Incident Response Tabletop Exercises

Kroll’s field-proven incident response tabletop exercise scenarios are customized to test all aspects of your response plan and mature your program.

Contact us
/en/services/cyber-risk/governance-advisory/incident-response-tabletop-exercises service

You know your organization has a cyber incident response plan (IRP). That’s great. But could that knowledge be giving you a false sense of security? In Kroll’s experience working on thousands of cyber matters a year, we have seen crises intensify or escalate when organizations discover their IRPs are outdated or when key team members are not prepared to act according to plan. 

Practicing your IRP on a regular basis is key for validating or restoring confidence in your IRP. Kroll can help with customized incident response tabletop exercises (TTX) led by our seasoned experts. Participating in a Kroll TTX gives the members of your incident response team a valuable opportunity to clarify and rehearse their roles. Ultimately, they will have greater confidence to carry out their assigned duties in the event of an incident. Additionally, a TTX will highlight where guidance or information (e.g., contact information) needs to be updated. 

Seven Steps to Greater Confidence in Responding to a Cyber Incident

Kroll follows a seven-step process refined by our leading hundreds of tabletop exercises for client organizations of various sizes, complexity and industry sectors. 

  • Kick Off the Process With Clear Communications 
    Kroll cyber experts will hold a call with all participants to provide an overview of the TTX methodology, what to expect during the interviews and a timeline for each step.  
  • Interview Key Stakeholders
    Our cyber experts will conduct onsite meetings to identify each stakeholder’s duties and experiences with incident response. We will also focus on your overall cyber security concerns. These can include specific factors or vulnerabilities that you perceive within your organization, developments within your industry or another public incident. 
  • Review Current Incident Response Plan and Other Documents
    Our in-depth review of your current incident response plan will focus on identifying gaps that will hamper or decrease the effectiveness of your response.  
  • Develop an Incident Response Plan
    If your organization does not already have a plan, we will develop a unique incident response plan for your organization designed to help you effectively mitigate damage from a cyberattack. We will provide this plan to you and your management approximately one week prior to the onsite TTX.  
  • Create Custom Tabletop Scenarios
    We design these scenarios to encourage communication among all stakeholders. In this way, not only will everyone understand his or her responsibilities and how to respond, but also it will allow any gaps in your incident response plan to be surfaced, identified and resolved.    
  • Facilitate the TTX
    In this discussion-based event, our cyber investigators will present four to six incident response tabletop scenarios customized for your organization in order to test the complete response plan. This exercise will give those involved an opportunity to experience an incident response in a stress-free, open environment. 
  • Deliver Report
    We will review and provide the results and lessons learned from the exercise and deliver a final report that summarizes our discussions and recommendations. 

Know How You Will Respond to a Cyber Incident Before One Strikes

Take advantage of Kroll’s unrivaled cyber incident response experience to better prepare to respond to a cyber incident. To schedule a customized tabletop exercise for your team, contact a Kroll expert today. 

Connect with us

Andrew Beckett
Andrew Beckett
Managing Director
Cyber Risk
Michael Quinn
Michael Quinn
Managing Director
Cyber Risk
Lucie Hayward
Lucie Hayward
Associate Managing Director
Cyber Risk

See all servicesStay Ahead with Kroll


Valuation of businesses, assets and alternative investments for financial reporting, tax and other purposes.

Compliance and Regulation

End-to-end governance, advisory and monitorship solutions to detect, mitigate and remediate security, legal, compliance and regulatory risk.

Corporate Finance and Restructuring

Comprehensive investment banking, corporate finance, restructuring and insolvency services to investors, asset managers, companies and lenders.

Cyber Risk

Incident response, digital forensics, breach notification, managed detection services, penetration testing, cyber assessments and advisory.

Environmental, Social and Governance

Advisory and technology solutions, including policies and procedures, screening and due diligence, disclosures and reporting and investigations, value creation, and monitoring.

Investigations and Disputes

World-wide expert services and tech-enabled advisory through all stages of diligence, forensic investigation, litigation and testimony.

Business Services

Expert provider of complex administrative solutions for capital events globally. Our services include claims and noticing administration, debt restructuring and liability management services, agency and trustee services and more.


Cyber Risk and CFOs: Over-Confidence is Costly

Sep 13, 2022

by Greg MichaelsJames McLearyWilliam Rimington


Optimizing the CISO and Board Roles in Heightened Risk Periods

Aug 05, 2022

by James McLeary Edward Starkie


Optimism, Underestimation and Invincibility: Bridging the Gap Between Reality and Perception in Cyber Security

Jun 15, 2022

by Willem HoekstraAlan Brill


IDC MarketScape: Worldwide Incident Readiness Services 2021

Dec 09, 2021

by Jason N. SmolanoffBenedetto DemonteGreg Michaels


Kroll Launches Strategic Communications Service

Jun 01, 2022


Kroll Partners with Armis to Extend Preparedness and Response for OT and ICS Environments

May 09, 2022


Kroll Responder Recognized in 2021 Gartner Market Guide for Managed Detection and Response Services

Nov 19, 2021


Op-Ed: The Australian Cyber Threat Landscape Today and How to Look Ahead

Jul 09, 2021


KAPE Intensive Training and Certification

Online Event Apr 12 - Dec 08, 2022 | Online Event