← Consultancy
Tabletop exercises

Rehearse your worst day before it happens

Facilitated incident simulations for leadership and technical teams, built on your real environment, so everyone knows who decides what when it counts. Every gap we find becomes a tracked action, not a note in a report.

Custom scenariosExecutive & technical tracksRemote or in personAudit-ready evidence
Scenario · Ransomware, Friday morning4 injects
07:40 Finance reports files renamed with a strange extension. A ransom note names the company.WHO IS IN CHARGE?
08:05 The backup console is unreachable. Nobody can confirm the last clean copy.RESTORE OR REBUILD?
09:30 Email and Teams are down. The phone tree stalls at the second call.HOW DO YOU TALK?
11:00 A journalist calls asking to confirm the attack.WHAT DO YOU SAY?
Why it's different

An exercise is only useful if something changes afterwards

The usual way With Touchpoint
Generic ransomware scenario from a template Scenario built from your systems, suppliers and current threat activity
Assumes email and chat keep working Includes a communication inject that takes your usual channels away
One session for everyone Separate executive and technical tracks, joined up at the key decision points
Lessons learned in a report nobody reopens Every gap logged with an owner and deadline, and followed up
Evidence scattered across emails Attendance, report and completed actions filed for auditors and insurers
Scenarios

The incidents most likely to hit you

Ransomware Encrypted systems, a ransom note and unreachable backups. Do you pay, restore or rebuild?
Business email compromise A finance director’s mailbox is used to redirect a supplier payment.
Supplier breach A critical vendor is compromised and you learn about it from the news.
Cloud account takeover An admin identity is used to exfiltrate data from your cloud tenant.
Insider data theft A leaver downloads sensitive files in their final week.
Your choice We build the scenario around the risk that worries your board most.
How it works

From your plan to a stronger one

  1. 01 Review We read your incident response plan and agree the objectives for the exercise.
  2. 02 Design A custom scenario with realistic injects, built on your environment and current threats.
  3. 03 Run A facilitated 2–4 hour session, remote or on site, with an observer capturing decisions.
  4. 04 Debrief An immediate hot wash, then a lessons-learned session with the report.
  5. 05 Track Every action is logged with an owner and a date, and followed up.
What you get

Proof you rehearsed, and a plan that improved

Auditors, regulators and insurers increasingly ask for evidence of incident exercises. You get everything they need in one place.

✓ Custom scenario packScenario, injects and participant briefing.
✓ Facilitated sessionLed by consultants who handle real incidents.
✓ After-action reportStrengths, gaps and a prioritised improvement plan.
✓ Updated playbooksRecommended changes to your incident response plan and escalation paths.
✓ Action trackerEach gap owned, dated and followed through to closure.
✓ Evidence packAttendance, report and completed actions for auditors and insurers.
Engagement options

Pick the level your team needs

Leadership Executive exercise For boards and leadership teams: decisions, communication and authority.
  • ✓Custom executive scenario
  • ✓2-hour facilitated session
  • ✓Regulatory and comms injects
  • ✓Executive after-action report
Get a fixed quote →
Most complete Executive + technical For organisations that want both levels tested and joined up.
  • ✓Two linked tracks
  • ✓Technical injects from your environment
  • ✓Communication-loss inject
  • ✓Action tracker with owners
Get a fixed quote →
Programme Annual exercise programme For regulated organisations that need regular, evidenced exercises.
  • ✓Two to four exercises a year
  • ✓Scenario rotation by risk
  • ✓Progress tracked across exercises
  • ✓Year-on-year improvement report
Get a fixed quote →
Questions

Before you ask

Do we need an incident response plan first?+

It helps, but it isn’t essential. If you don’t have one, the exercise shows what the plan needs to cover, and we can help you write it.

Who should attend?+

For executive sessions: leadership, legal, communications and IT leads. For technical sessions: IT, security and key system owners.

Remote or in person?+

Either. Remote works well for distributed teams; in person is best for a first executive exercise.

How often should we run one?+

At least once a year, and after major changes such as a new system, acquisition or leadership change.

Find the gaps in a rehearsal, not a real incident

Tell us what worries you most. We’ll design a scenario around it and agree a fixed price up front.

Plan an exercise
Other consultancy services Penetration testing→ Cloud security→ vCISO→ Engineering & implementation→