This is the sixth, and closing, post in this series addressing my perspective on the current state of Cybersecurity Incident Response (IR) and an approach to improve interest, participation, and expanded learning.
Part I: A Strategic Guide to Cybersecurity Table-Top Exercises
Part II: Rolling for Resilience
Part III: Battle Prep - The Scrolls of Response
Part IV: Boots in the Field - Manuals for Real-Time Action
Part V: Side Quests - Not Every Member of the Party Swings a Sword
Part VI: Loot Drops & Learning Points: Measuring What Matters
A successful table-top exercise is not merely due to the teams participating, having fun, or completing the scenario. Success needs to include the organization identifying what was learned, what needs to change, and what risks or gaps should be carried into improvement planning.
This is a moment at the end of every adventure when the party pauses.
The final encounter has ended. The noise of the battlefield begins to fade. The immediate danger has passed, at least for now. The adventurers gather themselves, take inventory, compare notes, and begin to understand what the journey actually revealed. They may count the gold, inspect the mythic unique items recovered, review the wounds taken (frost nova does leave a mark), and decide which lessons will shape the next campaign.
A table-top exercise should end the same way.
The conclusion of the scenario is not the end of the exercise. It is the beginning of the most important work. The value of a table-top is not found only in the scenario, the injects, the roleplay, or the decisions made under pressure. Those elements matter, yet they are the encounter itself. The lasting value comes from what the organization chooses to learn from the experience.
This is where the loot drops appear.
Not treasure in the traditional sense, yet better, organizational insight. The table-top reveals where teams communicated well, where decisions slowed, where assumptions were flawed, where participants had to improvise due to lack of or unclear guidance. It shows whether leadership had the information needed to make timely decisions. It shows whether the technical teams understood when to escalate. It shows whether legal, communications, human resources, third-parties, and business leaders were aligned before the incident pressure became real.
These are the learning points that matter.
A table-top exercise should not be measured by whether the party "won." It should be measured by what the party discovered.
The Wrong Treasure
It is tempting to measure a table-top exercise by simple outputs. Attendance was high. The scenario was completed. The participants were engaged. The exercise stayed on schedule. The after-action meeting produced a list of notes. Everyone agreed it was useful.

Participation does not prove readiness. Engagement does not prove capability. Completing the scenario does not prove the organization can respond effectively to a real incident. Even a smooth exercise can hide unresolved gaps if the measurement is focused only on whether the event felt successful.
A table-top is not a performance review. It is not a pass/fail test. It is not designed to embarrass the party or declare a single winner. The objective is not to prove that every player knows exactly what to do. Yet, to reveal how the organization thinks, communicates, escalates, and adapts when the path forward is uncertain.
The wrong treasure is a clean scorecard that makes everyone feel comfortable.
The right treasure is clarity...

Clarity may also come from friction. Yes, this needs to be considered a positive interaction... A team may not know who owns a decision. A policy may exist but not provide enough practical guidance. A third-party notification process may be understood by one department but not another. The Help Desk may follow a procedure that conflicts with what incident responders expect. Leadership may request a status update that the technical team is not prepared to provide. Communications may need language before Legal has enough confirmed facts to approve it.
These discoveries are not failures of the exercise. They are the reason the exercise exists.
Measuring the Campaign, Not Just the Encounter
A single encounter can show how the party reacts in the moment. A campaign shows whether the party is becoming stronger over time.
The distinction matters when measuring table-top exercises. Each exercise should produce observations, but the larger objective is to understand whether the organization is improving across repeated scenarios. The value grows when lessons are captured, assigned, implemented in procedure and process, and used to shape future exercises. The measurement asks better questions.

