay?" gets debated for the first time under real pressure.

ISO 27001 and the CIS Controls both expect incident response to be exercised, not just documented. Where NIS2 applies, management is accountable for it.

The Exercises

Choose your exercise

01 2-3 h

Executive Tabletop

For boards and leadership teams

  • The ransom decision
  • Disclosure to customers & regulator
  • Statement to the press
02 3-4 h

Operational Tabletop

For IT and security teams

  • Escalation & triage choices
  • Handover between IT and management
  • Evidence vs. fast recovery
03 scoped

Tailored Tabletop

For any team, any seniority

  • Mixed groups, cross-department
  • 4-12 per team, parallel teams
  • Objectives set at scoping

Non-profits: pro-bono or discounted exercises possible for selected organisations. Ask.

Scenarios

Known attack paths, played on your organisation

Most incidents follow well-known paths. The exercise follows them too - tailored to your size, your teams, and your pain points.

Ransomware

Systems encrypted, deadline running. Who decides - and what do customers hear on day one?

Supply chain compromise

Your key vendor is breached. What do your contracts give you - and what is plan B?

Data breach

Personal data gone, the 72-hour GDPR clock running. Legal, comms, and investigation compete for the same people.

Departing insider

An admin leaves on bad terms. What can they still reach, what did they take - and who notices?

Deepfake & AI abuse

A fake video of your CEO is spreading - and a cloned voice is asking finance to pay. Reputation first, fraud close behind.

Your scenario

The incident that worries you most - built from your environment at scoping.

Delivery

Structured, not chaotic

The exercise runs on a purpose-built exercise platform: the scenario keeps moving, and the debrief works from evidence, not memory.

Timed injects

An inject - an email, a call, a media report - arrives on a managed timeline. Pressure stays realistic.

Every decision logged

Responses, decisions, and timing captured as the exercise runs.

Parallel teams

Teams of 4-12 play the same scenario, compared side by side.

Objective debrief

Where time was lost, which decisions stalled, what nobody noticed.

On-site, facilitated

Preferred for executive groups. Travel is billed separately - most economical when combined with other on-site work.

Remote / online

Suits smaller exercises and remote-first teams - practise where the incident would hit you.

Method: Aligned with NUKIB & ENISA exercise guidance

Requirements

Inputs I need from you

Required inputs

A sponsor and objectives. One scoping call settles what the exercise tests.

The right people in the room. Those who would own the incident, 4-12 per team.

Honest input on how things work. Key systems, suppliers, decision-makers.

Book at least one month ahead. Scenario and inject design take time.

No incident response plan? Not a blocker.

A first exercise is the fastest way to find out what your plan must contain. If you have one, the exercise shows exactly where to revise it.

Pricing

Indicative pricing

Starting from
€2,000
per exercise
excl. travel
Always included
Scoping call & objectives
Tailored scenario & injects
2-4 hour facilitated session
Czech or English
Hot debrief after the exercise
After-action report with prioritised fixes
Audit-ready evidence for ISO 27001 / NIS2
Follow-up review call

What affects the final price

Group Size & Parallel Teams

One team of 4-12 is the baseline; each extra team adds facilitation and debrief work.

On-site Travel

Flights, hotel, and travel time are not included in the exercise price and are billed separately - most economical combined with other on-site work.

Scenario Depth 1 month lead time

A single-thread scenario costs less than a deep simulation of your suppliers and media pressure.

Send a Question Book a call

Fixed-price quote after the call. No surprises.

Process

How We Collaborate

01
Scoping call

Objectives, audience, format, language. 30 minutes, free.

02
Scenario & inject design

Written from your systems, suppliers, and decision chain. This is the month of lead time.

03
Exercise day

2-4 hours, facilitated. Injects on a timeline, decisions logged, hot debrief at the end.

04
Report & follow-up

After-action report with prioritised fixes, plus a follow-up call a few weeks later.

Book at least one month ahead - the scenario is written from your inputs, not pulled off a shelf.

After the Exercise

The findings need an owner

The exercise will almost certainly surface gaps in your incident response. The after-action report turns them into a prioritised fix list - what you do with it is up to you.

If you want help, the Retained Security Partner retainer works through the findings with you - steadily, at your tempo.

Scope an exercise

A free 30-minute call settles objectives, audience, and format - before you commit to anything.

Have questions? See the FAQ →

Hands-on labs or workshops instead? See Trainings & Workshops.

Whole-workforce behaviour change? See the Human Risk Programme.