Cybersecurity Tabletop Exercise: Rehearse the First Hour of a Microsoft 365 Incident

Justin Kirsch | | 12 min read
Microsoft 365 cybersecurity tabletop exercise for financial institutions: three inject cards, a laptop checklist, and a wall clock beside the lines Rehearse the first hour, Know who acts, Document every decision

In Bank Director's 2026 Risk Survey (U.S. banks below $100 billion in assets), 89% of bank CEOs and technology executives said their bank had run a tabletop exercise of its cybersecurity incident response plan in the prior 12 months. What those exercises found is the more useful number: respondents whose bank ran one cited overreliance on one individual or function (36%) and internal communications (35%) as the most common gaps.

Both gaps cost the same thing on the day it counts: time. When one person holds the administrator access, the vendor phone numbers, and the authority to take systems offline, the response waits until that person answers. A tabletop exercise finds that dependency in a conference room on a weekday, while there's still time to share the knowledge and write the decisions down.

This guide from ABT, a Tier-1 Microsoft Cloud Solution Provider that has served more than 750 financial institutions, shows credit unions, banks, and mortgage companies how to run a cybersecurity tabletop exercise built around Microsoft 365 incidents, including the questions to put to your provider.

36%
of respondents whose bank ran a cybersecurity tabletop exercise said it exposed overreliance on one individual or function, the most common gap.
Source: Bank Director, 2026 Risk Survey (257 directors and executives of U.S. banks below $100 billion in assets, January 2026)

What a cybersecurity tabletop exercise is

An incident response tabletop exercise is a structured conversation about a bad day. The National Institute of Standards and Technology (NIST) defines tabletop exercises as "discussion-based exercises where personnel meet in a classroom setting or in breakout groups to discuss their roles during an emergency and their responses to a particular emergency situation."

The Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook states the goal: "to determine whether targeted plans and procedures are reasonable, personnel understand their responsibilities, and different departmental or business unit plans are compatible with each other." The same section names the limit: by themselves, tabletop exercises are "likely insufficient to validate recovery capabilities," because they are limited to discussion. Pair the exercise with a restore test, and see our guide to the Microsoft 365 backup gap.

If your plan needs work first, start with our Microsoft 365 incident response plan guide for financial institutions. Five terms to know:

Tabletop exercise
A facilitated discussion of a realistic incident.
Inject
A new fact the facilitator adds partway through, such as a second alert or a customer's call.
Hotwash
The facilitated debrief right after the exercise.
After action report
The written record of findings and fixes, each with an owner and a target date.
Functional exercise
The next step up: people perform their duties in a simulated operational environment.

Who belongs in the room

The FFIEC's Information Security booklet asks management to test the incident response program "through different test types, including scenario planning and tabletop testing, and perform the tests with appropriate internal and external parties." Invite the people who would decide or act in a real incident:

  • An executive with authority to act: take systems offline, engage outside counsel, and approve what customers and members hear.
  • Your IT lead and information security officer: they know where the logs live and who holds administrator access.
  • Compliance and your BSA officer: a cyber incident can call for a Suspicious Activity Report and a notice to law enforcement.
  • Legal counsel and your spokesperson: the FFIEC expects management to designate who speaks to the news media.
  • Your Microsoft 365 or managed detection and response provider: with your service agreement on the table.
  • Your cyber insurance contact: so the exercise uses the notice steps your policy lists. Our map of cyber insurance requirements for Microsoft 365 covers what carriers ask about.

The FFIEC expects management to "coordinate incident response planning with any third-party service provider plans." NIST's Cybersecurity Framework 2.0 looks for improvements from "security tests and exercises, including those done in coordination with suppliers and relevant third parties." The Bank Director survey shows why: 22% of respondents whose bank ran an exercise found vendor vulnerabilities, and 21% found overreliance on vendors for key functions such as data protection or risk management.

Put three questions to your provider: which detections trigger containment automatically, when an engineer works an incident, and who writes the incident timeline. ABT publishes its own answers, by rung (Guardian's service tiers), on the Microsoft 365 Guardian page. Read your provider's answers aloud and test each inject against them.

Three Microsoft 365 scenarios to rehearse

Microsoft's incident response team (DART) reports in the 2026 Microsoft Digital Defense Report that it "continues to observe identity compromise as the leading threat for organizations," which makes a stolen Microsoft 365 sign-in the place to start. DART's engagement data also shows a statistically significant year-over-year increase in dwell time, the period between the earliest evidence of attacker activity and its detection. So every scenario should ask who notices first.