Did the right people receive the right information at the right time? Were participants clear on their responsibilities? Did teams know when to escalate? Were decision-makers able to act with incomplete information? Did the available playbooks support the actual choices that needed to be made? Were regulatory, legal, contractual, and customer obligations understood before they became urgent? Did the exercise reveal assumptions that should be tested again?
These questions move the organization from event execution to program improvement.
The table-top itself becomes part of the Security program, which it should be from the start. It becomes a way to validate readiness, strengthen relationships, test assumptions, and identify risk before a real incident forces the organization to learn under pressure.
That is the difference between running a game and building a campaign.
What Should Be Measured
The most useful table-top metrics are not always the easiest to count. Some can be tracked directly, such as how long it took to escalate a decision or whether required stakeholders were involved. Others require observation and discussion, such as whether teams were comfortable challenging assumptions.
The objective is not to create a complicated scoring model. Yet it is to capture meaningful evidence of readiness.
A useful table-top review should consider decision quality. Did the party make decisions based on available information, or did they wait for certainty that would not exist during a real incident? Did leaders understand which decisions were technical, which were business-driven, and which required cross-functional input?
It should consider communication flow. Did information move between teams clearly and quickly? Did participants know who needed to be informed? Were updates provided in a way all participants could understand? Were technical details translated to business impact?
It should consider escalation timing. Did the right issues reach the right people soon enough? Did teams hesitate due to lack of clarity of authority? Did leadership become involved too late, too early, or at the right point in the scenario?
It should consider role clarity. Did each participant understand their responsibilities? Were there empty chairs at the table where an important function, vendor, or decision-maker should have been represented?
It should consider usefulness of existing guidance. Did playbooks, policies, procedures, and field manuals help the party act? Were they too broad, too technical, too legalistic, or too disconnected from how teams actually work during an incident?
It should consider leadership involvement. Did executives receive enough context to make informed decisions? Did they understand the impact of their choices? Did they help remove obstacles or become them? Did the scenario reveal that leadership expectations and operational reality were not aligned?
It should also consider unresolved risk. Not every issue uncovered during a table-top can be fixed immediately. Some observations may become action items. Others may be accepted risks, future projects, training needs, or topics for the next exercise. What matters is that they are not lost when the session ends.

Capturing the Loot
Every table-top produces loot, but not every organization collects it well.
Some of the most valuable findings appear in the middle of conversation. A participant says, "I am not sure who would approve that." Another says, "We would need to check with Legal." Someone else says, "I do not think our vendor contract explains that." A technical lead says, "We can detect that, but we do not have a standard process for reporting it." A communications lead asks, "Who confirms what we are allowed to say externally?"
These moments are easy to miss if the exercise is focused only on moving to the next inject.
They should be captured as loot drops.
A loot drop may be a missing decision point. It may be unclear ownership. It may be a dependency on one person, one team, one vendor, or one undocumented process. It may be a gap between policy and practice. It may be an assumption that was treated as fact until the scenario exposed it.
The facilitator, scribe, and observers should be listening for these moments. They are often more important than the formal answers participants provide. They show how the organization actually thinks and where the next improvement should begin.
The after-action process should preserve these observations in a way that can be used. Notes should not disappear into a shared folder and become another forgotten artifact. Lessons learned should become assigned actions, risk entries, updated playbooks, revised communication templates, training needs, or future injects. The treasure must be carried out of the dungeon and used.

From Lessons Learned to Actions Taken
A table-top exercise loses value when lessons learned do not become actions taken.
The after-action process does not need to be overly complex, but it does need ownership. Each meaningful observation should have a next step. Some will require a policy update. Some will require a playbook change. Some will require leadership discussion. Some will require additional training. Some will need to be added to the risk register. Some may become future table-top injects designed to test whether the organization improved.
This is where many exercises fall short.
The room agrees that something should be fixed. The point is captured in the notes. The meeting ends. Everyone returns to normal work. Weeks later, the same gap remains. Months later, a similar scenario is run, and the same discussion happens again.
That is not a learning loop. That is a repeated encounter with the same monster.
A stronger process asks who owns the action, what needs to change, how progress will be tracked, and when the issue should be retested. Not every action must be solved immediately, but every meaningful issue should have a destination.
Some actions may be tactical. Update the incident notification list. Add a missing vendor contact. Clarify who can approve customer notification language. Create a leadership briefing template. Document how to request emergency access. Confirm who owns regulator notification decisions.
Other actions may be strategic. Improve cross-functional incident governance. Reassess contractual obligations. Align the table-top program with enterprise risk management. Build department-specific playbooks. Expand future exercises to include suppliers, business leaders, or regional teams. Both tactical and strategic actions matter. The small fixes remove friction. The larger improvements strengthen the campaign.
The Party Does Not Need Perfect Answers
One of the most important lessons from a table-top exercise is that the party does not need perfect answers to learn.
In fact, waiting for perfect answers can weaken the exercise. Real incidents rarely provide complete information at the right time. Teams make decisions with partial facts, changing conditions, and competing priorities. A good table-top should reflect that reality.
The measure is not whether participants knew everything. The measure is whether they knew how to proceed responsibly when they did not.
Did they ask the right questions? Did they identify what was known, unknown, and assumed? Did they separate technical uncertainty from business impact? Did they escalate when the decision exceeded their authority? Did they communicate uncertainty without creating unnecessary alarm? Did they document assumptions so they could be revisited later?
These behaviors matter because they are closer to real incident response than scripted perfection.
A party that can recognize uncertainty, communicate clearly, and adapt together is stronger than a party that only performs well when every clue is obvious.
Measuring Trust and Psychological Safety
The earlier parts of this series discussed engagement, buy-in, and psychological safety because they are not soft extras. They directly affect what the exercise reveals.
Participants are more likely to surface real problems when they trust that the exercise is not designed to punish them. They are more likely to admit confusion when the room treats uncertainty as useful information. They are more likely to challenge assumptions when leadership allows the discussion to be honest. That trust should also be measured, even if informally.
Did participants speak openly? Did junior team members contribute? Did non-technical stakeholders feel included? Did leadership listen without taking over the exercise? Did the facilitator create space for disagreement? Did the group treat gaps as improvement opportunities instead of personal failures?

