In This Article
In Bank Director's 2026 Risk Survey (U.S. banks below $100 billion in assets), 89% of bank CEOs and technology executives said their bank had run a tabletop exercise of its cybersecurity incident response plan in the prior 12 months. What those exercises found is the more useful number: respondents whose bank ran one cited overreliance on one individual or function (36%) and internal communications (35%) as the most common gaps.
Both gaps cost the same thing on the day it counts: time. When one person holds the administrator access, the vendor phone numbers, and the authority to take systems offline, the response waits until that person answers. A tabletop exercise finds that dependency in a conference room on a weekday, while there's still time to share the knowledge and write the decisions down.
This guide from ABT, a Tier-1 Microsoft Cloud Solution Provider that has served more than 750 financial institutions, shows credit unions, banks, and mortgage companies how to run a cybersecurity tabletop exercise built around Microsoft 365 incidents, including the questions to put to your provider.
What a cybersecurity tabletop exercise is
An incident response tabletop exercise is a structured conversation about a bad day. The National Institute of Standards and Technology (NIST) defines tabletop exercises as "discussion-based exercises where personnel meet in a classroom setting or in breakout groups to discuss their roles during an emergency and their responses to a particular emergency situation."
The Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook states the goal: "to determine whether targeted plans and procedures are reasonable, personnel understand their responsibilities, and different departmental or business unit plans are compatible with each other." The same section names the limit: by themselves, tabletop exercises are "likely insufficient to validate recovery capabilities," because they are limited to discussion. Pair the exercise with a restore test, and see our guide to the Microsoft 365 backup gap.
If your plan needs work first, start with our Microsoft 365 incident response plan guide for financial institutions. Five terms to know:
Who belongs in the room
The FFIEC's Information Security booklet asks management to test the incident response program "through different test types, including scenario planning and tabletop testing, and perform the tests with appropriate internal and external parties." Invite the people who would decide or act in a real incident:
- An executive with authority to act: take systems offline, engage outside counsel, and approve what customers and members hear.
- Your IT lead and information security officer: they know where the logs live and who holds administrator access.
- Compliance and your BSA officer: a cyber incident can call for a Suspicious Activity Report and a notice to law enforcement.
- Legal counsel and your spokesperson: the FFIEC expects management to designate who speaks to the news media.
- Your Microsoft 365 or managed detection and response provider: with your service agreement on the table.
- Your cyber insurance contact: so the exercise uses the notice steps your policy lists. Our map of cyber insurance requirements for Microsoft 365 covers what carriers ask about.
The FFIEC expects management to "coordinate incident response planning with any third-party service provider plans." NIST's Cybersecurity Framework 2.0 looks for improvements from "security tests and exercises, including those done in coordination with suppliers and relevant third parties." The Bank Director survey shows why: 22% of respondents whose bank ran an exercise found vendor vulnerabilities, and 21% found overreliance on vendors for key functions such as data protection or risk management.
Put three questions to your provider: which detections trigger containment automatically, when an engineer works an incident, and who writes the incident timeline. ABT publishes its own answers, by rung (Guardian's service tiers), on the Microsoft 365 Guardian page. Read your provider's answers aloud and test each inject against them.
Three Microsoft 365 scenarios to rehearse
Microsoft's incident response team (DART) reports in the 2026 Microsoft Digital Defense Report that it "continues to observe identity compromise as the leading threat for organizations," which makes a stolen Microsoft 365 sign-in the place to start. DART's engagement data also shows a statistically significant year-over-year increase in dwell time, the period between the earliest evidence of attacker activity and its detection. So every scenario should ask who notices first.
Scenario 1: A loan officer's Microsoft 365 session is stolen on a Friday afternoon
4:40 p.m. Friday. A customer calls a loan officer to confirm new wire instructions the officer never sent. A mailbox rule is forwarding the officer's email to an outside address.
Containment waits for the one person with administrator rights, who has left for the weekend. Every hour of waiting is an hour the attacker keeps reading the mailbox.
Questions for the room:
- Who can disable the account and select Revoke sessions in Microsoft Entra ID right now, and who is their backup? Microsoft cautions that "there could be a period between the initiation of access revocation and when access is effectively revoked," so the room should also decide who confirms that access has ended.
