When something goes wrong in an industrial environment, the response involves more than IT. Operators decide whether to run manually, engineers assess the process, safety staff weigh the risk, and executives manage customers and regulators. Those groups seldom practice working together. A tabletop exercise is a low-cost way to find out what happens when they have to.
A tabletop is a facilitated discussion of a scenario. No systems are touched. People talk through what they would do, and the facilitator notes where the plan is unclear, missing, or unrealistic.
Who should attend
Include people from across the organization.
- Operations and plant or field supervisors.
- Control system engineers and technicians.
- IT and security staff, or your managed provider.
- Safety and environmental personnel.
- Executive leadership.
- Finance, legal, HR, and communications representatives as appropriate.
- Key vendors, if they have a role in support.
Prepare
Set objectives
Decide what you want to learn: decision authority, communication, manual operating procedures, vendor engagement, or recovery priorities.
Choose a facilitator
Pick someone who can keep the discussion on track and who is not defensive about gaps. An outside facilitator can help.
Gather the plan
Bring the incident response plan, network diagrams, contact lists, and any manual operating procedures. If these do not exist, that is the first finding.
A sample scenario
Consider a hypothetical mid-sized energy services company with a central control room and several remote sites. Here is how a scenario might unfold in stages.
Stage 1: The first signal
A control room operator reports that the supervisory screen is responding slowly and several tags show stale data. A short time later, the IT help desk reports that business computers are showing a ransom message.
Discuss: Who is notified first? Who decides whether this is related? Who has the authority to disconnect the business network from the control network?
Stage 2: Escalation
The business network appears fully encrypted. Operators lose visibility at one remote site. The vendor who supports the control software says they can connect remotely to help.
Discuss: Do you allow the vendor in? What controls apply to their access? Can operators run the process safely by hand? For how long? Who makes that call?
Stage 3: External pressure
A customer calls asking about delivery commitments. A reporter hears about the outage. The attacker claims to have stolen data.
Discuss: Who speaks to customers, regulators, and the media? What are your notification obligations? Who contacts the insurer and counsel?
Stage 4: Recovery
The team needs to restore systems. Backups of the business systems exist, but the last known good controller configuration is uncertain.
Discuss: What is the restoration order? Where are the offline configuration copies? How do you verify that restored systems are clean and safe to reconnect?
Questions to ask throughout
- Who has authority, and do they know it?
- What do operators do if screens go dark?
- How do we communicate without email?
- Which decisions require safety review?
- What does each person need from the others?
Capture findings
Assign a note taker. Record gaps in three categories: plan gaps, such as missing procedures; capability gaps, such as no offline backups; and communication gaps, such as unclear contacts. Assign each finding an owner and a due date.
After the exercise
Within a couple of weeks, update the response plan and contact list, address the highest priority gaps, and schedule the next exercise. Share a short summary with leadership. Aim to run an exercise at least annually and after major changes.
Align with recognized guidance
CISA offers tabletop exercise resources, and NIST's Cybersecurity Framework 2.0 includes response and recovery as core functions. Regulated operators, including utilities under NERC CIP and pipeline operators under TSA directives, have specific planning and testing expectations to meet as well.
Working with Ironfield Cyber
Ironfield Cyber facilitates tabletop exercises for energy and construction companies, tailored to your operations and including both IT and operations staff. If you have never tested your plan, a short session can reveal more than another document review.