A tabletop exercise small organization leaders can actually run does not require a consultant, a conference room full of experts, or a full day off the calendar. It requires a realistic scenario, the right people in the room, and about 90 minutes. Done well, it reveals exactly where your incident response would break down before a real attacker or a real ransomware event forces the lesson on you.
Most small nonprofits and clinics have never run one. They have a vague sense that “we would call IT” if something went wrong, and that vague sense is the entire plan. When a breach actually hits, that gap turns a manageable incident into a crisis. Cyber insurers and HIPAA auditors have noticed, which is why a documented, tested tabletop exercise is increasingly a requirement rather than a nice-to-have.
This guide gives you everything you need to run a tabletop exercise small organization teams can execute this month. You get the preparation steps, a ready-to-use ransomware scenario, a reusable template, and the debrief process that turns the exercise into real improvement. No jargon, no consultant required.
A tabletop exercise is a guided, discussion-based walkthrough of a cyber incident where your team talks through exactly what they would do, step by step, without touching live systems. To run one at a small nonprofit or clinic, pick a realistic scenario like ransomware or a phishing-driven wire fraud, gather 4 to 8 key people, appoint a facilitator, walk through the scenario in stages while asking “what do we do now,” and document every gap you find. Budget 60 to 90 minutes. The goal is not to pass. The goal is to find your weak points before a real attack does.
Table of Contents
ToggleWhat a Tabletop Exercise Actually Is
A tabletop exercise is a structured conversation. Your team sits around a table, real or virtual, and a facilitator walks everyone through a realistic incident one stage at a time. At each stage, the facilitator asks what the team would do, and the team talks it through.
Nothing technical happens. You do not shut down real systems or send real emails. You simulate the decisions, the communications, and the actions on paper. That is what makes a tabletop exercise small organization teams can run so accessible. It costs almost nothing and carries zero risk to live operations.
The value comes from discovering gaps. You learn that nobody knows the cyber insurance claim phone number, that two people think someone else is responsible for notifying patients, or that your backups have never been tested. Finding these gaps in a meeting is far better than finding them during a live ransomware attack. Our incident response and forensics work consistently shows that the organizations that recover fastest are the ones that practiced first.
Why Small Nonprofits and Clinics Need to Run One
Small organizations often assume tabletop exercises are for large enterprises. The opposite is true. A large hospital has a dedicated security team that lives and breathes incident response. A small clinic has a practice manager juggling ten other jobs.
The threat is real and rising. Ransomware drives a large share of confirmed healthcare breaches, and attacks on small nonprofits and clinics have climbed sharply. When an incident hits a small organization, the first hour shapes the next six months, and confusion in that first hour is what makes incidents catastrophic.
There is also a compliance driver. Cyber insurers now expect a written, tested incident response plan before they will write or renew a policy, and a tabletop is how you test it. For clinics, HIPAA expects contingency planning and testing. Running a cyber tabletop nonprofit or clinic exercise satisfies both the insurer and the auditor while genuinely making you safer. Our work across nonprofits and medical clinics shows this dual benefit repeatedly.
Before You Start: Preparation Steps
Good preparation makes the difference between a productive exercise and a wasted hour. Spend 30 minutes setting up before you gather anyone.
Pick a realistic scenario. Choose a threat your organization actually faces. For most small nonprofits and clinics, ransomware or a phishing-driven wire fraud is the right choice. We provide a full ransomware scenario below.
Choose the right people. You want 4 to 8 participants covering leadership, operations, finance, and whoever handles IT. For a clinic, include the practice manager and a clinical lead. For a nonprofit, include the executive director and the finance lead.
Appoint a facilitator. One person guides the exercise, introduces each stage, and keeps the discussion moving. This can be an internal leader or an outside partner. The facilitator does not need to be the most technical person, just organized.
Set the ground rules. Make clear this is a no-blame exercise. The goal is to find gaps, not to judge people. Psychological safety is what makes participants honest about what they do not know.