If the answer is yes, the exercise likely produced better information.
If the answer is no, the organization may have measured the scenario without measuring the environment in which the scenario was played.
A table-top that silences the party will miss the most important loot.
Keeping the Scorecard Human
Metrics are useful, but they should not strip the humanity out of the exercise.
A table-top brings people into a room to think through difficult situations before they become real. The people in that room carry different responsibilities, pressures, experiences, and levels of confidence. A technical responder may be focused on containment. Legal may be focused on notification obligations. Communications may be focused on public statements. Human Resources may be focused on employee impact. Leadership may be focused on business continuity, customer trust, financial exposure, and board-level accountability.
The measurement approach should respect that complexity.
A simple red, yellow, and green rating may be useful, but it should not become the whole story. A finding labeled yellow may represent a serious decision-making gap. A green area may still have opportunities for improvement. A red issue may be less about failure and more about discovering that the organization had never tested a particular assumption before.
The scorecard should support the story, not replace it.
The best after-action reports explain what happened, why it mattered, what was learned, and what should happen next. They give leadership enough clarity to support change. They give teams enough specificity to improve. They preserve the voice of the exercise without turning people into numbers.
The Final Reward
At the end of a campaign, the party should be different than when it began.
They should understand each other better. They should know where they are strong. They should know where they need better equipment, clearer maps, stronger alliances, or more practice before the next encounter. They should have a better sense of what dangers remain and what choices must be made before the next adventure begins.
That is the real reward of a table-top exercise.
Not the completed agenda. Not the slide deck. Not the fact that the scenario reached its final inject. Those are artifacts of the session. The reward is the organizational clarity that comes from honest practice.
A well-designed table-top gives the party a safe place to discover what would otherwise be learned during an actual incident. It creates room for communication, leadership alignment, role-specific decision-making, and cross-functional learning. It reveals where the organization is prepared and where preparation still needs work.
The campaign does not end when the scenario concludes. It ends when the party reviews what was gained, what was missed, what needs repair, and what must be carried into the next adventure.

Closing the Campaign
Rolling for Resilience began with a simple idea: table-top exercises are more effective when they are designed as meaningful, immersive, and inclusive experiences rather than procedural obligations.
Across the series, we explored how to create engagement, support psychological safety, shape communication paths, involve leadership, prepare field-ready guidance, and build role-specific journeys through side quests and branching scenarios. Each part focused on a different layer of the same larger goal: helping organizations practice before pressure turns theory into consequence.
This final part brings that campaign to its natural close.
A table-top exercise should leave the organization with more than memories of a good discussion. It should leave behind evidence of readiness, a clearer view of risk, stronger relationships, updated guidance, and a practical path toward improvement. The best exercises do not end with applause. They end with action.
And when the next encounter begins, the party should not be starting from the same place.
They should be better equipped, better aligned, and better prepared to face whatever waits beyond the next unopened door.
Ready to roll for resilience?
Our team designs and facilitates custom table-top exercises built around your environment, your risks, and your people. If you want to move beyond checkbox compliance and into real incident readiness, let's build your next campaign together.
Contact UsDo you want to learn more about how Secure Ideas can team up with you on your next Table-Top campaign? Feel free to email me at Giovanni.Cofre@SecureIdeas.com.
About The Author:
Giovanni Cofré has joined Secure Ideas with 25+ years of IT experience, specializing in network security for corporate, OT, and e-commerce environments since 2000. He is committed to mentoring security professionals and promoting security awareness. His experience spans multiple industries in both private and public sectors, where he has implemented security frameworks based on CIS CSC, HITRUST, PCI, GDPR, and NIST standards. Giovanni is skilled in vulnerability assessment, penetration testing, and developing practical security processes. His notable work in e-commerce and energy industries includes establishing secure coding practices and maturing enterprise security strategies. Giovanni focuses on environment-specific practices that meet business needs while building resilient infrastructures.
Read More by Giovanni: Operational Technology's Use of Wireless Networks