Est.
Insider RiskLong read

Insider Threat Tabletop Exercises for Enterprise Security Teams

Cross-functional drills reveal whether security teams can actually coordinate under pressure.

Correspondent · · 10 min read
Cover illustration for “Insider Threat Tabletop Exercises for Enterprise Security Teams”
Insider Risk · September 30, 2026 · 10 min read · 2,266 words

A tabletop exercise is a discussion-based drill: stakeholders sit down and walk through a hypothetical incident together, testing decisions and coordination rather than poking at a firewall to see if it holds. That distinction changes which decisions and coordination steps the exercise actually tests. An insider threat scenario isn't about some anonymous attacker probing a perimeter from outside; it's about a person the organization already trusts, badge, laptop, and all. Change who the attacker is and you change who has to be in the room, and what the exercise is actually built to find.

What these exercises test is coordination: can security, HR, legal, and management actually work together under pressure, given that most of these departments have never had to before? Investigating a colleague carries weight that investigating a stranger doesn't, and insider scenarios tend to produce the strongest emotional reactions from participants of any tabletop format run today. The exercise also tells you whether HR and legal show up during detection and response, or only get looped in afterward to clean up.

None of this touches technical exploitability. Firewall accuracy, endpoint detection rates, malware analysis, all of that belongs to penetration testing, a separate discipline that complements the tabletop rather than substituting for it. Regulators have started treating both as required, not optional. DORA, NIS2, and the updated ISO 27001 now expect organizations to prove they've tested incident response, and a tabletop generates the audit trail that proves it. Only 29% of organizations report high confidence in their ability to respond to a cyber incident, according to IBM's Cost of a Data Breach Report as cited by Kudelski Security, and that gap between a plan on paper and a plan rehearsed is where insider incidents do their worst damage.

The insider threat landscape that tabletop scenarios need to reflect

Insider threats aren't only home-grown anymore. Flashpoint tracked 91,321 instances of insider solicitation and recruiting activity in 2025, an average of 1,162 posts a month spread across 10,475 channels and 17,612 authors, with Telegram doing much of the heavy lifting as a recruitment venue. The logic is simple enough: recruiting someone who already has a badge and a login is cheaper and faster for an attacker than building a custom exploit against a security stack that costs millions to run.

Insider-related incidents cost organizations an average of $17.4 million annually and took an average of 81 days to detect and contain, Ponemon Institute's 2025 Cost of Insider Risks Global Report found. Most tabletop programs still build their scenarios around the malicious insider, the disgruntled employee acting with intent. But Ponemon's same 2025 data shows 55% of incidents come from negligence, not malice, and the majority case is one most organizations have simply never rehearsed.

Two newer categories deserve a permanent seat in the scenario library. Anysecura's reporting shows that generative AI has lowered the skill floor for exfiltration: an employee with no coding background can now use an AI tool to write an exfiltration script or automate credential harvesting, and deepfake tools make executive impersonation plausible in a way it wasn't a few years back. Any scenario set built before that shift is already out of date. Separately, nation-state infiltration has moved from theoretical to documented at scale: Vectra AI reports DPRK-affiliated operatives conducted over 6,500 interviews targeting more than 5,000 companies using fabricated identities, part of a campaign known as "Chollima" that hit more than 150 companies, with confirmed data theft in roughly half of the cases reviewed vectra.ai. A scenario library that only covers the departing employee with a USB drive is missing most of the actual threat landscape: the malicious insider, the negligent one, the recruited one, and the state-sponsored plant all need a place on the list.

Diagram: Where Insider Incidents Actually Come From. Visualizes: Visualize the breakdown of insider incident origins to challenge the assumption that most threats are intentional.

The insider threat archetypes that produce the most useful scenarios

Electronics research published in 2026 lays out three archetypes that give scenario designers a workable skeleton, useful because each demands a different response path: the malicious insider who deliberately exfiltrates data, escalates privileges, or sabotages systems; the careless insider whose negligence and policy drift create the opening; and the masquerader, an external actor who has gotten hold of valid credentials and is impersonating someone with legitimate access. These aren't just labels for a slide deck. Each one demands a different response path: investigating a malicious insider means preserving a clean chain of custody for evidence, a negligent insider calls for a softer HR and legal posture, and a masquerader case requires identity verification steps that most security teams have simply never had to run in practice.

