Why Incident Response Plans Fail in Practice

A written incident response plan is a necessary foundation, but it is not sufficient. The SAMA Cybersecurity Framework (SAMA CSF) and the NCA Essential Cybersecurity Controls (NCA ECC) both require organisations to demonstrate capability, not merely document intent. When a real incident strikes, teams face simultaneous pressure: technical investigation, business continuity decisions, regulatory notification, and media management all demand attention within hours. Without prior rehearsal, coordination breaks down, critical steps are skipped, and recovery extends far longer than necessary.

Tabletop exercises bridge the gap between policy and performance. They simulate realistic incident scenarios in a controlled environment, allowing teams to discover misalignments before they cost time, money, and reputation.

What Makes a Tabletop Exercise Effective

A tabletop exercise is a structured, facilitated discussion in which key stakeholders walk through a hypothetical incident scenario step by step. Unlike full-scale simulations, it requires no technical infrastructure or live system disruption. Instead, it focuses on decision-making, communication, and role clarity.

Essential elements include:

  • Cross-functional participation: Security, IT operations, legal, compliance, communications, and business leadership must all be present. Each role will face decisions during a real incident; absence from the exercise means those decisions will be made under pressure without prior thought.
  • Realistic scenario: Base the scenario on threats relevant to your sector and organisation size. A financial services firm should simulate data exfiltration or ransomware affecting customer records. A critical infrastructure operator should consider supply-chain compromise or operational technology attack.
  • Timed injects: The facilitator introduces new information at planned intervals—a ransom demand, a media inquiry, a regulator's call—forcing teams to adapt and escalate decisions in real time.
  • Documented outcomes: Capture decisions, delays, and disagreements. These are not failures; they are the point. Post-exercise debrief turns friction into learning.

Alignment with Saudi Regulatory Expectations

The Saudi Data Protection Law (PDPL) requires organisations to demonstrate incident response capability and to notify affected individuals and authorities within defined timeframes. The NCA ECC explicitly mandates testing of incident response procedures. Tabletop exercises provide auditable evidence of this testing and create a record of how your organisation would meet PDPL notification obligations under pressure.

SAMA CSF governance principles require boards to understand cyber risk and the organisation's readiness to respond. A tabletop exercise, with results presented to leadership, satisfies this requirement far more credibly than a static plan.

Common Gaps Revealed by Tabletop Exercises

In practice, organisations discover:

  • Unclear escalation paths: Who authorises a ransom negotiation? Who decides to shut down systems?
  • Communication delays: Legal and communications teams are not looped in early enough; critical stakeholders learn of the incident from the news.
  • Incomplete contact lists: Key decision-makers' phone numbers are outdated or missing.
  • Conflicting priorities: Finance wants to pay a ransom immediately; legal advises against it. No prior agreement exists on who decides.
  • Regulatory knowledge gaps: Teams do not know PDPL notification timelines or NCA reporting requirements, leading to compliance violations.

Making Tabletop Exercises Routine

Conduct at least one tabletop exercise annually, with different scenarios and rotating participants. After each exercise, document findings, assign remediation owners, and track closure. Over time, this builds institutional muscle memory and confidence.

For organisations new to this practice, start small: a two-hour exercise with 8–10 participants is sufficient. As maturity grows, expand to half-day sessions with more complex scenarios and external participants (e.g., regulators, law enforcement, incident response vendors).

The Competitive Advantage

Organisations that rehearse incident response consistently recover faster, communicate more effectively, and suffer less regulatory and reputational damage. In a region where cyber threats are rising and regulatory scrutiny is intensifying, tabletop exercises are no longer optional. They are a core control that separates prepared organisations from those hoping their plan will work.