- Will the evidence still be there when someone looks? Microsoft Entra ID keeps sign-in logs for 30 days with Entra ID P1 and seven days on the free tier. Microsoft Purview Audit (Standard) keeps audit records for 180 days by default. Microsoft 365 Business Premium includes Entra ID P1.
- Who decides whether this is a reportable incident for your regulator, and when is that decision made?
- Who calls the customer, and who decides whether to request a recall of any wire already sent?
- Does this call for a Suspicious Activity Report, and who files it?
Scenario 2: The "help desk" calls on Microsoft Teams
Microsoft's report describes Teams voice phishing in which attackers persuade employees, "usually on workdays during business hours," to grant access through a remote monitoring and management tool. From there, Microsoft writes, "Attackers complete reconnaissance in two minutes or less and then download malicious payloads." Our breakdown of the Teams helpdesk impersonation attack chain walks through every stage. These are the exercise injects:
An external caller asks a branch supervisor to install a remote support tool to fix an email problem. The supervisor accepts.
Defender flags suspicious activity on the supervisor's workstation. Who sees the alert first, and who can isolate the device?
The same tool appears on a loan processing workstation. Does anyone have the authority to cut the branch's network, and is it written down?
Containment is still in progress at closing time. Who's on call tonight, and who can approve taking a system offline at 2 a.m.?
The FFIEC names the question this scenario is built to answer: "Which personnel have authority to perform specific actions in the containment of the intrusion and restoration of the system." Two more to settle in the room. Can every employee recognize the "External" label on a Teams call (Microsoft recommends making sure external-user warnings are enabled)? Does your provider's automated containment act after hours or wait for a person to approve it?
On Microsoft 365 Guardian, the answer is in writing: at Guardian Contain and above, "critical risk detections trigger pre-authorized containment, including session revocation, in seconds at any hour."
Pre-authorization answers part of the FFIEC's authority question before the incident starts. Those seconds measure when containment starts. Revoking a session addresses the account; isolating the workstation and removing the remote tool are separate steps, so the exercise should name who takes each one and who confirms that access has ended. Hold your provider to an answer that specific.
Scenario 3: Your provider calls you
At 6:15 p.m., a service provider emails your designated contact: it has had a security incident, and services you rely on have been degraded for most of the afternoon.
Under federal banking rules, a bank service provider must notify "at least one bank-designated point of contact at each affected banking organization customer as soon as possible" when it determines an incident has materially disrupted or degraded, or is reasonably likely to, covered services (those subject to the Bank Service Company Act) for four or more hours. For federally insured credit unions, an incident that came through a credit union service organization, cloud service provider, or other third-party data host has its own trigger. The National Credit Union Administration (NCUA) must receive notice "within 72 hours of being notified by a third-party," or 72 hours after the credit union reasonably believes it had a reportable incident, whichever is sooner.
- Is the bank-designated point of contact on file with each provider current, and is that inbox or phone answered on a weekend?
- Who decides whether the provider's incident is also a reportable incident for your institution?
- What does each contract say the provider owes you, and how fast? The FFIEC expects outsourced response work to follow "the institution's policies" and to protect the confidentiality of data.
The notice clocks your exercise should test
Each notice rule starts its clock at a different moment, and most of those moments are decisions someone at your institution makes.