Microsoft 365 infographic: three tabletop exercise scenarios for financial institutions, a stolen session, a fake help desk call, and a provider incident, each with the decision to test
Three Microsoft 365 scenarios, each built around a decision to make before an incident.

Scenario 1: A loan officer's Microsoft 365 session is stolen on a Friday afternoon

The inject

4:40 p.m. Friday. A customer calls a loan officer to confirm new wire instructions the officer never sent. A mailbox rule is forwarding the officer's email to an outside address.

The cost of an unowned decision

Containment waits for the one person with administrator rights, who has left for the weekend. Every hour of waiting is an hour the attacker keeps reading the mailbox.

Questions for the room:

Scenario 2: The "help desk" calls on Microsoft Teams

Microsoft's report describes Teams voice phishing in which attackers persuade employees, "usually on workdays during business hours," to grant access through a remote monitoring and management tool. From there, Microsoft writes, "Attackers complete reconnaissance in two minutes or less and then download malicious payloads." Our breakdown of the Teams helpdesk impersonation attack chain walks through every stage. These are the exercise injects:

10:05 a.m.
A Teams call from "IT support"

An external caller asks a branch supervisor to install a remote support tool to fix an email problem. The supervisor accepts.

10:12 a.m.
A Microsoft Defender alert

Defender flags suspicious activity on the supervisor's workstation. Who sees the alert first, and who can isolate the device?

11:30 a.m.
A second workstation

The same tool appears on a loan processing workstation. Does anyone have the authority to cut the branch's network, and is it written down?

4:55 p.m.
The overnight question

Containment is still in progress at closing time. Who's on call tonight, and who can approve taking a system offline at 2 a.m.?

The FFIEC names the question this scenario is built to answer: "Which personnel have authority to perform specific actions in the containment of the intrusion and restoration of the system." Two more to settle in the room. Can every employee recognize the "External" label on a Teams call (Microsoft recommends making sure external-user warnings are enabled)? Does your provider's automated containment act after hours or wait for a person to approve it?

On Microsoft 365 Guardian, the answer is in writing: at Guardian Contain and above, "critical risk detections trigger pre-authorized containment, including session revocation, in seconds at any hour."

Pre-authorization answers part of the FFIEC's authority question before the incident starts. Those seconds measure when containment starts. Revoking a session addresses the account; isolating the workstation and removing the remote tool are separate steps, so the exercise should name who takes each one and who confirms that access has ended. Hold your provider to an answer that specific.

Scenario 3: Your provider calls you

At 6:15 p.m., a service provider emails your designated contact: it has had a security incident, and services you rely on have been degraded for most of the afternoon.

Under federal banking rules, a bank service provider must notify "at least one bank-designated point of contact at each affected banking organization customer as soon as possible" when it determines an incident has materially disrupted or degraded, or is reasonably likely to, covered services (those subject to the Bank Service Company Act) for four or more hours. For federally insured credit unions, an incident that came through a credit union service organization, cloud service provider, or other third-party data host has its own trigger. The National Credit Union Administration (NCUA) must receive notice "within 72 hours of being notified by a third-party," or 72 hours after the credit union reasonably believes it had a reportable incident, whichever is sooner.

  • Is the bank-designated point of contact on file with each provider current, and is that inbox or phone answered on a weekend?
  • Who decides whether the provider's incident is also a reportable incident for your institution?
  • What does each contract say the provider owes you, and how fast? The FFIEC expects outsourced response work to follow "the institution's policies" and to protect the confidentiality of data.

The notice clocks your exercise should test

Each notice rule starts its clock at a different moment, and most of those moments are decisions someone at your institution makes.

WhoNotifyDeadlineThe clock starts
Banks supervised by the OCC, FDIC, or Federal ReservePrimary federal regulatorAs soon as possible, no later than 36 hoursWhen the bank "determines that a notification incident has occurred" (12 CFR 304.23, with the same wording at 12 CFR 53.3 and 225.302)
Federally insured credit unionsNCUAAs soon as possible, no later than 72 hoursWhen the credit union "reasonably believes" it had a reportable cyber incident, or, for an incident that came through a credit union service organization, cloud service provider, or other third-party data host, when that third party notifies it, whichever is sooner (12 CFR 748.1(c))
Bank service providersEach affected bank's designated contactAs soon as possibleWhen the provider determines an incident has materially disrupted or degraded, or is reasonably likely to, covered services for four or more hours (12 CFR 53.4)
Entities covered by New York's cybersecurity regulationNew York's superintendent of financial servicesNo later than 72 hoursAfter "determining that a cybersecurity incident has occurred" (23 NYCRR 500.17)
The same New York entities, if they make an extortion paymentNew York's superintendent of financial servicesWithin 24 hours, then a written explanation within 30 daysWhen the payment is made (23 NYCRR 500.17(c))
Mortgage companies and other non-bank lenders under the FTC Safeguards RuleFederal Trade CommissionNo later than 30 daysAfter discovery of a notification event involving 500 or more consumers (16 CFR 314.4(j))
Companies covered by Fannie Mae's information security supplementFannie Mae (a contractual requirement)No later than 36 hoursAfter identification of the incident, "or the reasonable conclusion" one may have occurred (Fannie Mae supplement)

