Crisis Preparedness & Tabletop Exercises
Cybersecurity Tabletop Exercise for Boards and Executives
Practice the first 72 hours before they happen. Your team leaves knowing who decides what, when to escalate, and how disclosure timing works.
- Custom scenario built for your board and leadership team
- SEC Item 1.05 four-day disclosure rehearsal included
- After-action report plus a director crisis decision guide
Led by Tyson Martin, CISSP, NACD contributor and NRF CISO Executive Committee member
Prefer to talk? Call +1 (802) 430-9200
Scope your tabletop exercise
Tell us who needs to be in the room. You'll get a scoped proposal back.
Why run this exercise with Tyson Martin
Decisions, not a lecture
The session puts real choices in front of your people. They practice calling them under time pressure.
Disclosure timing rehearsed
Includes a board disclosure rehearsal aligned to SEC Item 1.05 four-day timing, so nobody guesses on the day.
Escalation that holds up
You leave with clear decision rights and escalation thresholds that still work in a real incident.
Plain-English throughout
Technical risk is translated into business impact: downtime, vendor exposure, revenue and disclosure duties.
Written proof of the work
An after-action report and updated response plan give directors something they can point to later.
Independent voice in the room
An outside advisor with enterprise security leadership experience at AWS, Home Depot and Best Buy.
What the tabletop exercise covers
Most organizations have an incident response plan. Far fewer have tested whether the board knows its role, whether executives know which decisions are theirs, and whether the company can preserve evidence and meet disclosure obligations while the clock runs.
This engagement prepares you for the hours and days after a cyber incident. The scenario is built around your business, your vendors and your reporting duties. Afterward you get documents you can inspect, hand to auditors and reuse next year.
- Customized tabletop exercise scenario for your board, executives or response team
- Incident response readiness review against how your team actually operates
- Board disclosure rehearsal aligned to SEC Item 1.05 four-day timing
- Backup and restore validation so recovery assumptions get tested
- Deliverable: updated incident response plan
- Deliverable: board-level disclosure playbook
- Deliverable: tabletop after-action report
- Deliverable: director crisis decision guide
- Delivered virtually or in person, nationwide in the US
Experience behind the exercise
“Tyson Martin brings the full package: deep technical expertise, functional clarity, and the leadership presence to rally teams when it matters most. He's one of the few security leaders I've worked with who truly understands how to design, deploy, and operationalize SIEM solutions that generate real business insight, not just noise. When incidents arise, Tyson leads with calm urgency, aligning stakeholders, containing threats, and preserving trust. His ability to connect the dots between architecture, governance, and response makes him a standout in the field.”
“Tyson Martin has a unique ability to translate complex cybersecurity risks into actionable business insights which helped our executive team make informed strategic decisions.”
“What sets Tyson apart is his ability to translate cybersecurity into strategic growth language for boards. He builds frameworks that don't just mitigate risk, they enable competitive advantage. He's exactly who you want guiding your organization in high-trust environments.”
What happens after you submit
Scoping call
We talk through your participants, your industry and the incident you most worry about.
Scenario build
You get a proposal with a custom scenario, session length and the deliverables you will receive.
Run and debrief
We facilitate the exercise, then deliver the after-action report and updated plan with clear owners.
Frequently asked questions
Who should be in the room?
The exercise is built for boards, audit and risk committees, executive teams and response teams. Some clients run one session for the board and a separate one for management. We confirm the right mix on the scoping call.
Is this a penetration test or technical audit?
No. This is a decision-making exercise. Penetration testing and technical security audits are not services offered here. The focus is on roles, escalation, disclosure and recovery decisions.
How much does a cybersecurity tabletop exercise cost?
Pricing depends on the participants, scenario complexity, session length and whether it is virtual or in person. Send your details and you'll get a scoped proposal.
Can you run it remotely?
Yes. Sessions are delivered virtually or on site anywhere in the US.
What do we have in hand when it's over?
An updated incident response plan, a board-level disclosure playbook, a tabletop after-action report and a director crisis decision guide.
Do you cover SEC disclosure obligations?
Yes. The exercise includes a board disclosure rehearsal aligned to SEC Item 1.05 four-day timing, so directors practice the call before it matters.
Test your response before an attacker does
Tell us who needs to be in the room and what worries you most. You'll get a scoped tabletop exercise proposal with the deliverables spelled out.
- Custom scenario built for your board and leadership team
- SEC Item 1.05 four-day disclosure rehearsal included
- After-action report plus a director crisis decision guide
Prefer to talk? Call +1 (802) 430-9200