Prepare your template. Use the clinic incident simulation template in the next section to capture decisions and gaps as you go. Documentation is what turns the exercise into improvement.
A Ready-to-Use Ransomware Scenario
Here is a complete scenario you can run today. Read each stage aloud, then ask the team the questions that follow. Let the discussion breathe. The gaps reveal themselves in the pauses.
Stage 1: The discovery. It is Monday morning. A staff member reports that their computer is showing a message demanding payment to unlock their files, and they cannot open anything. Two other staff report the same thing.
Ask: Who does this person call first? What is the very first action we take? Who has the authority to make decisions right now?
Stage 2: The spread. Within 20 minutes, your EHR or donor database is inaccessible. The ransomware has spread across the network. Staff cannot work.
Ask: Do we disconnect systems from the network, and who does that? How do we communicate with staff when email may be compromised? Do we know if our backups are safe?
Stage 3: The demand. The attacker demands $40,000 in cryptocurrency within 72 hours. They claim to have copied patient or donor data before encrypting it.
Ask: Who decides whether we pay? Have we contacted our cyber insurance carrier? Do we have the carrier’s claim phone number? Do we need legal counsel?
Stage 4: The obligations. You confirm that patient or donor data was likely accessed. Notification laws and, for clinics, HIPAA breach rules may now apply.
Ask: Who determines if this is a reportable breach? What are our notification deadlines? Who drafts the communication to patients, donors, or the board?
Stage 5: The recovery. Three days later, you are restoring from backups. Some data is lost. Staff are exhausted and behind on work.
Ask: How long does full recovery take? What did we lose? What would we do differently next time?
This scenario surfaces almost every gap a small organization has. Run it once and you will have a prioritized list of fixes.
The Tabletop Exercise Template
Use this simple tabletop exercise template to capture what happens during the exercise. Fill it in live as you go. The completed document becomes proof of testing for insurers and auditors, and a roadmap for your fixes.
| Field | What to capture |
|---|---|
| Date and participants | Who attended and their roles |
| Scenario used | Ransomware, wire fraud, or other |
| Decisions made | Key decisions at each stage |
| Gaps identified | Every point where the team was unsure |
| Owner assigned | Who fixes each gap |
| Target date | When each fix will be complete |
| Facilitator notes | Overall observations and priorities |
Keep the completed template on file. When your cyber insurer or HIPAA auditor asks whether you have tested your incident response plan, this document is your answer. A reusable tabletop exercise template also means your next exercise takes half the setup time.
Running the Exercise: Step by Step
With preparation done and your template ready, here is how the 60 to 90 minutes actually flow.
Open with the ground rules (5 minutes). Remind everyone this is a no-blame learning exercise and that honesty about gaps is the entire point.
Introduce the scenario (5 minutes). Set the scene. Explain that you will move through stages and that the team should talk through their real actions, not idealized ones.
Walk through each stage (45 minutes). Read each stage, ask the questions, and let the team discuss. Capture every gap in your template. Do not solve the gaps in the moment, just record them.
Debrief (15 minutes). Review the gaps together. Assign an owner and a target date to each one. Agree on the top three priorities.
Document and follow up (after). Finalize the template, distribute it, and schedule a check-in to confirm the fixes get made. An exercise without follow-up is theater.
The most common mistake is stopping at the exercise itself. The learning happens in the debrief and the follow-up. A clinic incident simulation that identifies ten gaps and fixes none is worse than useless because it creates false confidence.
Turning Gaps Into a Stronger Defense
The gaps a tabletop reveals almost always cluster into a few themes. Knowing them helps you prioritize your fixes.
Backup gaps. If the exercise revealed that nobody knows whether backups work, that is your first fix. Our ransomware backup strategy guide and our disaster recovery and backup service address this directly.
Communication gaps. If nobody knew how to reach staff, the board, or the insurer, build a contact directory into your incident response plan now.
Authority gaps. If it was unclear who could make decisions, define that in advance. Someone must own the incident.
