One-Time or AnnualLeadership & Cross-FunctionalRealistic ScenariosFindings Report

Tabletop Exercises & IR Simulation

Incident Preparedness|Facilitated breach scenarios that test your team before the real one does

You don't want your first breach response to be during an actual breach

Every organization has an incident response plan — on paper. But when ransomware hits at 2am on a Friday, does your team actually know what to do? Who calls the insurance carrier? Who talks to the press? Who decides whether to pay? Who notifies the state within 7 days?

The time to find those gaps is before an incident — not during one. A tabletop exercise is a no-risk, facilitated simulation that puts your team through a realistic scenario and reveals exactly where your response breaks down.

Realistic scenarios — facilitated by Ridgepoint

Ridgepoint leads your team through a structured, scenario-driven exercise. We present a realistic breach scenario that unfolds in stages, and your team works through their response in real time. We observe, ask probing questions, and document every gap. Afterward, you receive a written findings report with prioritized recommendations.

  • Pre-exercise planning call to understand your environment, team structure, and existing IR plan
  • Facilitated 2–3 hour exercise with scenario injection points and decision gates
  • Two exercise formats: leadership-focused (board, C-suite, legal, HR) or cross-functional (IT, operations, communications)
  • Three built-in scenarios: ransomware attack, business email compromise, and insider threat
  • Custom scenario development available — tailored to your industry and specific risk profile
  • Written findings report with gap analysis and prioritized remediation recommendations
  • Post-exercise debrief and Q&A session

Annual programs for continuous improvement

A single tabletop exercise reveals your gaps. An annual program closes them. Ridgepoint offers recurring tabletop exercise programs — quarterly or semi-annual — that rotate through different scenarios and track improvement over time. Each exercise builds on the last, creating a measurable improvement in your team's readiness.

Annual programs are available as standalone engagements or included in vCISO Plus retainers.

Frequently Asked Questions

Want to talk it through?

Every engagement starts with a working conversation, not a pitch. We learn about your business, you tell us what’s on your mind, and we tell you honestly whether we are the right fit.