Education

Cyber Tabletop Exercises in the Classroom: A Guide for Instructors

October 5, 20266 min readby

Cyber Tabletop Exercises in the Classroom: A Guide for Instructors

Students can memorise the NIST incident response phases. What they rarely get to practise is making a decision under pressure with incomplete information, while a "CEO" and a "lawyer" argue across the table.

A tabletop exercise gives them exactly that, in one class session. This guide is for instructors in university programmes, bootcamps, professional courses and certification prep who want to run one well.

Why tabletops work in teaching

  • They make abstract frameworks concrete. "Containment" means something different when it costs the business a day of revenue.
  • Every student has a role. Quiet students who wouldn't speak in a lecture will defend their decision as Legal or CFO.
  • They show that security is a business problem. Most of the hard calls are about money, regulators and communication.
  • The debrief is assessable. You can grade reasoning, not just right answers.

A 90-minute class plan

  1. Brief (10 min). Explain the setting, the roles and the rules: decisions are made by the group, and every decision needs a reason.
  2. Assign roles (5 min). Use the standard Crisis Management Team roles: CEO, CISO, CFO, Legal, Communications, plus an observer who takes notes. Larger classes run several teams in parallel.
  3. Play (45 min). Three or four decision points, each with a short inject: new information, a deadline, a phone call from a journalist.
  4. Debrief (25 min). Where did teams choose differently? What information did they wish they had? What would they change in the plan?
  5. Exit task (5 min). Each student writes one lesson learned from their role's point of view.

Choosing the scenario

Pick a scenario that matches the course level:

  • Intro courses: phishing that leads to a compromised email account. Simple, relatable, and rich in communication decisions.
  • IR and SOC courses: ransomware with a real technical thread. See our ransomware scenario walkthrough.
  • Management, MBA and CISO programmes: real incidents as boardroom dilemmas, such as Colonial Pipeline, MOVEit and SolarWinds.

Real incidents work well because students can read what actually happened after the exercise and compare.

Facilitation tips

  • Don't rescue the room. Silence and disagreement are where the learning happens.
  • Use time pressure. A visible timer on each decision changes the conversation.
  • Inject, don't lecture. If a team misses something, send an inject that makes it matter ("The regulator calls asking why they haven't heard from you").
  • Write down the split. Note where the team disagreed. That's your debrief agenda.

Assessing students

Grade the reasoning, not the outcome. A simple rubric with four criteria works:

  • Situational awareness: did they ask for the right information?
  • Role ownership: did each student act within their role's authority?
  • Decision quality: were trade-offs named and justified?
  • Reflection: does the exit task show a lesson they can apply?

Running it with CyberWar24

CyberWar24 builds branching tabletop exercises from a one-sentence description and runs them live. Students join from their own devices, you control the pace from a private facilitator panel (Facilitator Mode), and every session produces a decision heatmap and a debrief report you can use for grading.

Instructors: we give a free partner account for 6 months to instructors who use CyberWar24 in a course, and students join on the free plan. Email support@cyberwar24.com from your institution address to set it up.

Want to see the format first? Play the SolarWinds scenario, no signup needed.

Related Reading

educationinstructorsclassroomtabletop exercisecybersecurity training

Ready to Put This Into Practice?

Use our free scenario builder to create custom cyber tabletop exercises based on these strategies.