HIVE80lab — Ops notes

The 5 Failure Points a Small-Team Tabletop Will Find (Before a Real Incident Does)

A tabletop exercise sounds like enterprise theatre: a conference room, a

facilitator, a binder. But the small-team version is just walking through

"it's 9am Tuesday and every file server shows an extortion note" out loud,

with your actual people, and writing down what you didn't have an answer to.

The value isn't the ceremony — it's that the gaps surface in a room instead of

at 2am.

Run any of the classic walkthroughs — ransomware, business email compromise,

a credential spray against your admin accounts, a leaver who still has access,

a supplier breach on your shared drive — and the same handful of failure

points shows up in nearly every small team:

1. Nobody knows who decides

The single most common gap. Ask "who is authorised to unplug the file server?"

and the room goes quiet. Not "who can" — anyone can pull a cable. Who

decides. If that isn't written down before the incident, the decision gets

made by whoever panics first.

2. The backups restore into the same breach

Everyone knows they have backups. Far fewer teams have walked the question:

if ransomware encrypts the NAS, do the backups live somewhere the attacker

also reached? Walkthroughs surface this in five minutes. Real incidents

surface it at restore time, when it's too late.

3. No message was ever written

Someone has to tell staff what to do right now, and someone has to answer

the first customer email. Teams that haven't pre-written those two messages

lose hours drafting them mid-incident — or worse, say nothing and let

rumours run. Two half-page templates, written on a calm day, fix this.

4. Access nobody removed

The tabletop asks: who has admin access today? The honest answer in most

small teams is "more people than we meant". Old suppliers, ex-contractors,

shared passwords in a spreadsheet. The exercise turns that into a one-hour

cleanup task instead of an incident-scoping nightmare.

5. The plan lives in a drawer

Every walkthrough ends the same way: the "plan" was a document nobody had

read. The fix isn't more documentation — it's a one-page fill-in plan with

named roles, plus short checklists people can actually follow under stress.

Print it. Tape it near the router if you have to.

---

None of these are exotic. All of them are findable in an afternoon with five

pre-built scenario scripts and a facilitator page. The Ops Starter Kit

includes five walkthrough scenarios (ransomware, BEC, credential spray,

insider, supplier breach) with the questions and failure points above

pre-written into the facilitator notes.

*This is general guidance, not legal or regulatory advice. Adapt every template

to your own environment.*