Skip to content
INTCSC
Support

Tabletop Exercises

Ready-to-run scenarios and facilitation packs (NCSC Exercise in a Box, CISA CTEPs and more) so teams can practise decisions, communications and recovery before an incident — not just write a plan.

33 current resources

Best starting points

Highest starting-point strength resources in this category.

NCSC Exercise in a Box (opens in a new tab)

Why: Free UK NCSC scenarios and facilitation packs for running cyber tabletop exercises, so organisations can practise decision-making without designing every drill from scratch.

Living doc Strong start
Last verified 6 September 2026 Open

NCSC Exercise in a Box — Tabletop exercises (opens in a new tab)

Why: NCSC index of free 60–90 minute cyber tabletop discussion exercises. Facilitators pick a scenario (ransomware, supply chain, insider threat, BYOD, etc.), download the pack, and run structured injects with senior leaders, cyber engineers and communications.

Evergreen hub Strong start
Last verified 6 September 2026 Open

Showing 33 resources

NCSC Exercise in a Box (opens in a new tab)

Why: Free UK NCSC scenarios and facilitation packs for running cyber tabletop exercises, so organisations can practise decision-making without designing every drill from scratch.

Living doc Strong start
Last verified 6 September 2026 Open

NCSC Exercise in a Box — Tabletop exercises (opens in a new tab)

Why: NCSC index of free 60–90 minute cyber tabletop discussion exercises. Facilitators pick a scenario (ransomware, supply chain, insider threat, BYOD, etc.), download the pack, and run structured injects with senior leaders, cyber engineers and communications.

Evergreen hub Strong start
Last verified 6 September 2026 Open

CISA CTEP — Ransomware Situation Manual (opens in a new tab)

Why: Downloadable ransomware CTEP situation manual (DOCX, Sept 2023). Customisable objectives, injects and discussion questions for IR, leadership and communications to rehearse encryption/extortion response and recovery; pair with CTEP package documents.

Dated artefact Solid
Last verified 6 September 2026 Open

CISA — Elections Cyber Tabletop in a Box (opens in a new tab)

Why: Elections-infrastructure cyber tabletop package (StopRansomware hub). State/local election officials and cyber partners discuss threats to election systems with template objectives, scenario and discussion questions; editable Word version via CISA Exercises email.

Living doc
Last verified 6 September 2026 Open

CISA CTEP — Cybersecurity Scenarios (listing) (opens in a new tab)

Why: CISA download library of cybersecurity CTEP situation manuals (ransomware, insider threat, ICS, sector packs for healthcare, water, maritime, local government, etc.). Planners download a DOCX scenario then pair it with CTEP package documents for facilitator/AAR templates.

Evergreen hub
Last verified 6 September 2026 Open

CISA CTEP — Insider Threat Situation Manual (opens in a new tab)

Why: Insider-threat CTEP situation manual (DOCX, Sept 2023). Helps security, HR and legal practise detection, investigation boundaries and containment when a trusted insider abuses access; customisable modules for pre-incident sharing through recovery.

Dated artefact
Last verified 6 September 2026 Open

NCSC EiB — Bring your own device (opens in a new tab)

Why: Tabletop covering compromised personal devices and business data leakage under BYOD. Helps security, IT and policy owners rehearse MDM/conditional access decisions, wipe vs contain choices and staff communications; NCSC pack for facilitators.

Living doc
Last verified 6 September 2026 Open

NCSC EiB — Heightened cyber threat (opens in a new tab)

Why: Exercise for periods of elevated national or sector cyber threat. Leadership and cyber teams practise stepping up monitoring, change freezes, remote-access hardening and crisis comms without waiting for an active breach; free NCSC materials.

Living doc
Last verified 6 September 2026 Open

NCSC EiB — Home and remote working (opens in a new tab)

Why: Tests controls and response when remote/home working drives data compromise risk. Good for validating VPN/zero-trust assumptions, endpoint hygiene and HR/comms playbooks; 60–90 minute NCSC facilitated discussion with downloadable pack.

Living doc
Last verified 6 September 2026 Open

NCSC EiB — Supply chain (opens in a new tab)

Why: Broader supply-chain risk tabletop for products, systems and services from suppliers. Procurement, cyber and business continuity owners discuss assurance, contractual levers and fallback when a critical supplier fails or is attacked.

Living doc
Last verified 6 September 2026 Open

NCSC EiB — Supply chain software (opens in a new tab)

Why: Focused on software suppliers in the estate. Teams walk a supply-chain software attack: inventory of critical components, detection signals, isolation, rebuild and customer impact; NCSC downloadable discussion pack.

Living doc
Last verified 6 September 2026 Open

← Back to full library