Call UsGet Free Assessment
    Back to Blog
    Mindset & Strategy7 Min Read

    Run the Fire Drill Before the Fire: A One-Hour Tabletop Exercise for Your Team

    Run the Fire Drill Before the Fire: A One-Hour Tabletop Exercise for Your Team

    Every business practices fire drills. Nobody waits for an actual fire to figure out where the exits are and who calls 911. We practice, calmly, ahead of time, so that if the real emergency ever comes, people move on instinct instead of panic. Yet almost no small business does the same thing for a cyberattack, even though a serious cyber incident is far more likely than a fire. They may have a plan on paper, but a plan nobody has ever practiced is really just a guess, and the middle of a crisis is the worst possible time to discover its gaps.

    The fix is simple, low-cost, and genuinely valuable: run a cyber fire drill. It is called a tabletop exercise, and despite the formal name, it is just your team sitting around a table, or over lunch, talking through what you would do if something went wrong. No technology, no stress, no real systems touched. Just an hour of "what would we do if" that surfaces your gaps and builds your team's readiness before the bad day. This is the natural companion to having a business continuity plan: the plan says what to do, and the drill makes sure your team can actually do it. Here is exactly how to run one.

    What a tabletop exercise is, and why it works

    A tabletop exercise is a guided, hypothetical walk-through of an emergency. Someone presents a scenario, "here is what just happened," and the group talks through how they would respond, step by step, out loud. That is the whole thing. It is called a tabletop because it happens around a table in conversation, not in your live systems.

    It works for a few reasons. It reveals gaps safely, so you find out that nobody knows who to call, or that no one is sure the backups work, in a calm discussion rather than a real disaster. It builds a kind of muscle memory, so that when a real incident happens, the steps feel familiar instead of foreign. And it clarifies roles, so people know in advance who does what, which prevents the confusion and paralysis that make real incidents worse. An hour of talking through scenarios does more to prepare a team than any document sitting in a drawer.

    How to run your one-hour exercise

    You do not need expertise or special tools to do this well. Here is a simple structure you can follow, start to finish, in about an hour.

    • Gather the right people. Include whoever handles operations, money, and technology, at a minimum, plus anyone who would play a role in a real incident. In a small business, that might be just a few people, and that is fine.
    • Pick a facilitator. One person, often the owner, guides the discussion, presents the scenario, and asks the questions. Their job is to keep it moving and make sure real answers get discussed, not glossed over.
    • Set the tone. Make clear this is a no-blame, low-stakes practice, the whole point is to find gaps, so "I don't know" is a useful and welcome answer, not a failure. People should feel free to be honest about what they are unsure of.
    • Walk through a scenario. Present one of the situations below, then work through it step by step, asking the guiding questions and letting the team talk through what they would actually do. Do not rush to tidy answers; the uncertainty is where the learning is.
    • Capture the gaps. As you go, write down every "we're not sure," "we don't have that," or "who would even do that?" These are gold. They are your action items.
    • Turn gaps into actions. After the exercise, assign each gap to someone to fix, with a rough timeline, so the drill produces real improvements rather than just a good conversation.

    Aim to cover one or two scenarios in your hour, and rotate through others in future sessions. Now, the scenarios.

    Scenario 1: The files are locked (ransomware)

    Set the scene: "We arrive Monday morning and our files will not open. There is a message on the screen demanding payment to unlock everything. We cannot access our systems."

    Walk through these questions as a team:

    • Who notices first, and who do they tell? Is it clear who to report this to right away?
    • Who do we call first, our IT support, a security professional, our insurance carrier? Do we have those numbers handy?
    • Do we have backups? When were they last tested, and are we confident we could actually restore from them?
    • Can we keep operating at all while systems are down, and how?
    • Do we pay the ransom? (For the real answer, see our guide on whether to pay a ransom.) Who makes that call, and with whose advice?
    • Who communicates with customers or clients if we are down or their data is involved?

    The gaps this scenario usually surfaces: untested backups, no clear first call, and no one assigned to customer communication. Every one of those is fixable now, on a calm day.

    Scenario 2: The urgent wire request (business email compromise)

    Set the scene: "Our bookkeeper receives an email that appears to be from the owner, saying we urgently need to wire a large payment to a new account today, and to keep it quiet because it is time-sensitive."

    Walk through these questions:

    • What is our rule for verifying payment and banking requests? Does everyone who handles money know it?
    • How exactly would the bookkeeper verify this before sending anything? Who would they call, and on what number?
    • Does our team feel comfortable questioning a request that appears to come from the owner? Have we made that safe?
    • What if the money already went out before anyone caught it? Do we know the recovery steps and the urgency? (See our wire fraud recovery playbook, where the first hours are critical.)
    • Who do we notify, our bank, the authorities, and how fast?