The bank rule covers a narrower set of events than everyday security alerts. A notification incident is "a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade" the bank's operations, key business lines, or operations tied to U.S. financial stability. Deciding whether an event crosses that line is a judgment call, and it's the judgment to rehearse.

Customer notice, law enforcement contact, and Suspicious Activity Reports run on separate tracks. The interagency guidance on response programs expects procedures for each of them.

Compare your tenant with ABT's 750+ financial institution benchmark

ABT's free Microsoft 365 Security Assessment reviews the identity, email, and device settings your scenarios depend on through a read-only connection, compares them with ABT's 750+ financial institution benchmark, and includes an examiner readiness gap analysis. Most assessments complete within two weeks.

How to run a 90-minute tabletop exercise

Free tabletop exercise templates make the preparation lighter. NIST SP 800-84 includes a sample tabletop facilitator guide, participant guide, and after action report in its appendix. The Cybersecurity and Infrastructure Security Agency (CISA) offers more than 100 Tabletop Exercise Packages, including cyber scenarios built around ransomware, insider threats, and phishing.

Tier-1 Cloud Solution Provider (CSP)

A 90-Minute Microsoft 365 Tabletop Exercise

1
Set one objective

Pick the decision you most need to test, such as who can revoke a compromised session after hours, and write it down.

2
Write four to six injects

Build the scenario from a real Microsoft 365 attack path and plan a new fact every 10 to 15 minutes.

3
Invite the room

The executive decision-maker, IT, security, compliance, legal, communications, and your provider. Send everyone the service agreement in advance.

4
Run the injects

The facilitator reads each inject and asks what happens next, who decides, and where the evidence is. A note taker records every decision and every "we'd have to check."

5
Hold the hotwash

Discuss what went well and what needs work while it's fresh.

6
Write the after action report

Within a week, list each gap with an owner, an action plan, and a target date.

7
Retest the fix

Run the same inject at the next exercise to confirm the gap is closed.

Microsoft 365 infographic: a 90-minute tabletop exercise run of show, from setting one objective and writing injects to the hotwash, the after action report, and the retest
A suggested 90-minute run of show, from the objective to the retest of each fix.

If your last cyber tabletop exercise found no gaps, make the next one harder. In the Bank Director survey, 26% of respondents whose bank ran an exercise said it found none. Try a fresh inject, an after-hours start, or a missing key person.

What examiners look for afterward

The FFIEC's Business Continuity Management booklet lists what examiners review in an exercise and testing program, including "Exercises and tests related to interaction with third parties" and "Documentation of issues identified through exercises and tests, and action plans and target dates for resolution." An after action report with owners and dates is that documentation.

NCUA Letter to Credit Unions 24-CU-02, Board of Director Engagement in Cybersecurity Oversight (October 2024)

Conduct regular tabletop exercises to simulate cyber incident scenarios.

Incident Response Planning and Resilience: Tabletop Exercises (full letter)

For banks, the Interagency Guidelines direct each institution to "Regularly test the key controls, systems and procedures of the information security program," with the frequency and nature of the tests set by the bank's own risk assessment. Tests "should be conducted or reviewed by independent third parties or staff independent of those that develop or maintain the security programs." Credit unions follow the same testing language in NCUA's Part 748, Appendix A. That independence language is a good reason to have someone outside the IT team facilitate.

New York's cybersecurity regulation requires covered entities to test their incident response and business continuity plans "at a minimum annually" "with all staff and management critical to the response," and to test their ability to restore critical data from backups. Entities under the size thresholds in section 500.19(a) are exempt from that section. Fannie Mae's Information Security and Business Resiliency Supplement, which applies to the sellers, servicers, and other companies identified as subject to it, tells each one to "Complete, on at least an annual basis, a test of the incident response plan and capabilities and incorporate lessons learned from tests into the incident response plan," and to exercise its continuity plans annually "through tabletop or other similar exercises."