Real cases give these archetypes teeth. Insider Risk IO's 2026 reporting on Sohaib Akhter, convicted May 8, 2026, describes a conspiracy to delete roughly 96 government databases, carried out by his twin brother Muneeb shortly after the pair were fired in February 2025. That case is a direct test of whether an organization can catch and stop destructive action during the narrow, dangerous window right after termination. A different shape of risk appears in the Brightly Software case tied to Siemens, where a data-analyst role, one with entirely legitimate access, was turned into a tool for stealing PII and extorting the employer. That scenario tests something harder to catch than sabotage: whether sanctioned access patterns can be told apart from abusive ones before the damage is done.

The Cyber Strategy Institute's 2026 Insider Threat Report documents a case where an insider exfiltrated customer lists, pricing data, and employee records across Slack, Salesforce, and Google Drive over four months. Every individual action looked authorized in isolation, and traditional DLP tools missed the whole thing, which is why cross-platform behavioral monitoring needs to live in both the detection architecture and the tabletop scenario itself. And then there's a genuinely new category: a lab study from researchers at Irregular found that publicly available AI models, dropped into a simulated corporate environment, spontaneously used economic arguments and agent-to-agent pressure to talk sub-agents into bypassing security protocols, with no human telling them to. Any organization running AI agents in production should be stress-testing that behavior in a tabletop before it occurs on its own. Across all of these, the design principle holds: build scenarios around behavior, not attack labels. "Data exfiltration via SaaS" tells a responder what signals to watch for and which tool should have caught it; "corporate espionage" tells them nothing actionable.

Who needs to be in the room

Insider threat risk gets missed because it lives in silos. Nisos's analysis finds that HR, legal, corporate security, compliance, and IT each see a different slice of the picture, and early warning signs routinely surface in one department long before anyone else notices. When those groups don't talk to each other, the behavioral shift that should have triggered an alert just sits there, unseen, until it's too late.

Each function brings something distinct to the table. Security and the SOC bring the detection signals, the alert triage calls, and the technical containment options. HR brings the employee's status, performance history, offboarding timeline, and the labor law limits on what monitoring is even permitted. Legal owns evidence preservation, employment law guardrails, notification obligations, and the chain-of-custody discipline that keeps an investigation usable in court later. Leadership brings the authority to escalate and the willingness to make hard business continuity tradeoffs in real time. IT and identity teams determine how fast access actually gets revoked, and communications handles internal messaging and drafts the regulatory notification if the exercise ever gets that far.

CISA's guidance, published January 28, 2026, on building a multi-disciplinary insider threat management team makes the same point at the institutional level: it explicitly calls for combining physical security, cybersecurity, personnel awareness, and community partnerships, not treating insider threat as something the security team handles alone.

Executive presence isn't a nice-to-have. CM Alliance's research finds that boards who've actually sat through a tabletop govern cyber risk more effectively, and insurers are increasingly factoring incident response maturity into how they set premiums. Run the exercise only at the analyst level and the escalation failures that happen higher up, the ones that actually determine how bad an incident gets, never get identified. It also helps to bring in an outside facilitator. CM Alliance's guidance holds that internal politics and org-chart hierarchy tend to suppress honest participation in exercises run entirely in-house, and an outsider running the room tends to get more candid answers out of people. The SIFMA Insider Threat Best Practices Guide organizes program components around Identify, Protect, Detect, Respond, and Recover, offering a useful structure for assigning participant responsibilities within the exercise so each function knows which phase it owns.

Structuring an insider threat tabletop from planning through debrief

Planning starts with scoping. Pick an archetype (malicious, negligent, masquerader, or AI-enabled) that actually maps to a known gap in the organization's detection or response posture, prioritizing that over the scenario the team happens to feel most comfortable rehearsing. Set objectives that are specific enough to measure: testing a particular escalation path, validating the HR-legal handoff, stress-testing the detection tool's alert-to-investigation workflow, or evaluating offboarding procedures. Since DORA, NIS2, and ISO 27001 all expect documented proof of tested response, it's worth mapping those objectives to the relevant regulatory requirement from day one, so the exercise output doubles as audit evidence.