| Who | Notify | Deadline | The clock starts |
|---|---|---|---|
| Banks supervised by the OCC, FDIC, or Federal Reserve | Primary federal regulator | As soon as possible, no later than 36 hours | When the bank "determines that a notification incident has occurred" (12 CFR 304.23, with the same wording at 12 CFR 53.3 and 225.302) |
| Federally insured credit unions | NCUA | As soon as possible, no later than 72 hours | When the credit union "reasonably believes" it had a reportable cyber incident, or, for an incident that came through a credit union service organization, cloud service provider, or other third-party data host, when that third party notifies it, whichever is sooner (12 CFR 748.1(c)) |
| Bank service providers | Each affected bank's designated contact | As soon as possible | When the provider determines an incident has materially disrupted or degraded, or is reasonably likely to, covered services for four or more hours (12 CFR 53.4) |
| Entities covered by New York's cybersecurity regulation | New York's superintendent of financial services | No later than 72 hours | After "determining that a cybersecurity incident has occurred" (23 NYCRR 500.17) |
| The same New York entities, if they make an extortion payment | New York's superintendent of financial services | Within 24 hours, then a written explanation within 30 days | When the payment is made (23 NYCRR 500.17(c)) |
| Mortgage companies and other non-bank lenders under the FTC Safeguards Rule | Federal Trade Commission | No later than 30 days | After discovery of a notification event involving 500 or more consumers (16 CFR 314.4(j)) |
| Companies covered by Fannie Mae's information security supplement | Fannie Mae (a contractual requirement) | No later than 36 hours | After identification of the incident, "or the reasonable conclusion" one may have occurred (Fannie Mae supplement) |
The bank rule covers a narrower set of events than everyday security alerts. A notification incident is "a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade" the bank's operations, key business lines, or operations tied to U.S. financial stability. Deciding whether an event crosses that line is a judgment call, and it's the judgment to rehearse.
Customer notice, law enforcement contact, and Suspicious Activity Reports run on separate tracks. The interagency guidance on response programs expects procedures for each of them.
Compare your tenant with ABT's 750+ financial institution benchmark
ABT's free Microsoft 365 Security Assessment reviews the identity, email, and device settings your scenarios depend on through a read-only connection, compares them with ABT's 750+ financial institution benchmark, and includes an examiner readiness gap analysis. Most assessments complete within two weeks.
How to run a 90-minute tabletop exercise
Free tabletop exercise templates make the preparation lighter. NIST SP 800-84 includes a sample tabletop facilitator guide, participant guide, and after action report in its appendix. The Cybersecurity and Infrastructure Security Agency (CISA) offers more than 100 Tabletop Exercise Packages, including cyber scenarios built around ransomware, insider threats, and phishing.
A 90-Minute Microsoft 365 Tabletop Exercise
Pick the decision you most need to test, such as who can revoke a compromised session after hours, and write it down.
Build the scenario from a real Microsoft 365 attack path and plan a new fact every 10 to 15 minutes.
The executive decision-maker, IT, security, compliance, legal, communications, and your provider. Send everyone the service agreement in advance.
The facilitator reads each inject and asks what happens next, who decides, and where the evidence is. A note taker records every decision and every "we'd have to check."
Discuss what went well and what needs work while it's fresh.
Within a week, list each gap with an owner, an action plan, and a target date.
Run the same inject at the next exercise to confirm the gap is closed.
Suggested agenda: 10 minutes for the objective and ground rules, 60 minutes of injects, a 15-minute hotwash, and 5 minutes to assign owners.
If your last cyber tabletop exercise found no gaps, make the next one harder. In the Bank Director survey, 26% of respondents whose bank ran an exercise said it found none. Try a fresh inject, an after-hours start, or a missing key person.
What examiners look for afterward
The FFIEC's Business Continuity Management booklet lists what examiners review in an exercise and testing program, including "Exercises and tests related to interaction with third parties" and "Documentation of issues identified through exercises and tests, and action plans and target dates for resolution." An after action report with owners and dates is that documentation.
Conduct regular tabletop exercises to simulate cyber incident scenarios.
For banks, the Interagency Guidelines direct each institution to "Regularly test the key controls, systems and procedures of the information security program," with the frequency and nature of the tests set by the bank's own risk assessment. Tests "should be conducted or reviewed by independent third parties or staff independent of those that develop or maintain the security programs." Credit unions follow the same testing language in NCUA's Part 748, Appendix A. That independence language is a good reason to have someone outside the IT team facilitate.
New York's cybersecurity regulation requires covered entities to test their incident response and business continuity plans "at a minimum annually" "with all staff and management critical to the response," and to test their ability to restore critical data from backups. Entities under the size thresholds in section 500.19(a) are exempt from that section. Fannie Mae's Information Security and Business Resiliency Supplement, which applies to the sellers, servicers, and other companies identified as subject to it, tells each one to "Complete, on at least an annual basis, a test of the incident response plan and capabilities and incorporate lessons learned from tests into the incident response plan," and to exercise its continuity plans annually "through tabletop or other similar exercises."
