
Cybersecurity Tabletop Exercises
From Planning to Execution
Two veteran security consultants walk through planning, running, and following up on tabletop exercises, from technical incident-response drills to executive-level and cross-functional scenarios.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Robert Lelewski,John Hollenberger
- Published
- 2024
- Publisher
- No Starch Press
- Pages
- 200
- Language
- English
Read this if
Incident responders, security managers, and anyone tasked with improving an organization's readiness who needs to actually run a tabletop, not just read about why they matter. Includes ready-to-adapt scenarios, injects, and storyboards for technical, executive, and cross-functional exercises.
Skip this if
Readers looking for incident-response technique itself (forensics, containment, eradication); this book is about rehearsing and testing a response plan, not executing one. Pair with Incident Response and Computer Forensics or Intelligence-Driven Incident Response for that side.
Key takeaways
- Splits cleanly into process (how to plan, facilitate, and evaluate an exercise) and content (ready-made scenarios across technical, executive, and cross-functional levels).
- Facilitation technique gets real attention — keeping participants engaged is treated as a skill, not an afterthought.
- Evaluation and follow-up are covered as seriously as the exercise itself, closing the loop that many tabletop efforts skip.
Notes
The natural companion to this catalog's incident-response and threat-intelligence titles (Incident Response and Computer Forensics, Intelligence-Driven Incident Response) for the rehearsal side those books don't cover. Useful alongside Security Chaos Engineering for teams thinking about readiness testing more broadly, on live systems as well as on paper.
What to read before
What to read before Cybersecurity Tabletop Exercises →Intermediate · 2025
La norme ISO/IEC 27005
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
Beginner · 2019
The Pragmatic Programmer
Thomas and Hunt's career-defining set of practical heuristics for writing software professionally — orthogonality, broken-windows, DRY, tracer bullets, and the underlying argument that craftsmanship is a posture, not a process.
Beginner · 2023
A Hacker's Mind
Bruce Schneier extends the security-engineering frame of "hacking" to law, finance, politics, and tax: every rule-based system has exploitable seams, and the wealthy and powerful exploit them constantly.
What to read next
What to read after Cybersecurity Tabletop Exercises →Intermediate · 2025
La norme ISO/IEC 27005
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.
Intermediate · 2010
Cybercriminalité
A practitioner's treatment of cybercrime law — offences, procedure, and the application of criminal law to digital crime — by a French magistrate specialised in the field.
Explore similar books
Alternatives to Cybersecurity Tabletop Exercises →Intermediate · 2025
La norme ISO/IEC 27005
A three-part guide to the ISO/IEC 27005:2022 standard, running from information-security governance foundations to the detail of every risk-management process, with fictional case studies to practice against.
Intermediate · 2021
RGPD et droit des données personnelles
A complete French manual on data-protection law under the GDPR and the 2018 loi Informatique et Libertés — obligations, rights and how to comply — by an engineer and doctor of law.
Intermediate · 2010
Cybercriminalité
A practitioner's treatment of cybercrime law — offences, procedure, and the application of criminal law to digital crime — by a French magistrate specialised in the field.