{"id":8134,"date":"2026-09-21T06:57:00","date_gmt":"2026-09-21T10:57:00","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=8134"},"modified":"2026-09-03T11:12:06","modified_gmt":"2026-09-03T15:12:06","slug":"breach-tabletop-exercise-tax-firm","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/breach-tabletop-exercise-tax-firm\/","title":{"rendered":"How Do You Actually Run a Breach Tabletop Exercise?"},"content":{"rendered":"\n<p><strong>By now, most firms know <\/strong><a href=\"https:\/\/verito.com\/blog\/ftc-safeguards-breach-notification-30-day-rule\/\" target=\"_blank\" rel=\"dofollow\" ><strong>the FTC\u2019s 30-day clock<\/strong><\/a><strong>: unencrypted data, 500 consumers, thirty days from discovery, no extensions for a still-open investigation. What almost no firm has actually done is rehearse what happens in the room when that clock starts. A tabletop exercise is a discussion-only walkthrough of a specific breach scenario, run with your actual team, before a real incident forces everyone to improvise for the first time during a busy time of the year. Here\u2019s how to run one.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Key takeaways<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A tabletop exercise is entirely discussion-based. No live systems, no real alerts, just a facilitator walking the team through a scenario out loud.<\/li>\n\n\n\n<li>Pick one specific, realistic scenario and stick to it. A stolen laptop and a ransomware-locked file server force completely different decisions.<\/li>\n\n\n\n<li>Assign roles before the exercise starts: who leads, who talks to the client, who contacts counsel, who\u2019s actually filing the FTC report.<\/li>\n\n\n\n<li>The facilitator\u2019s real job is introducing complications mid-exercise, not reading a script. That\u2019s where a plan\u2019s gaps actually show up.<\/li>\n\n\n\n<li>Debrief immediately afterward and update your WISP\u2019s incident response section while what didn\u2019t work is still fresh, not weeks later.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#what-a-tabletop-exercise-actually-is\">What a tabletop exercise actually is<\/a><\/li><li><a href=\"#picking-a-scenario-worth-running\">Picking a scenario worth running<\/a><\/li><li><a href=\"#assigning-roles-before-you-start\">Assigning roles before you start<\/a><\/li><li><a href=\"#where-the-exercise-actually-earns-its-keep\">Where the exercise actually earns its keep<\/a><\/li><li><a href=\"#after-the-exercise-closing-what-you-found\">After the exercise: closing what you found<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-a-tabletop-exercise-actually-is\"><strong>What a tabletop exercise actually is<\/strong><\/h2>\n\n\n\n<p><strong>A tabletop exercise is a discussion-based walkthrough of one specific incident, run in a conference room with no live systems involved. A facilitator presents a scenario, and the team talks through, out loud, exactly what they\u2019d do and in what order.<\/strong><\/p>\n\n\n\n<p>That\u2019s a different thing from having a written incident response plan, and it tests a different question. A written plan proves the steps exist on paper. A tabletop exercise proves the people who\u2019d actually execute those steps understand them the same way, under time pressure, before the moment they\u2019d need to. Plenty of firms have a plan nobody\u2019s ever actually walked through, and the gap between those two things usually isn\u2019t visible until the first real incident makes it visible the hard way.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"picking-a-scenario-worth-running\"><strong>Picking a scenario worth running<\/strong><\/h2>\n\n\n\n<p><strong>The scenario that\u2019s actually useful feels realistic, closely resembles what your firm could plausibly face, starts small, and escalates until it needs more than whoever\u2019s in the room can handle alone.<\/strong><\/p>\n\n\n\n<p>For a tax firm, three scenarios do most of the work, and they force genuinely different decisions:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Scenario<\/th><th>The decision it forces<\/th><\/tr><\/thead><tbody><tr><td>A staff laptop with client files is stolen<\/td><td>Was the drive encrypted? That single fact decides whether this even triggers the FTC\u2019s 30-day clock<\/td><\/tr><tr><td>A phishing email compromises a staff email account<\/td><td>You often don\u2019t know what was actually accessed, only what the account could reach<\/td><\/tr><tr><td>Ransomware locks the file server mid-week<\/td><td>Do you pay, restore from backup, or do both fail because the backup was never tested<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-1024x576.jpg\" alt=\"File server and backup recovery scenario cinematic visual | Verito\" class=\"wp-image-8153\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-recovery.