    The gaps this usually surfaces: no firm verification rule, employees who would hesitate to question the boss, and no one sure what to do if money already moved. These are among the most valuable gaps you can find, because this scenario is one of the costliest real attacks there is.

    Scenario 3: The lost laptop

    Set the scene: "An employee left their work laptop in a taxi, or it was stolen from their car. It is gone, and we do not know who has it."

    Walk through these questions:

    • What business information was on that laptop, and how sensitive is it?
    • Was the device locked with a strong password, and was it encrypted, so the data is protected?
    • Can we remotely wipe or lock it, and does someone know how to do that right now?
    • What accounts was that laptop logged into, and do we need to change passwords or secure those accounts?
    • Do we have any obligation to notify anyone if sensitive data was on it?

    The gaps this usually surfaces: no remote-wipe capability set up, uncertainty about encryption, and no clear sense of what was on the device. All straightforward to address, and far better addressed before a device actually goes missing. For the fuller picture, our guide to mobile device security covers what to have in place before a phone or laptop goes missing.

    After the drill: close the gaps

    The exercise itself is valuable, but its real payoff is what you do next. Take your list of gaps and turn each into a concrete action with an owner and a timeline. Untested backups? Schedule a restore test. No verification rule? Write one and share it. No remote wipe? Set it up. This is where a drill turns into genuine readiness. And once you have made improvements, running the exercise again in a few months, perhaps with a fresh scenario, both reinforces the learning and checks that your fixes actually stuck. A tabletop exercise is not a one-time event; it is a habit that keeps your team sharp.

    For the fuller picture of what to actually do when a real incident strikes, your drill pairs naturally with our step-by-step guide on what to do after a cyberattack. Practicing with these scenarios makes that real response far smoother if you ever need it.

    How we think about it

    Practicing your response, not just planning it, is very much how we think about readiness at Red Door Shield, through a simple framework we call KIT: Keep, Inspect, Trust. Keep what is valuable secure, with the protections and tested backups that your drill will confirm are truly in place. Inspect, in the sense of honestly examining your readiness through exercises like this rather than assuming you are prepared. And trust through validation, which a tabletop exercise embodies perfectly: you do not trust that your team would know what to do, you validate it by practicing. We help businesses build both the protections and the practiced readiness, so that if the real fire ever comes, your team moves like they have done it before, because they have.

    What ready looks like

    Picture a real incident striking your business, and your team responding with a calm competence that surprises even them, because it feels familiar. They know who to call, they verify before they act, they reach for the tested backups, they move through the steps without panic, because they walked through this exact kind of situation over lunch a few months ago and fixed the gaps they found. The drill turned a plan on paper into instinct in people, and that instinct is what carries you through the hard day.

    That is what ready feels like. Not hoping your team would rise to the occasion, but knowing they are prepared because you practiced, the same way you would never skip a fire drill.

    You run fire drills for an emergency that is unlikely. A cyber incident is far more likely, and an hour of practice can be the difference between a controlled response and a chaotic one. Gather your team, pick a scenario, and run your first drill this month. And if you want help building the protections and the readiness that make your team truly prepared, our free Business Security Assessment is the place to start, and it is a conversation worth having today.

    Know Where Your Business Stands

    Our free Business Security Assessment gives you a clear, professional picture of your current security posture in less than 10 minutes. No technical knowledge required.

    Not sure where your business actually stands?

    Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.

    Get My Free Security Assessment
    Share this post:
    Tony Chan, Founder of Red Door Technologies

    Tony ChanFounder of Red Door Technologies LLC and the author of Operation CyberGuard: Protect Your Business, Outsmart Cyber Threats, and Secure Your Future. He has served small businesses across Chicago for 17 years.

    Related Articles

    Free Security Resources

    Employee Security Checklist

    A simple, plain English checklist for your team to prevent the most common email attacks.

    Vendor Risk Assessment

    Questions you must ask your IT provider or software vendors to ensure they aren't your weakest link.

    Operation CyberGuard

    Download a free sample chapter from Tony Chan's 2025 guide: "The 5 Lies Business Owners Believe About Cybersecurity."

    Stay Ahead of the Threats

    Join Chicago business owners who receive our plain-English cybersecurity updates, threat alerts, and practical advice directly in their inbox.

    We respect your privacy. No spam, ever.