Cyber crisis rehearsal, run for you

Rehearse the breach. Own the record.

Tabletop.ai runs realistic cyber-attack drills for your whole company, then hands you the board-ready report: what worked, what broke, and who owns the fix.

Grounded in FEMA HSEEP. Scored to NIST CSF 2.0. Privileged and board-ready.

Board readiness report

Ransomware at the plant

Ready

72 / 100

Overall readiness

Gaps found

3

Actions assigned

9

People involved

12

The team isolated the network in six minutes. The legal hold ran late; the General Counsel now owns that fix.

Auto-generated the moment the exercise ends

Grounded in

  • FEMA HSEEP
  • NIST CSF 2.0
  • SEC / OCIE-aligned
  • Attorney-client privilege

What it does

One program from the opening scenario twist to the board scorecard.

Tabletop.ai replaces one-off, document-heavy exercises with a repeatable, documented governance program that compounds across your enterprise.

01

Live exercises, one seat per role

Run tabletops in real time, sending each role its own updates on their own device. Facilitators steer the record while participants make real decisions under pressure.

Executives, counsel, responders, and plant-floor leads each see only their seat.

Live exercise

Running
CISOIsolate the affected network segments
LegalPrivilege asserted, memo open
Plant leadSafety systems confirmed intact

02

A defensible record, not anecdotes

Every decision and gap maps to a NIST CSF 2.0 control, then auto-generates the After-Action Report, a privileged risk memo, and a board-ready scorecard.

One exercise, three client-branded deliverables mapped across all six functions.

NIST CSF 2.0 posture

72 / 100

Identify82
Protect74
Detect61
Respond68

03

Govern every business unit as one program

Profile each business unit, run both everyday IT scenarios and plant-floor (operational technology) scenarios where they operate, and track findings to closure in a risk register kept separate for each unit.

One head-office program, many business units, rolled up to a single board view.

Head office

Runs the program and sees rolled-up readiness.

Business unit

Runs local exercises against its own separate data.

Counsel

Holds privilege over the whole record.

For the first time our board sees cyber readiness the way it sees financial controls: scored, tracked, and defensible. The privilege posture is what got legal comfortable running it enterprise-wide.
CISO · Fortune-500 manufacturer

FAQ

Questions security and legal teams ask.

What is a tabletop exercise?

A facilitated, discussion-based drill where your team walks through a realistic cyber incident and makes the decisions they'd make in a real one. It surfaces gaps in plans, roles, and communication before an actual incident forces the meeting.

Why run it under attorney-client privilege?

Privilege lets teams name real weaknesses candidly without creating a discoverable record that an adversary or plaintiff could use. Tabletop.ai is structured so exercises run under counsel and produce privileged work product: legal memos, not operational confessions.

Do you support plant-floor (OT) scenarios?

Yes. Alongside office IT scenarios, the library includes plant-floor exercises, known as operational technology or OT, covering the controllers that run machines, the automatic safety systems, and malware arriving through a trusted vendor. These are the incidents that threaten physical operations and safety, not just data.

How is data kept separate between business units?

A database rule tags every record to its organization, so each one is walled off from the rest. Business units cannot see each other's data, and the head office sees only what its role permits. Every request runs as the signed-in user, checked against those same rules.

What does an exercise produce?

Each exercise auto-generates an After-Action Report, an attorney-client-privileged risk memo, and a NIST CSF 2.0 board scorecard. Findings also flow into a continuous risk register with owners and due dates.

Which frameworks is it grounded in?

Exercises follow FEMA HSEEP design and evaluation doctrine, and outcomes map to NIST CSF 2.0 across all six functions. The record is built to support SEC/OCIE-style, board-visible program expectations.

Can we produce client-branded deliverables like a CSIRP or BIA?

Yes. The platform generates client-branded privileged deliverables including Cyber Security Incident Response Plans (CSIRP) and Business Impact Analyses (BIA) alongside exercise reports.

How do we get started?

Pick a plan and you're running the same day. You subscribe once as the organization; everyone you seat shares it, and business units roll up under the same plan.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.