Making Cybersecurity Awareness Month Fun: A Very Spooky Tabletop

Practice before panic.
Erik Boemanns
Contributing CISO
Halloween Pixel Art
Lab01 - らぼわん - stock.adobe.com

October is Cybersecurity Awareness Month and is often a month full of extra awareness training and activities. And while most people don’t get excited about security awareness training, if you saw the other articles from our “Making Cybersecurity Awareness Month Fun” series the last two years, it is possible to make them fun and more effective.

Beyond making sure the team can enjoy some training, cybersecurity awareness also depends on leadership being aware of their own policies, procedures, and who needs to be involved in case of an incident.

October ends up being an ideal month to take care of this awareness too, through an annual tabletop exercise.

With the heightened attention to security and being the last month of the year without attention-stealing holidays, October is a prime month for running this exercise.

An added bonus is it can be a precursor to your company costume party.

During a tabletop, you are pretending to have a bad day at work, so that you’ve rehearsed what you should do if you ever have a real “bad” day with a cyber or other incident.

Since it’s all pretend, it is almost like everyone is wearing their costume.

What’s the role you’ll be playing in a crisis? Be sure to dress for the part. Plus, someone will be playing the role of “game master” who will be taking the team through the exercise. They get to pretend to be the hacker, the natural disaster, or whatever bad scenario that was dreamed up.

Make Sure Everyone Knows Their Role

A good tabletop is a well written fiction, grounded in the reality of your business. It should include all the participants you would bring to a real incident.

Your executive leadership, legal team, IT, marketing (or PR), human resources, and more have a role to play. Outside vendors should be included too, if they are a key part of the response. When it isn’t feasible to involve real outside resources (e.g. law enforcement), it’s another opportunity for someone to “dress up” and play that part.

Whether you run tabletops using an internal team or a trusted partner, it’s important to make sure someone is covering key roles.

Commit to the Bit

It’s important for everyone involved to “commit to the bit.” Whatever “costume” team members are wearing, they need to lean into the role and react the way they would in a real scenario.

And if, during the tabletop, you find out they don’t know how they would react, that’s an important lesson! Whether you find the team isn’t familiar with the procedure or the procedure doesn’t even exist, finding out during the dress rehearsal is the best time learn and create a plan to fix the gap you’ve discovered.

Your tabletop is as much as about practice as it is about discovering what’s missing.

Build a Scenario That Feels Real

Good tabletop scenarios are like good costumes. They look realistic even if they seem farfetched.

Many tabletop exercises end up feeling like store-bought costumes: a computer gets ransomware, someone gets phished, a data center has an outage. These all work in a pinch, and are realistic scenarios, but also should be well-worn paths for most organizations.

The interesting tabletops are ones that are realistic but not expected.

One organization had a scenario involving an air traffic accident nearby, and the effect it would have on traffic, power grids, and more. Others may opt for large scale cyber-attacks, natural disasters, and other major events.

When your tabletop “thinks big” you are likely to exercise a lot of different procedures and find even more gaps.

Keep the Exercise Grounded in Your Business

Conversely, the tabletop still needs to be grounded in the reality of your business. While a zombie apocalypse makes a good team costume theme, it isn’t something most businesses needed to address (and the CDC already covered it back in 2011.

The air traffic incident worked for the one company because their headquarters is near several airports. If your company is remote-first, that one is less relevant, but something like the CrowdStrike update incident could be relevant to you.

How would you respond if all your remote employees’ laptops stop working all at once?

Finding a good topic depends on knowing what is important to your company and where the business could be interrupted in a real-world incident.

Keep the Scenario Under Wraps

Whether you choose to work with a tabletop provider or build one internally, it’s also important to keep the details of the scenario secret from everyone except the ones running it.

Even your stand-in participants (e.g. playing an external role) should not know what will happen, just that if they’re called upon, what role they need to play. Depending on how the exercise unfolds, they might not even get brought into the conversation. The scenario might end up causing them to be unavailable or end up being handled differently.

But everyone who could potentially be involved needs to know that the tabletop is occurring and to be ready and available to participate in their potential part.

Turn the Exercise Into Action

The conclusion of every tabletop needs to be an honest discussion from the team of what worked and what didn’t. There are always gaps in process and a good tabletop finds them. Even bad contact information can be discovered by trying to call the number you have in your documents.

The post-exercise conversation should be used to identify opportunities for improvement and then make sure they are assigned to the people responsible for making it happen.

Tabletops serve two purposes:

  • First is to get the experience of what needs to be done in an emergency.
  • Second is to see where the process can be improved.

It’s important to make sure your tabletop serves both purposes.

Most compliance programs expect organizations to have at least one annual tabletop exercise. Finding the right time when you can pull executives and others into a multi-hour (or even all-day) session is difficult.

By leveraging Cybersecurity Awareness Month as an extra reason to schedule it, you may find October works as the best month to host it, and maybe even make it a little more fun by leaning into the themes the season brings.

So, while your tabletop exercise may not end up being spooky, at least the time of year will make everyone used to seeing “fake” scary things around them.

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters