Forensics & IR
Tabletop Exercise
Also known as: TTX, Cyber tabletop
Definition
A discussion-based simulation in which stakeholders walk through a hypothetical cyber incident to test plans, roles, decisions, and communication.
Examples
- A two-hour ransomware tabletop covering containment, ransom decisioning, and legal notifications.
- A supply-chain compromise scenario testing vendor coordination and customer communications.
Related terms
Incident Response Plan
A documented, approved playbook that defines how an organisation prepares for, detects, contains, eradicates, recovers from, and learns from cyber incidents.
Incident Response
The organised process of preparing for, detecting, analysing, containing, eradicating, and recovering from cyber security incidents, then capturing lessons learned.
DFIR (Digital Forensics and Incident Response)
A combined discipline that fuses digital forensic investigation with incident response to detect, contain, eradicate, and learn from cyber incidents.
Business Impact Analysis (BIA)
Business Impact Analysis (BIA) — definition coming soon.
Red Team
Red Team — definition coming soon.
Blue Team
Blue Team — definition coming soon.