CISA Tabletop Exercise Packages (CTEPs) (opens in a new tab)
Why: Ready-made CISA tabletop packages spanning cyber and physical scenarios, so teams can practise response without designing every exercise from scratch.
Ready-to-run scenarios and facilitation packs (NCSC Exercise in a Box, CISA CTEPs and more) so teams can practise decisions, communications and recovery before an incident — not just write a plan.
33 current resources
Highest starting-point strength resources in this category.
Why: Ready-made CISA tabletop packages spanning cyber and physical scenarios, so teams can practise response without designing every exercise from scratch.
Why: Free UK NCSC scenarios and facilitation packs for running cyber tabletop exercises, so organisations can practise decision-making without designing every drill from scratch.
Why: NCSC index of free 60–90 minute cyber tabletop discussion exercises. Facilitators pick a scenario (ransomware, supply chain, insider threat, BYOD, etc.), download the pack, and run structured injects with senior leaders, cyber engineers and communications.
Showing 33 resources
Why: Ready-made CISA tabletop packages spanning cyber and physical scenarios, so teams can practise response without designing every exercise from scratch.
Why: Free UK NCSC scenarios and facilitation packs for running cyber tabletop exercises, so organisations can practise decision-making without designing every drill from scratch.
Why: NCSC index of free 60–90 minute cyber tabletop discussion exercises. Facilitators pick a scenario (ransomware, supply chain, insider threat, BYOD, etc.), download the pack, and run structured injects with senior leaders, cyber engineers and communications.
Why: Reusable CTEP planner/facilitator handbooks, invitation letter, slide deck, participant feedback and AAR-IP templates. Use alongside any situation manual so exercise teams can run and document a full HSEEP-style tabletop without building paperwork from scratch.
Why: Downloadable ransomware CTEP situation manual (DOCX, Sept 2023). Customisable objectives, injects and discussion questions for IR, leadership and communications to rehearse encryption/extortion response and recovery; pair with CTEP package documents.
Why: 60–90 minute NCSC tabletop for senior leaders, cyber engineers and communications. Walks phishing-delivered ransomware from detection through containment, recovery and external messaging; ZIP pack includes facilitator and participant PDFs.
Why: Elections-infrastructure cyber tabletop package (StopRansomware hub). State/local election officials and cyber partners discuss threats to election systems with template objectives, scenario and discussion questions; editable Word version via CISA Exercises email.
Why: Hub for CTEPs that explore physical impacts from cyber vectors (and vice versa). Useful for OT/ICS and critical-infrastructure exercise planners designing convergence discussions beyond pure IT scenarios; contact CISA Exercises for packages.
Why: CISA download library of cybersecurity CTEP situation manuals (ransomware, insider threat, ICS, sector packs for healthcare, water, maritime, local government, etc.). Planners download a DOCX scenario then pair it with CTEP package documents for facilitator/AAR templates.
Why: Electricity-subsector cyber CTEP situation manual (DOCX, July 2024). Grid/utility cyber and operations leads can exercise OT impacts, reliability obligations and multi-party coordination after a cyber attack on electric systems.
Why: Executive/senior-leadership cyber CTEP situation manual (DOCX, Aug 2024). Board-facing discussion injects for decision-making, risk acceptance, external communications and oversight during a major cyber incident—not a technical deep-dive.
Why: Federal DDoS CTEP situation manual (DOCX, Nov 2023). Network defenders and service owners rehearse detection, scrubbing/mitigation choices, public messaging and restoration under sustained denial-of-service pressure.
Why: Sector CTEP for healthcare/public health cyber scenarios (DOCX, Oct 2023). Useful for hospital CISOs and clinical ops to exercise patient-care continuity, clinical system downtime and regulatory notification under cyber attack.
Why: ICS/OT-focused CTEP situation manual (DOCX, Aug 2024). Designed for operators and cyber teams to discuss ICS compromise, safety/process impacts and IT–OT coordination; strong fit for critical-infrastructure tabletops.