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Run one scenario per session, not all three. A tabletop exercise that tries to cover everything ends up rehearsing nothing specifically, and the value comes from working through one situation in enough depth that the team hits real decision points, not from surveying every possible incident in the abstract.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"assigning-roles-before-you-start\"><strong>Assigning roles before you start<\/strong><\/h2>\n\n\n\n<p><strong>Roles get assigned before the exercise starts, not improvised once it\u2019s underway. At minimum: someone leads the response, someone talks to the client, someone contacts counsel, and someone is responsible for actually filing the FTC report.<\/strong><\/p>\n\n\n\n<p>For a tax firm, most of these map directly onto roles the FTC Safeguards Rule already assumes exist. The qualified individual named in your WISP is a natural fit for incident lead. Whoever handles client relationships is the obvious choice for client communication, since that conversation has to happen whether or not the technical picture is fully clear yet. And someone specific needs to own the mechanics of the FTC filing itself, since the deadline runs from discovery regardless of how the investigation is going. Deciding this in the exercise, ahead of time, is the entire point. Deciding it during a real incident means it doesn\u2019t get decided at all until someone finally asks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"where-the-exercise-actually-earns-its-keep\"><strong>Where the exercise actually earns its keep<\/strong><\/h2>\n\n\n\n<p><strong>The facilitator\u2019s actual job is introducing new complications at intervals, called injects, not narrating a script from start to finish. <\/strong><a href=\"https:\/\/www.uptimelabs.io\/learn\/incident-response-tabletop-exercises\" target=\"_blank\" rel=\"nofollow noopener\"><strong>A well-designed inject sequence keeps the group from solving the scenario too early<\/strong><\/a><strong> and forces the same kind of pressure a real incident would.<\/strong><\/p>\n\n\n\n<p>For the stolen-laptop scenario, a useful inject sequence might look like: the laptop turns out not to have had full-disk encryption enabled after all, despite what the team assumed. A client calls on day three asking directly whether their return was affected, before anyone\u2019s confirmed what data was actually on the device. The firm\u2019s cyber insurance carrier asks for documentation of the incident response plan being followed, not just that one existed. Each of those is a moment where a real firm would have to make a decision on the spot, and running into it during a rehearsal is a much better place to discover a gap than running into it for real.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"after-the-exercise-closing-what-you-found\"><strong>After the exercise: closing what you found<\/strong><\/h2>\n\n\n\n<p><strong>Debrief right after the exercise ends, while what didn\u2019t work is still fresh, and feed it directly into your WISP\u2019s incident response section. A tabletop exercise that doesn\u2019t change the plan afterward was just a meeting.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-1024x576.jpg\" alt=\"Incident response plan updated after exercise cinematic visual | Verito\" class=\"wp-image-8154\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/breach-tabletop-exercise-tax-firm-debrief.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Keep the debrief simple: what did the team get right, where did people hesitate or disagree about who owned a decision, and what did the exercise assume the firm had in place that it actually doesn\u2019t. <a href=\"https:\/\/verito.com\/written-information-security-plan\/\" target=\"_blank\" rel=\"dofollow\">Every WISP built to IRS Pub 4557 and the FTC Safeguards Rule already needs a written incident response plan<\/a> as one of its required sections. Running a tabletop exercise once or twice a year is what keeps that section describing how your firm would actually respond, rather than a version written once and never checked against reality.<\/p>\n\n\n\n<p><a href=\"https:\/\/verito.com\/contact\/\" target=\"_blank\" rel=\"dofollow\"><strong>Talk to us about building your firm\u2019s incident response plan \u2192<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"By now, most firms know the FTC\u2019s 30-day clock: unencrypted data, 500 consumers, thirty days from discovery, no&hellip;\n","protected":false},"author":12,"featured_media":8152,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-8134","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=8134"}],"version-history":[{"count":2,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8134\/revisions"}],"predecessor-version":[{"id":8155,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8134\/revisions\/8155"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8152"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=8134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=8134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=8134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}