Prevention gaps. Many tabletop gaps trace back to weak prevention. If phishing started the scenario, strengthen your email security and phishing defenses. If access was the issue, tighten your onboarding and offboarding process.
For organizations that want the whole lifecycle handled, from prevention to tested response, our managed IT services operate it as one program. And our free risk assessment is a fast way to see which gaps you have before you even run the exercise.
Note Worthy Info
- A tabletop is a discussion, not a technical drill. No live systems are touched, which makes it safe and cheap to run.
- 90 minutes is enough. A focused exercise with 4 to 8 people surfaces most of your gaps.
- The first hour of a real incident decides everything. Practicing that hour is the entire point.
- Insurers and auditors now expect testing. A documented tabletop satisfies both.
- No blame is the rule. Honesty about gaps only happens when people feel safe.
- The debrief matters more than the exercise. Assign owners and dates to every gap.
- Follow-up is non-negotiable. An exercise with no fixes creates false confidence.
The Bottom Line
Running a tabletop exercise small organization teams can execute is one of the highest-return, lowest-cost security investments available. It costs a room, 90 minutes, and a realistic scenario, and it reveals exactly where your response would fail before a real incident makes you pay for the lesson.
Start this month. Pick the ransomware scenario above, gather your key people, appoint a facilitator, and work through it stage by stage. Document every gap, assign every fix, and schedule the next one. If you want help facilitating your first tabletop exercise small organization session or building the incident response plan behind it, request a free risk assessment and we will help you turn a 90-minute conversation into a genuinely stronger defense.
Frequently Asked Questions
1. What is a tabletop exercise and how is it different from a real drill?
A tabletop exercise is a discussion-based walkthrough of a cyber incident where your team talks through what they would do, stage by stage, without touching any live systems. Unlike a technical drill, nothing is actually shut down or tested in production, which makes it safe, cheap, and easy to run. The value comes from the conversation, which reveals gaps in your plan, your communications, and your decision-making.
2. How long does a tabletop exercise take for a small nonprofit or clinic?
Budget 60 to 90 minutes for the exercise itself, plus about 30 minutes of preparation beforehand. That includes opening ground rules, walking through the scenario in stages, and a debrief to assign fixes. A focused session with 4 to 8 participants is enough to surface most of your gaps without consuming a full day.
3. Who should participate in a cyber tabletop nonprofit or clinic exercise?
Include 4 to 8 people covering leadership, operations, finance, and whoever handles IT. For a clinic, add the practice manager and a clinical lead. For a nonprofit, include the executive director and the finance lead. The goal is to have everyone in the room who would actually make decisions during a real incident, so the exercise reflects reality.
4. Do we need to hire a consultant to run a tabletop exercise?
No. A small nonprofit or clinic can run an effective tabletop exercise internally using a ready-made scenario and a simple template. You need a facilitator to guide the discussion, but that person does not have to be highly technical, just organized. That said, an outside partner can add value by bringing realistic scenarios and spotting gaps an internal team might miss.
5. How often should we run a tabletop exercise?
At least once a year, and after any major change to your systems, staff, or vendors. Cyber insurers and HIPAA auditors increasingly expect annual testing of your incident response plan, and a documented tabletop is how you demonstrate it. Running one annually keeps the plan current and keeps the team’s response reflexes sharp.
6. What scenario should a small clinic or nonprofit use?
Choose a threat you actually face. For most small clinics and nonprofits, a ransomware attack or a phishing-driven wire fraud is the most realistic and instructive choice. This guide includes a full ransomware scenario you can use as-is. A good clinic incident simulation feels real enough that participants engage seriously with the decisions.
7. What do we do with the results of the exercise?
Capture every gap in a tabletop exercise template during the session, then assign an owner and a target date to each one in the debrief. Finalize the document, distribute it, and schedule a follow-up to confirm the fixes get made. The completed template also serves as proof of testing for insurers and auditors. The exercise only creates value if the gaps it reveals actually get fixed.