Why: IT-sector CTEP situation manual (DOCX, June 2024). Suited to MSPs, cloud and enterprise IT teams exercising cyber incident coordination, customer impact and sector information-sharing during an unfolding attack.
Why: Insider-threat CTEP situation manual (DOCX, Sept 2023). Helps security, HR and legal practise detection, investigation boundaries and containment when a trusted insider abuses access; customisable modules for pre-incident sharing through recovery.
Why: Local-government cyber CTEP situation manual (DOCX, Nov 2023). Built for municipal IT/security and emergency management to exercise ransomware and service disruption against citizen-facing systems and mutual-aid coordination.
Why: Maritime ports cyber CTEP situation manual (DOCX, Nov 2023). Port operators and cyber teams can rehearse OT/IT impacts on cargo operations, vessel scheduling and multi-agency response after a cyber incident.
Why: Open-source software risk CTEP situation manual (DOCX, April 2024). Teams discuss dependency inventory, disclosure of vulnerable components and remediation when open-source libraries or tooling become the incident vector.
Why: Vendor/supply-chain compromise CTEP situation manual (DOCX, Aug 2024). Exercises response when a trusted vendor is the intrusion path—vendor isolation, software integrity checks and customer notification for cyber practitioners.
Why: Water/wastewater cyber CTEP situation manual (DOCX, Nov 2023). Utility operators and ICS security leads practise process disruption, public health messaging and recovery when treatment/SCADA systems are targeted.
Why: Scenario of compromise via unknown Wi-Fi and outdated software. Validates travel/remote working controls, endpoint patch posture and user guidance; short NCSC facilitated discussion with downloadable materials.
Why: Tabletop covering compromised personal devices and business data leakage under BYOD. Helps security, IT and policy owners rehearse MDM/conditional access decisions, wipe vs contain choices and staff communications; NCSC pack for facilitators.
Why: Exercise for periods of elevated national or sector cyber threat. Leadership and cyber teams practise stepping up monitoring, change freezes, remote-access hardening and crisis comms without waiting for an active breach; free NCSC materials.
Why: Tests controls and response when remote/home working drives data compromise risk. Good for validating VPN/zero-trust assumptions, endpoint hygiene and HR/comms playbooks; 60–90 minute NCSC facilitated discussion with downloadable pack.
Why: Scenario where a user grants unauthorised third parties access to sensitive information. Involves cyber, HR and legal in detection, account disablement, evidence handling and breach notification decisions; NCSC tabletop pack.
Why: Practises receiving and handling a vulnerability disclosure on an online system. Security, engineering and comms rehearse triage, patch/mitigation timelines, researcher engagement and public messaging; NCSC facilitator pack.
Why: Tabletop on a stolen mobile used to extract confidential information. Tests device encryption, remote wipe, MFA/session revocation and insider-risk follow-up; suitable for IT, security and staff who handle sensitive data on phones.
Why: Broader supply-chain risk tabletop for products, systems and services from suppliers. Procurement, cyber and business continuity owners discuss assurance, contractual levers and fallback when a critical supplier fails or is attacked.
Why: Exercises organisational response when ransomware hits a supplier and cascades into your operations. Useful for IR leads and business owners to test dependency maps, alternate providers and crisis communications; NCSC pack.
Why: Focused on software suppliers in the estate. Teams walk a supply-chain software attack: inventory of critical components, detection signals, isolation, rebuild and customer impact; NCSC downloadable discussion pack.
Why: NCSC discussion exercise on responding when a third-party software supplier is compromised. Useful for CISOs and IT leads to stress-test vendor dependency, isolation options and customer/stakeholder communications; downloadable exercise pack.
Why: Tabletop on preventing, detecting and responding to threats to leak sensitive information (extortion-style pressure). Brings together cyber, legal, privacy and communications on containment, engagement strategy and notification duties.