By BJ Gardner, Assistant VP – Information Technology
In the age of AI, cyber threats are growing more sophisticated. Email phishing attempts for information are increasingly difficult to differentiate from legitimate email requests. Targeted deepfakes can mimic voices with enough accuracy to extract sensitive data you might otherwise hesitate to share. Given these advancing capabilities, one’s ability to respond to potential cyber threats is a crucial line of defense against cybercriminals.
How can you put your cyber safety knowledge to the test? Tabletop exercises ensure teams understand their roles and how to put policies into action when an emergency strikes.
In 2025, PLM conducted a tabletop test based on a real-world cybercriminal group, Scattered Spider, which has been known to target company staff while posing as the help desk. Over four hours, our team members responded to a multi-factor authentication spoof that escalated to a ransomware attack using our established policies and procedures.
Afterward, we examined our performance. It served as an invaluable tool to discover and address any gaps in accountability. Admittedly, we identified a few outdated policies and procedures – mainly some point persons listed in procedures who no longer worked at the company, were not properly identified, or had not participated in the exercise. With those lessons learned, our team is now better equipped for any future disruptions.
Consider what we gained from our tabletop exercise and see how, in addition to the following best practices, you can improve on your own recovery response efforts:
- Define roles: Businesses should have a communications process that is clearly defined and distributed to all relevant parties. Employee leaders should know their roles and what to do with their staff in an emergency. Leaders should designate who is responsible for engaging external law enforcement or crisis communications teams.
- Train: Leadership should maintain ongoing cyber risk mitigation training with employees. Cyber policies should be incorporated into onboarding, and employees should be tested on policies and procedures through monthly phishing tests. This way, leaders gain a better understanding of employee awareness and can address critical gaps where additional training is needed.
- Practice: Businesses should consider utilizing tabletop exercises beyond cyber. Business continuity is not specific to IT or disaster recovery. Tabletop exercises can be a helpful way to verify policies, clarify roles and practice response times to limit any operational disruption across an organization.
The methods used by cybercriminals are becoming more difficult to identify. Tabletop exercises are one way to better ensure an organization is prepared to manage a situation should a threat slip through their cyber defenses. When you are armed with the right tools and information, you are better equipped to mitigate cyber threats and avoid a full-scale disaster.



