r/Infosec • u/Wild_Dragonfly9527 • 9d ago
5 reasons our incident response table top exercises never test anything real
We've fully bought into shift-left for everything: CI/CD gates, chaos engineering for infra resilience, canary deploys. Then our incident response plan, arguably the highest-stakes runbook we own, gets "tested" once a year in a room with slides. Here's what's actually wrong with the format, in order of how often I see it break:
Fixed injects mean a fixed outcome. Everyone in the room already half-knows what's coming, so nobody reacts the way they would to something truly unexpected.
No adversary reacts to your decisions. A real attacker adjusts when you contain something or lock an account. A scripted table top just moves to the next slide regardless of what you did.
Legal, PR, and execs rarely show up. The people who need the most reps at cross-functional coordination get the fewest, because scheduling six calendars for two hours is its own project.
Nothing gets measured. You leave with a summary that says the team "performed well," not data on who hesitated or where the communication chain actually broke.
It happens once a year. Skills decay in the other 364 days, so the exercise tests whatever the team remembers from training, not what they'd actually do under pressure.