Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
Get 24/7 incident response assistance from our global team
Please review the following rules before submitting your application:
1. Our main objective is to foster a community of like-minded individuals dedicated to combatting cybercrime and who have never engaged in Blackhat activities.
2. All applications must include research or a research draft. You can find content criteria in the blog. Please provide a link to your research or research draft using the form below.
Sharpen your incident response and crisis management with guided, scenario-based simulations
When a cyberattack strikes, there’s no pause button. Group-IB’s Tabletop Exercises place your team in a discussion-based, realistic simulation led by expert facilitators. You’ll uncover blind spots, test coordination, and strengthen decision-making before the stakes are too high.

Train response through realistic, discussion-based scenarios without touching live systems

Spot and fix gaps in escalation, role clarity, and decision flow

Upskill technical teams, business units, and leadership

Build confidence, resilience, and faster decision-making

Demonstrate readiness to your board, partners, and regulators

Get a detailed post-exercise report with insights and recommendations
If you have unused hours in your Group-IB Services Retainer, you can request a Tabletop
Exercise at no extra cost. Turn every purchased hour into real value for your team.





Participants work through evolving text- and visual-based scenarios using Group-IB’s proprietary platform. The exercise focuses on decision-making, cross-functional collaboration, and role clarity without technical attack execution.



A cybersecurity tabletop exercise is a simulated scenario where cross-functional teams respond to a mock cyber incident. It is designed to test coordination, decision-making, and incident response capabilities without affecting real systems.
A typical scenario might involve a ransomware attack disrupting core systems. Teams must contain the threat, manage internal and external communications, and make key decisions in real time.
Each session lasts 2 to 3 hours and includes several decision checkpoints.
Participants use Group-IB’s proprietary simulation platform with access to incident data, time constraints, and communication channels for live interaction with facilitators.
The standard package includes a pre-briefing, scenario delivery, expert facilitation, and a post-exercise report. Optional modules include scenario customization, documentation review, and improvement implementation support.
Our scenarios are based on Group-IB Threat Intelligence and cover the most common and high-impact attack types across industries and regions.
Examples may include:
Ransomware attacks
Nation-state espionage
Malware outbreaks
Business Email Compromise
Insider threats
Data breaches
Each scenario can be tailored to reflect your organization’s specific risks, structure, and regional threat profile.
Yes. Group-IB analyzes your threat landscape, attack vectors, organizational structure, and response plans to build a scenario that reflects your specific risks.