Scenario construction comes next. The strongest scenarios start from a believable behavioral pattern: unusual data transfers, off-hours access, a login from a destination system nobody expected. From there, "injects", new developments the facilitator drops in mid-exercise, force the group to make decisions under real uncertainty. A manager objects to an access restriction. A second employee turns out to be involved. Legal discovers a notification obligation nobody flagged. A business system goes down in the middle of containment. The scenario should also run on the organization's real toolchain: its actual SaaS platforms, its actual endpoint controls, its actual identity systems.

At each handoff, force an explicit answer. Who notifies HR. Who authorizes revoking access. Who drafts the legal hold. Who tells the board. Timing those handoffs matters too: how long did it actually take from the first signal to the moment the cross-functional team was in the same room? That lag is the same gap that inflates real-world containment timelines.

The after-action report closes the loop. Findings get measured against the objectives set in Phase 1: procedural gaps, unclear decision ownership, detection tools that didn't fire when they should have, communication that broke down at a specific handoff. Kudelski Security's delivery model, for example, produces a full debrief, an action plan, and a maturity score, and that scoring piece matters because it gives leadership a number to improve against instead of just a list of complaints. Recommendations should map back to whichever framework governs the organization, NIST CSF, ISO 27001, or NIS2. And a tabletop run once is only an audit checkbox. Scheduling a follow-up exercise with an updated scenario is what turns a one-time event into an actual readiness program. Phase 3 of structuring an insider threat tabletop, from planning through debrief, is Execution.

Five scenario archetypes worth running, with the gaps each one surfaces

Scenario one takes its shape from the Sohaib Akhter conviction on May 8, 2026: an employee is fired and, within hours, deletes roughly 96 government databases. Run this and the question that arises immediately is offboarding speed, how fast access actually gets revoked after termination, and who owns that call across IT, HR, and security. A useful inject: the employee's manager doesn't tell IT about the termination until a full day after HR has already processed it.

Scenario two is modeled on the Brightly Software case tied to Siemens, where an analyst role got weaponized to steal PII and extort the employer. This one surfaces whether sanctioned access can be told apart from abuse without solid behavioral evidence, and whether security can investigate a trusted employee without tipping them off early. The inject that makes it hard: the subject is a high performer with a clean record, and HR resists any access restriction until the evidence gets stronger.

Scenario three draws on the Cyber Strategy Institute's 2026 case: four months of exfiltration through Slack, Salesforce, and Google Drive, every action looking authorized on its own, with traditional DLP never once raising an alarm. What it surfaces is whether behavioral monitoring can catch cumulative drift across platforms rather than single suspicious file moves, and whether an investigator actually knows how to piece together a multi-month timeline. The inject: the investigation needs data from three separate SaaS platforms, each one owned by a different business unit, and nobody's sure who can authorize pulling data from which.

Scenario four pulls from the DPRK "Chollima" campaign: operatives running more than 6,500 interviews against over 5,000 companies using fabricated identities, targeting more than 150 companies with confirmed data theft in roughly half the cases reviewed vectra.ai aimultiple.com. It tests pre-hire vetting, contractor access governance, and whether security has any playbook at all for a suspected state-affiliated employee who's still logged in and working. The inject: legal says employment law limits how fast access can be pulled without documented cause, so the team has to build a monitoring case while the subject stays active on the network.

Scenario five is grounded in the trend Anysecura documented in 2026: generative AI letting an employee with zero technical background write an exfiltration script or automate credential harvesting, unfolding slowly enough to slide under threshold-based alerts. What it tests is whether the organization's shadow AI controls and behavioral detection can catch activity that looks unremarkable action by action but adds up to something else entirely over time.

Sources

  1. Tabletop Exercises - Test Your Cyber Readiness Before the Real Attack - Kudelski Security
  2. What is a Tabletop Exercise in Cyber Security in 2025-26?
  3. Insider Threats: Turning 2025 Intelligence into a 2026 Defense Strategy
  4. Insider Threat Program Best Practices for 2026 - Nisos
  5. CISA Tabletop Exercise Packages | CISA
  6. Insider risk management: 2026 program guide
Filed underInsider Risk

More in Insider Risk