// INTEL LOG
Why your BCP/IR Tabletops Suck.
And it's not your fault.
Most tabletop exercises are still run through a PowerPoint deck or a Word document. In October 2025, I ran my first business continuity tabletop. I was excited about it despite having no experience with BC-specific exercises. My background was in Incident Response tabletops, which felt more natural to me. I knew our security controls, I knew our IT environment, and IR tabletops are inherently more technical. Business continuity is a different animal: more moving pieces, more departments, different locations, different SLAs, RTOs, MADs, all of that jazz.
During that first BC tabletop, I leaned on a PowerPoint and some Word docs, and the silence was deafening. Departments I didn't know well had nothing to work from, and engagement flatlined. This wasn't even a large group compared to what bigger organizations deal with.
That experience pointed to a problem beyond my first tabletop: modern tabletop exercises are bad at generating real interaction and real data. When participants aren't bought in, you're not getting anything useful out of the exercise, just a checkbox and a quiet room. This isn't a slight on any of the departments. It's a problem with the process.
// 01 — THE FACILITATOR GAP
The facilitator can be lost, too
The facilitator can be just as lost as the participants. Whether you're running an Incident Response tabletop, a Business Continuity tabletop, or a combo scenario that touches both, you're expected to have command over every department's processes, every system dependency, and every recovery priority in the room. You're building injects from scratch, guessing at what scenarios are relevant to teams you don't fully understand, and hoping it lands. It's a lot of pressure to put on one person, and when it doesn't go well, the exercise gets written off instead of the process.
"When it doesn't go well, the exercise gets written off instead of the process."
// 02 — THE PREP TAX
All that work, for a quiet room
The prep work starts before anyone walks into the room. You're building scenario decks, writing inject questions, formatting Word documents, coordinating across teams, and trying to put together something professional enough to take seriously. After all of that, you get an hour of awkward silence and a room full of people who would rather be anywhere else. The ROI just isn't there, and most organizations feel that but don't know how to fix it.
// 03 — THE PAPER TRAIL
What happens after
After the exercise, someone takes notes, maybe, and those notes turn into a summary document that gets filed somewhere and never looked at again. Action items get assigned with no real ownership and no follow through. Then audit season rolls around and you're scrambling to prove the exercise happened and meant something. The cycle repeats every year, with the same gaps and problems going unaddressed.
// 04 — THE SOLUTION
A better way to run tabletops
With Breachday, participants join via a room code with no setup. Structured injects, multiple response formats, and industry-standard tabletop templates support the exercise. When it's over, you have audit-ready reports and actionable data instead of a pile of sticky notes and someone's meeting notes.
Beyond the exercise itself, Breachday gives you a Lessons Learned Kanban board, asset and business process tracking, and a home for your overall BC/IR program. That program data feeds directly into your tabletops, grounding scenarios in your actual environment. The less your participants have to think about the tool, the more they can focus on the exercise. You also get audit-ready reports with tracked responses, lessons learned, and a sign-in sheet in one package for your auditors.
No accounts, no installs. Any participant joins from any device with a 4-character code.
Track action items from every exercise with real ownership and follow-through built in.
Built-in CISA Cybersecurity Tabletop Exercise Package templates ready to adapt for Plus and Pro users.
Describe your scenario, optionally pull in your BC assets, and generate a tabletop tailored to your org.
Breachday comes loaded with default templates out of the box, and for Plus and Pro users, CISA Cybersecurity Tabletop Exercise Package templates are built right in, ready to be adapted and dropped into your next exercise without having to hunt them down yourself.
But templates only get you so far. Breachday uses AI for two focused tasks. The platform pulls in cybersecurity industry news to suggest scenarios and recommend matching templates or CISA CTEPs based on the current threat landscape, not what was relevant two years ago. The AI Scenario Builder also lets you describe a scenario you're worried about and optionally pull in your BC assets and business processes to generate a tabletop tailored to your organization. Instead of a generic ransomware scenario that could apply to any company, your tabletop reflects your environment, your risks, and your people.
// 05 — WHO IT'S FOR
Built for tabletop owners
Breachday is built for people who own the tabletop process: GRC security analysts, security managers, compliance leads, and MSPs running exercises across multiple clients. It supports structured, repeatable exercises without the overhead of starting from scratch every time, whether you're working toward SOC 2 or PCI DSS or building a more mature BC/IR program.
// READY TO TRY IT?
15-day free trial. No credit card required.
Every account comes with a 15-day risk-free trial. Sign up and run your first exercise today, or contact us for a guided demo.