Mortgage companies and other non-bank lenders under the FTC Safeguards Rule need a written incident response plan that defines "clear roles, responsibilities, and levels of decision-making authority," which is what an exercise tests. Lenders that maintain customer information on fewer than five thousand consumers are exempt from that requirement under 16 CFR 314.6.

Your after action report should cover:

  • The scenario and the objective you set
  • Each decision, who made it, and how long the room took to reach it
  • Every gap the exercise exposed, each with an owner, an action plan, and a target date
  • The contact, access, and authority changes that remove a one-person dependency
  • The date of the retest

How ABT helps

ABT has served more than 750 financial institutions and manages Microsoft 365 tenants for credit unions, banks, and mortgage companies. Two parts of that work line up with what a tabletop exercise tests:

  • Who acts during an incident, by rung. On Microsoft 365 Guardian, automated containment runs around the clock at Guardian Contain and above. At Guardian Respond, ABT security engineers investigate and remediate covered incidents during business hours and produce "a written incident timeline suitable for an examiner or an insurer." At Guardian Resolve, a human is on the incident at any hour, so containment work continues while the one person with administrator rights is away for the weekend. Your exact severity definitions and response targets are set out in your service agreement.
  • The settings your scenarios depend on. ABT's free Microsoft 365 Security Assessment reviews identity and access, email authentication, data protection, device compliance, external sharing, and compliance posture through a read-only connection, and most assessments complete within two weeks. The assessment covers configuration; the exercise covers people, authority, and contracts.

For the exam itself, ABT's virtual CISO and exam readiness engagement is scoped and quoted to your exam calendar. Run the exercise on a weekday this quarter, find the one-person gap, and give the fix an owner, a target date, and a line in next year's budget.

Rehearse the response, then close the gaps it finds

Start with the settings your scenarios depend on, or see who acts on an incident at each Guardian rung.

🎯

Start with a free assessment

A read-only review of your Microsoft 365 identity, email, and device settings, delivered as a written report with a prioritized hardening roadmap.

Request a Free Microsoft 365 Security Assessment
💬

Compare the Guardian response rungs

See what automated containment covers around the clock and when an ABT security engineer joins a covered incident.

See the Guardian Rungs

Frequently Asked Questions

A cybersecurity tabletop exercise is a facilitated, discussion-based rehearsal of a realistic cyber incident. A facilitator presents a scenario and adds new situations as the session goes on, while participants talk through their roles, decisions, and coordination. NIST describes tabletop exercises as discussion-based only, so no systems or equipment are deployed during the session.

Federal guidance ties testing frequency to each institution's risk assessment, and NCUA Letter 24-CU-02 calls for regular tabletop exercises. Some rules set a floor: New York's cybersecurity regulation requires covered entities above its size thresholds to test incident response plans at least annually, and Fannie Mae's supplement requires an annual incident response test for the companies it covers.

Include the people who would make or carry out decisions in a real incident: an executive with authority to act, IT and information security staff, compliance and the BSA officer, legal counsel, communications, and outside providers that run part of your response. The FFIEC expects tests with appropriate internal and external parties.

Start with incidents your institution could face this year. Microsoft reports identity compromise as the leading threat its incident response team sees, so a stolen Microsoft 365 session makes a strong first scenario. Others worth rehearsing include Microsoft Teams help desk impersonation that leads to a remote access tool, and a security incident at a service provider.

Ask which detections trigger containment automatically, when an engineer works an incident, and who writes the incident timeline. ABT answers by rung for Microsoft 365 Guardian: from Guardian Contain up, critical risk detections trigger pre-authorized containment at any hour; Guardian Respond adds a written timeline and business-hours engineers on covered incidents; Guardian Resolve adds a human at any hour.

Record the scenario and objective, each decision and who made it, and every gap the exercise exposed. Give each gap an owner, an action plan, and a target date, because the FFIEC lists documentation of issues with action plans and target dates among the items examiners review. Then schedule a retest of each fix.


Justin Kirsch

Justin Kirsch

Co-Founder & CEO, Access Business Technologies

Justin Kirsch has been building and managing Microsoft environments for financial institutions since 1999. He is Co-Founder and CEO of Access Business Technologies, a Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services that has served more than 750 financial institutions. He helps banks, credit unions, and mortgage companies prepare for and respond to Microsoft 365 security incidents.