What Happens During a Real Incident Response Tabletop Exercise
If your incident response plan has never actually been tested, here's a hard truth: you don't really know if it works. A plan sitting in a binder can tell you what's supposed to happen when something goes wrong. It can't tell you whether your team actually knows how to do it, who's supposed to make which call, or whether the person who's "in charge" of a given step even remembers they own it.
That's exactly what an incident response tabletop exercise is built to find out, and it's something we run every year with insurance agencies here in Wesley Chapel and across the greater Tampa Bay area.
What A Tabletop Exercise Actually Is
A tabletop exercise is not a live drill. Nobody's pulling a plug, no systems get touched, and nothing on your network actually breaks. That surprises a lot of agencies going in, because "cybersecurity exercise" tends to sound technical. It isn't.
What it actually is: your team sitting down together, usually for an hour or two, working through a realistic incident scenario step by step, out loud, in a conference room. A facilitator guides the conversation and everyone else responds the way they'd actually respond if the incident were real.
The value isn't in simulating the technical attack. It's in finding out, in a calm room with coffee on the table, whether your team actually knows what to do when something goes wrong. Think of it like a fire drill for a data breach or a ransomware event. You don't wait for the real fire to find out if people know where the exits are.
What A Scenario Looks Like
Here's a simplified version of a scenario we might run for an insurance agency. It's Monday morning. Someone tries to open a client file and gets an error. A few minutes later, another employee reports the same issue. By the time a third person mentions it, the pattern is obvious: this looks like ransomware.
From there, the facilitator adds new details as the exercise unfolds, much like a real incident actually would. IT confirms files across shared drives are encrypted. A ransom note shows up on a couple of workstations. A client calls asking why they can't access their portal, and the front desk isn't sure what to say. Each new detail forces the room to make a decision, in the moment, the same way they'd have to during a real event.
By the end, the team has typically worked through a dozen or more small decisions under a bit of simulated pressure, in a setting where getting something wrong costs nothing but a few minutes of discussion.
Who Should Be In The Room
This isn't just an IT exercise, and that's one of the most common mistakes agencies make the first time they schedule one. The room should include agency leadership with the actual authority to approve downtime or notify carriers and clients, anyone with day to day operational or client facing responsibility like an office manager or front desk staff, your IT or managed services provider, and whoever would actually be responsible for talking to clients or carriers if the incident were real.
Leaving any of these roles out of the room means testing a version of your incident response plan that doesn't reflect how your agency actually operates.
The Gaps That Almost Always Show Up
We've run enough of these exercises now to see the same kinds of gaps surface again and again. Nobody's sure who actually has the authority to shut down a system. Nobody has a client notification template ready to go. A step in the written plan sounds fine on paper, but when you ask the room directly who does this and how, nobody quite remembers.
Beyond those three, agencies frequently lack a clear communication tree, have no defined process for backup and restore responsibilities, haven't decided who's authorized to speak publicly if a client or reporter calls, and don't have a way to document the decisions made during an incident for their own after action review or for compliance purposes.
Finding all of this out in a conference room is a completely different experience than finding it out during a real incident. Every one of these gaps is fixable, usually in a single follow up meeting, once you actually know it's there.
Why This Matters For Florida Insurance Agencies
A tested incident response plan is increasingly something cyber insurance carriers want to see evidence of before offering favorable terms, and it directly supports the incident response expectations built into Florida's regulatory framework for insurance agencies under Rule 69O-128.032. A written plan that's never been exercised is a plan nobody's actually confirmed will work.
If your agency's incident response plan has never been tested, that's worth fixing, and it's a lot easier to fix before you need it than after. Annual incident response planning with a facilitated tabletop exercise is part of what we build into our Main Event tier at Main Event MSP, alongside broader WISP-as-a-service and compliance mapping for Florida insurance agencies.
Reach out if your agency is ready to find out where the gaps in your plan really are, before an actual incident finds them for you.
Youtube Video on this topic:

