Cyber crisis rehearsal, run for you

Rehearse the breach. Own the record.

Tabletop.ai is a cybersecurity tabletop exercise platform. It runs realistic cyber-attack drills for your whole company, then hands you the board-ready report: what worked, what broke, and who owns the fix.

Grounded in FEMA HSEEP. Scored to NIST CSF 2.0. Privileged and board-ready.

Board readiness report

Ransomware at the plant

Ready

72 / 100

Overall readiness

Gaps found

3

Actions assigned

9

People involved

12

The team isolated the network in six minutes. The legal hold ran late; the General Counsel now owns that fix.

Auto-generated the moment the exercise ends

Grounded in

  • FEMA HSEEP
  • NIST CSF 2.0
  • SEC / OCIE-aligned
  • Attorney-client privilege

What it does

One program from the opening scenario twist to the board scorecard.

Tabletop.ai replaces one-off, document-heavy exercises with a repeatable, documented governance program that compounds across your enterprise.

01

Live exercises, one seat per role

Run tabletops in real time, sending each role its own updates on their own device. Facilitators steer the record while participants make real decisions under pressure.

Executives, counsel, responders, and plant-floor leads each see only their seat.

Live exercise

Running
CISOIsolate the affected network segments
LegalPrivilege asserted, memo open
Plant leadSafety systems confirmed intact

02

A defensible record, not anecdotes

Every decision and gap maps to a NIST CSF 2.0 control, then auto-generates the After-Action Report, a privileged risk memo, and a board-ready scorecard.

One exercise, three client-branded deliverables mapped across all six functions.

NIST CSF 2.0 posture

72 / 100

Identify82
Protect74
Detect61
Respond68

03

Govern every business unit as one program

Profile each business unit, run both everyday IT scenarios and plant-floor (operational technology) scenarios where they operate, and track findings to closure in a risk register kept separate for each unit.

One head-office program, many business units, rolled up to a single board view.

Head office

Runs the program and sees rolled-up readiness.

Business unit

Runs local exercises against its own separate data.

Counsel

Holds privilege over the whole record.

04

A 12-month plan built around your weak spots

Tabletop.ai reads each business unit's own reconnaissance, assets, and posture, then schedules a year of exercises against what that unit is actually weak on. No shared template.

Different for every business unit, and defensible: each date traces to a named gap.

Annual program

Tailored per unit

Q1

Business email compromise

Recon flagged finance-email exposure

Q2

Ransomware recovery

Recover posture scored weak

Q3

Vendor breach

New supplier onboarded

Q4

Plant-floor compromise

OT assets in scope

05

Generate the drill the catalog doesn't have

Describe what you need to test. Tabletop.ai researches your environment, builds a full three-phase exercise, and red-teams it before you get it, usually in a few minutes. Then you run it live with your team.

Program includes one custom exercise a month. Command includes three.

Custom exercise

Generating
1DescribeWhat you need to test
2ResearchYour environment and the threat
3BuildA full three-phase exercise
4ValidateRed-teamed before you run it
For the first time our board sees cyber readiness the way it sees financial controls: scored, tracked, and defensible. The privilege posture is what got legal comfortable running it enterprise-wide.
CISO · Fortune-500 manufacturer

FAQ

Questions security and legal teams ask.

What is a tabletop exercise?

A facilitated, discussion-based drill where your team walks through a realistic cyber incident and makes the decisions they'd make in a real one. It surfaces gaps in plans, roles, and communication before an actual incident forces the meeting.

Why run it under attorney-client privilege?

Privilege lets teams name real weaknesses candidly without creating a discoverable record that an adversary or plaintiff could use. Tabletop.ai is structured so exercises run under counsel and produce privileged work product: legal memos, not operational confessions.

Do you support plant-floor (OT) scenarios?

Yes. Alongside office IT scenarios, the library includes plant-floor exercises, known as operational technology or OT, covering the controllers that run machines, the automatic safety systems, and malware arriving through a trusted vendor. These are the incidents that threaten physical operations and safety, not just data.

How is data kept separate between business units?

A database rule tags every record to its organization, so each one is walled off from the rest. Business units cannot see each other's data, and the head office sees only what its role permits. Every request runs as the signed-in user, checked against those same rules.

What does an exercise produce?

Each exercise auto-generates an After-Action Report, an attorney-client-privileged risk memo, and a NIST CSF 2.0 board scorecard. Findings also flow into a continuous risk register with owners and due dates.

Which frameworks is it grounded in?

Exercises follow FEMA HSEEP design and evaluation doctrine, and outcomes map to NIST CSF 2.0 across all six functions. The record is built to support SEC/OCIE-style, board-visible program expectations.

Can we produce client-branded deliverables like a CSIRP or BIA?

Yes. The platform generates client-branded privileged deliverables including Cyber Security Incident Response Plans (CSIRP) and Business Impact Analyses (BIA) alongside exercise reports.

Can I create my own exercise?

Yes. Describe what you need to test and Tabletop.ai researches your environment, builds a full three-phase exercise, and red-teams it before you run it. The Program plan includes one custom exercise a month; Command includes three. Readiness upgrades to either.

Can my team join a custom exercise?

Yes. A custom exercise runs through the same engine as any built-in drill. Invite your seated members, one seat per role, each on their own device. Everyone needs a Tabletop.ai account, and seats stay within your plan limit.

What if a generation isn't strong?

Every exercise is pressure-tested before you get it, so a weak draft is caught and repaired first. A rare miss doesn't cost your monthly credit, and you can try again at no charge.

How do we get started?

Pick a plan and you're running the same day. You subscribe once as the organization; everyone you seat shares it, and business units roll up under the same plan.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.