Tabletop Exercises from NineStar Connect Asks, “What Would You Do?”
A Tabletop Exercise, or TTX, is a collaborative role-playing activity in which participants work through hypothetical scenarios designed to test their responses to any number of real-world situations that might affect their organization. Designated facilitators present seemingly innocuous facts that belie a more serious issue in order to evaluate how an organization or department responds. The goal of the exercise is to work as a team to crowdsource solutions, evaluate processes, and shore up any weaknesses before these scenarios happen in real life.
TTXs can be used to work through a number of situations, including:
- Natural disasters, such as tornadoes, floods, ice storms, droughts, heat waves, and more.
- Malicious actors, such as professional cyber criminals/terrorists, “hacktivists,” thrill seekers, etc.
- Equipment failures, power outages, and fiber/line cuts.
- Insider threats, which are often caused by human error, such as an employee unwittingly installing malware on a company computer or a disgruntled employee abusing his/her access privileges.
- A negative public relations incident that has an adverse effect on an organization’s image and requires mitigation.
- Customer service, especially as it pertains to angry/violent customers.
“TTXs are designed to help organizations talk through a problem and test their processes and solutions,” says Shira Dankner of NineStar Connect. “We help companies brainstorm existing solutions, look for new ones, and create an action plan to help you be more effective when and if a particular situation arises.”
GAME ON!
Similar to Dungeons & Dragons and other popular role-playing games, a TTX sends its participants on a quest to mitigate a seemingly small setback before it becomes a full-blown situation.
Although the Kankakee Valley REMC (KVREMC) participated in a disaster planning session in the past, IT Operations Manager Brandon Sutter was excited to be part of a TTX that would evaluate his department individually. Having worked with NineStar Connect on past engagements regarding cybersecurity, he knew that Dankner’s team could be trusted to create a realistic scenario designed around specific goals that KVREMC had in mind while offering their professional expertise, guidance, and support throughout the process.
“It’s never easy to have an outside party come into your environment and bring light to your weaknesses, but Shira and her team approached it professionally. They conveyed to me a message of positivity, assuring us that they are not trying to make us feel bad about ourselves … but to make us better as a team,” he said.
SETTING THE SCENE
Sutter, Dankner, and the NineStar personnel formed the “Red Team,” which was responsible for creating a scenario that was both realistic and relevant in order to keep the participants engaged in the exercise.
Sutter said it was important to have someone on the Red Team who knew the inner workings of the environment in order to bring issues to the surface and force him to think critically about the ways in which an attack could occur. Ultimately, they opted to become hypothetical hackers who had infiltrated KVREMC’s systems and caused havoc.
Department employees then used their existing protocols to evaluate the issue, identify the source, and respond accordingly — a process they executed with varying degrees of success.
“I saw, in real time, our team in a very stressful situation and their minds going a million miles a minute trying to think of every technical detail,” Sutter says.
Throughout the process, participants took notes and worked the problem on a trial-and-error basis until the issue was mitigated. Once the TTX was completed, the NineStar Connect team evaluated their efforts and created an action plan that they could implement for future incidents.
KVREMC’s action plan consisted of 10 areas of improvement, which Dankner said is typical for most organizations that have a decent amount of security protocols in place.
Sutter says he wasn’t completely caught off guard by any of the findings. In fact, it confirmed some of his concerns regarding certain areas, and he now plans to make those a priority. He recognizes the importance of having a well-thought-out incident response and communications plan to take the guesswork out of the process and ensure that steps are not missed during a chaotic event.
He said he was very happy with the level of professionalism and expertise that NineStar brought to the experience.
“This exercise was not like anything we had done before, so we found ourselves experiencing a mix of emotions,” Sutter said. “While some aspects were stressful, it was still a very humbling experience to be a part of. Like any first-time experience, you are never at your best, so we will make it a priority to keep testing ourselves so that when a cyber incident occurs, we will be prepared to respond.”
To learn more about NineStar’s Cybersecurity solutions, CLICK HERE.