Mortgage companies and other non-bank lenders under the FTC Safeguards Rule need a written incident response plan that defines "clear roles, responsibilities, and levels of decision-making authority," which is what an exercise tests. Lenders that maintain customer information on fewer than five thousand consumers are exempt from that requirement under 16 CFR 314.6.
Your after action report should cover:
- The scenario and the objective you set
- Each decision, who made it, and how long the room took to reach it
- Every gap the exercise exposed, each with an owner, an action plan, and a target date
- The contact, access, and authority changes that remove a one-person dependency
- The date of the retest
How ABT helps
ABT has served more than 750 financial institutions and manages Microsoft 365 tenants for credit unions, banks, and mortgage companies. Two parts of that work line up with what a tabletop exercise tests:
- Who acts during an incident, by rung. On Microsoft 365 Guardian, automated containment runs around the clock at Guardian Contain and above. At Guardian Respond, ABT security engineers investigate and remediate covered incidents during business hours and produce "a written incident timeline suitable for an examiner or an insurer." At Guardian Resolve, a human is on the incident at any hour, so containment work continues while the one person with administrator rights is away for the weekend. Your exact severity definitions and response targets are set out in your service agreement.
- The settings your scenarios depend on. ABT's free Microsoft 365 Security Assessment reviews identity and access, email authentication, data protection, device compliance, external sharing, and compliance posture through a read-only connection, and most assessments complete within two weeks. The assessment covers configuration; the exercise covers people, authority, and contracts.
For the exam itself, ABT's virtual CISO and exam readiness engagement is scoped and quoted to your exam calendar. Run the exercise on a weekday this quarter, find the one-person gap, and give the fix an owner, a target date, and a line in next year's budget.
Rehearse the response, then close the gaps it finds
Start with the settings your scenarios depend on, or see who acts on an incident at each Guardian rung.
Start with a free assessment
A read-only review of your Microsoft 365 identity, email, and device settings, delivered as a written report with a prioritized hardening roadmap.
Request a Free Microsoft 365 Security AssessmentCompare the Guardian response rungs
See what automated containment covers around the clock and when an ABT security engineer joins a covered incident.
See the Guardian RungsFrequently Asked Questions
A cybersecurity tabletop exercise is a facilitated, discussion-based rehearsal of a realistic cyber incident. A facilitator presents a scenario and adds new situations as the session goes on, while participants talk through their roles, decisions, and coordination. NIST describes tabletop exercises as discussion-based only, so no systems or equipment are deployed during the session.
Federal guidance ties testing frequency to each institution's risk assessment, and NCUA Letter 24-CU-02 calls for regular tabletop exercises. Some rules set a floor: New York's cybersecurity regulation requires covered entities above its size thresholds to test incident response plans at least annually, and Fannie Mae's supplement requires an annual incident response test for the companies it covers.
Include the people who would make or carry out decisions in a real incident: an executive with authority to act, IT and information security staff, compliance and the BSA officer, legal counsel, communications, and outside providers that run part of your response. The FFIEC expects tests with appropriate internal and external parties.
Start with incidents your institution could face this year. Microsoft reports identity compromise as the leading threat its incident response team sees, so a stolen Microsoft 365 session makes a strong first scenario. Others worth rehearsing include Microsoft Teams help desk impersonation that leads to a remote access tool, and a security incident at a service provider.
Ask which detections trigger containment automatically, when an engineer works an incident, and who writes the incident timeline. ABT answers by rung for Microsoft 365 Guardian: from Guardian Contain up, critical risk detections trigger pre-authorized containment at any hour; Guardian Respond adds a written timeline and business-hours engineers on covered incidents; Guardian Resolve adds a human at any hour.
Record the scenario and objective, each decision and who made it, and every gap the exercise exposed. Give each gap an owner, an action plan, and a target date, because the FFIEC lists documentation of issues with action plans and target dates among the items examiners review. Then schedule a retest of each fix.
Justin Kirsch
Co-Founder & CEO, Access Business Technologies
Justin Kirsch has been building and managing Microsoft environments for financial institutions since 1999. He is Co-Founder and CEO of Access Business Technologies, a Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services that has served more than 750 financial institutions. He helps banks, credit unions, and mortgage companies prepare for and respond to Microsoft 365 security incidents.

