by Robert Lelewski (Author), John Hollenberger (Author)
The complete start-to-finish guide for planning and delivering successful cybersecurity tabletop exercises.
Cybersecurity Tabletop Exercises, written by veteran security consultants Robert Lelewski and John Hollenberger, is an essential resource for cybersecurity professionals and anyone tasked with enhancing their organization's incident response capabilities. This comprehensive guide to tabletop exercise planning and delivery offers practical insights, step-by-step instructions, and real-world examples to improve your team's ability to prevent and respond to cyberattacks. The book is divided into two main parts. In Part I: The Tabletop Exercise Process, you'll learn:- Why you should perform tabletop exercises and what their organizational benefits are
- Effective planning and logistics tips, including how to gain executive sponsor support
- How to develop realistic scenarios, injects, and storyboards
- Facilitation techniques to ensure active participant engagement
- Evaluation methods and follow-up activities
The example scenarios in Part II include:
- Technical tabletops covering phishing campaigns, ransomware attacks, and zero-day vulnerabilities
- Executive-level exercises that focus on high-impact incidents
- Cross-functional cases such as physical security breaches, social media compromises, and insider threats
With examples tailored for various roles, you'll discover how to transform tabletop exercises from a mere compliance requirement into a powerful strategic preparedness tool. Whether you're new to tabletop exercises or an experienced practitioner, this book provides proven insights to strengthen your organization's cyber incident response capabilities and overall security posture.
Author Biography
Robert Lelewski has more than 20 years of experience in IT, cybersecurity, incident response, and risk management. He started out as a computer forensic consultant before joining IBM's global incident response team. Later, he pivoted to helping organizations prepare for a cybersecurity event as the Director of Proactive Incident Response with Dell Secureworks. Currently, he is the VP of Cyber Security Strategy at Zurich Insurance's Global Ventures. Over his career, he has conducted hundreds of tabletop exercises, and has been a consultant to organizations ranking from small regional banks to Fortune 50 companies across the globe. In addition, Robert holds multiple degrees and numerous industry certifications, including CISSP-ISSMP, CISA, CISM, CRISC, CIPM, CDPSE, and GCIH.
John Hollenberger is a seasoned cybersecurity consultant with over 16 years of experience in web and host-based vulnerability assessments, incident response, digital forensics, PCI compliance, and Data Loss Prevention. As a Senior Security Consultant of Proactive Services, he develops tabletop exercises, reviews and creates incident response plans, and conducts security assessments for a wide range of organizations. John holds degrees and certifications including a BA, CISSP, CISA, CISM, CRISC, GCIH, GWAPT, and Security+.