Aon | Professional Services Practice
Table Stakes: Planning a Tabletop Simulation
Release Date: July 2024Tom Ricketts, Cyber Practice Leader of the Professional Services Practice at Aon, discusses how indispensable tabletop simulations are in allowing professional service firms to better prepare and respond to cyber-attacks.
Key Takeaways
- Tabletop simulations are an indispensable part of a professional service firm’s preparation for a cyber event.
- There are many vendors available to run a tabletop, at a variety of price points.
- Careful planning is crucial to maximizing value and return on investment.
Setting the Table
Tabletop simulations are strongly recommended by insurers and are a consideration in underwriting. A cyber incident is an enterprise event that can impair the firm’s ability to service clients in multiple ways and potentially impact clients directly. It is essential that the firm’s leadership team understands and prepares for these events and be ready to implement the actions required to respond.
Difficult decisions will need to be made quickly and under pressure – for instance, should a ransom be paid? Who can authorize and make such a payment in an emergency?
In the words of Mike Tyson, “Everyone has a plan until they get punched in the mouth.” A cyber-attack is a metaphorical punch in the mouth. Written plans should be stress tested, via tabletop simulations, to ensure that roles, responsibilities and authority are clear and to give leaders experience with role-played scenarios to prepare them to better deal with the unexpected.
The IBM-Ponemon “Cost of a data breach 2023” found that not only was incident response planning and testing a top 3 cost mitigator, but also that organizations with high levels of these countermeasures saved $1.49 million in data breach costs compared to organizations with low levels or none, and they resolved incidents 54 days faster.
What’s on the Menu?
Tabletop exercises can be structured to fit different purposes and can take many forms. They can be on-site or remote, be brief or intensive, can involve different constituencies within the firm as well as external vendors.
But whatever the purpose or form, the most important issue is planning. A cheap and quick tabletop that is well-planned will have more value than an expensive one that is just “delivered” with no planning.
For a professional service firm to get the most value, the tabletop and the expectations behind it should be planned in detail, with leaders spending time with the vendor or staff member, understanding and agreeing on what is needed, expectations and objectives, required pre-work, and what product, deliverables, and post-exercise reports (if any) are expected.
Is the tabletop intended to:
- Raise awareness about the potential implications and impact of a cyber event with senior executives and management?
- Help senior executives and management recognize and assign leadership roles and responsibilities in responding to a cyber event (particularly ransomware and extortion)?
- Test an existing Incident Response Plan and/or Business Continuity Plan? Should it be scenario-driven or conceptual? Will the firm involve other vendors (managed security service provider, breach counsel, et.al.)?
- Form the basis for creating or enhancing an Incident Response Plan or Business Continuity Plan?
- Be a purely IT-focused exercise with the emphasis on specific technical response issues?
Each of these would be a very different exercise and depending on the maturity and level of preparedness within the firm there may be value in holding several tabletops as part of an overall development process, using different vendors, and engaging different constituencies within the firm.
Involving the firm’s selected, insurer-approved service providers helps the firm understand their role and their expected actions and what assistance and cooperation they will need from the firm.
Prix-Fixe or à la Carte
Our feedback and experience indicate that, broadly speaking, you get what you pay for with tabletop exercises.
However, the most important point is that paying for an exercise that is not responsive to your firm’s cyber-maturity, organizational structure and specific objectives will have a very low return on investment and could be counter-productive, especially if participants feel their time was wasted.
Pricing will vary depending on duration and the number of facilitators and vendors involved. Other factors include the amount of preparation and post-work that the facilitator will be required to do, as well as whether it is conducted as a remote or on-site exercise. So, before purchasing a “fixed-price, set-piece” tabletop it is important to understand what is being offered to ensure it meets the firm’s objectives.
A “canned” exercise that is delivered remotely with no tailoring to the firm’s needs will be much less expensive than a custom-built exercise delivered on-site over several days, but the value realized will depend on whether the exercise meets the firm’s needs and expectations.
Ways to Save
There are many vendors who can facilitate a tabletop and, as with any investment, the economics are important. It is worth considering options that might offer savings when sourcing a facilitator for a simulation:
- Many cyber insurers and their panels of approved vendors offer tabletops and may offer discounts because of the insurer relationship.
- Security services vendors are often able to provide tabletops and again, may provide discounts to firms with existing relationships. The vendor’s familiarity with the firm’s network, security and team may also be helpful (although rotating vendors periodically to keep the exercises fresh and different is also important).
- Many independent vendors offer tabletops – consulting firms, law firms with data privacy and breach counsel practices, technology vendors (particularly those in security), cybersecurity firms, et.al. These firms may offer different pricing structures depending on the delivery structure and format of the exercise.
Conclusion
Tabletop simulations can make an enormous difference to the firm’s cyber-resilience. They can materially mitigate the impact and ultimate cost of a cyber-attack.
- Insurers recommend holding tabletop simulations regularly.
- Varying the scenarios helps test different aspects of the response and ensures that teams learn to be flexible. Including extortion in scenarios is important, as this is the most common outcome of attacks.
- Careful planning and collaboration with the facilitator will add a lot of value to the exercise.
- Leveraging relationships with vendors can help save money.
- Rotating vendors periodically is recommended.
Field Marshal Helmuth von Moltke observed, in the heat of battle the plan rarely survives the first encounter; but being prepared and having run through many scenarios, the participants learn the flexibility and develop the “muscle memory” that helps them to respond effectively.
“In preparing for battle I have always found that plans are useless, but planning is indispensable.”
Dwight D. Eisenhower
Read more articles by Tom Ricketts here.
Contact
The Professional Services Practice at Aon values your feedback. To discuss any of the topics raised in this article, please contact Tom Ricketts.
Tom Ricketts
Managing Director
New York
About Aon
Aon plc (NYSE: AON) (NYSE: AON) exists to shape decisions for the better — to protect and enrich the lives of people around the world. Through actionable analytic insight, globally integrated Risk Capital and Human Capital expertise, and locally relevant solutions, our colleagues in over 120 countries and sovereignties provide our clients with the clarity and confidence to make better risk and people decisions that help protect and grow their businesses.
Follow Aon on LinkedIn, X, Facebook and Instagram. Stay up-to-date by visiting Aon’s newsroom and sign up for news alerts here.
©2024 Aon plc. All rights reserved.
Aon is not a law firm or accounting firm and does not provide legal, financial or tax advice. Any commentary provided is based solely on Aon’s experience as insurance practitioners. We recommend that you consult with your own legal, financial and/or insurance advisors on any commentary provided herein. All descriptions, summaries or highlights of coverage described herein are for general informational purposes only and do not amend, alter or modify the actual terms and conditions of any relevant policy. Coverage is governed only by the terms and conditions of such policy. Insurance coverage in any particular case will depend upon the type of policy in effect, the terms, conditions and exclusions in any such policy, and the facts of each unique situation. No representation is made that any specific insurance coverage would apply in the circumstances outlined herein. Please refer to the individual policy forms for specific coverage details.
The information contained in this document and the statements expressed are of a general nature and are not intended to address the circumstances of any particular individual or entity.
This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.
Insurance products and services offered by Aon Risk Insurance Services West, Inc., Aon Risk Services Central, Inc., Aon Risk Services Northeast, Inc., Aon Risk Services Southwest, Inc., and Aon Risk Services, Inc. of Florida and their licensed affiliates.