Guides

How to run an insider threat tabletop exercise for a departing employee

Law & Forensics Editorial
Editorial illustration for the article "How to run an insider threat tabletop exercise for a departing employee".

The departing employee is one of the most predictable and least rehearsed threats an organization faces. When a trusted person with legitimate access gives notice, the window between resignation and offboarding becomes a period of concentrated risk to sensitive data. An insider threat tabletop exercise built around this exact moment tests something no technical control can measure on its own: whether human resources, legal, and security can move together, quickly, and without stepping on one another. This is where a malicious insider incident response plan either proves itself or reveals its gaps.

A tabletop exercise is a discussion-based activity where key stakeholders come together to simulate a real-world incident in a low-stress environment. As Bitsight describes it, no actual systems are impacted. Participants talk through their roles, actions, and decisions to understand how the organization's incident response plan would play out. For an insider threat, the scenario-based format is a good fit because the hardest questions are procedural and legal rather than purely technical. Who decides to revoke access. When does legal get involved. What can be monitored and preserved without overstepping. These are the questions the exercise forces into the open.

Why the departing employee scenario matters

Insider threats are a documented and growing concern. PreparedEx cites the 2022 Insider Threat Report by DTEX Systems Group, which found a 72 percent increase in actual insider threat incidents. The departing employee variant is especially instructive because it combines a person in a position of trust with a clear motive and a defined timeline.

Threat Intelligence frames the core insider scenario around exactly this profile. In its example, a DevOps engineer responsible for managing software on cloud infrastructure, holding a position of trust and motivated by personal gain, decides to leak sensitive company information by using their extensive access privileges. GTIA offers a related and more severe variant in which a ransomware attack is initiated by a disgruntled insider, highlighting how employee dissatisfaction, if unaddressed, can be exploited by external threat actors with catastrophic consequences. The lesson across both is the same. Access plus motive plus opportunity is the combination the exercise should stress.

A tabletop exercise built on this profile serves several purposes at once. According to PreparedEx, these exercises help identify vulnerabilities, improve response time, and strengthen policies and procedures. They also enhance collaboration by encouraging communication and ensuring everyone is working from the same understanding when an insider incident unfolds.

Set objectives before you build the scenario

Clear objectives come first. PreparedEx advises that objectives should align with the organization's risk profile and overall security strategy, and that scenarios should be relevant to the organization's specific risks. Vague goals produce vague discussion. Concrete goals produce action items.

For a departing employee exercise, useful objectives include the following.

  • Confirm that the trigger for a coordinated review exists the moment an employee with privileged access gives notice.
  • Test how quickly access can be adjusted or revoked, and who has authority to order it.
  • Establish how evidence of exfiltration is detected, preserved, and documented.
  • Clarify the point at which legal and human resources must be brought in.
  • Verify that communication between departments follows a defined chain rather than ad hoc messaging.

Threat Intelligence stresses that a tabletop exercise is not designed to evaluate the efficiency of security controls. That is the job of an attack simulation or penetration test. What it tests is whether stakeholders are prepared to respond. Do they know what to do. Do they know who to call. Is there a communication chain in place. Keeping objectives focused on coordination rather than technical proof keeps the exercise honest.

Bring the right people to the table

The value of this scenario depends entirely on who participates. Because a departing employee case sits at the intersection of employment, law, and technology, no single department can resolve it alone. PreparedEx is explicit that all relevant stakeholders, including IT, human resources, and legal, should be involved to create a coordinated approach and cross-departmental collaboration.

Bitsight expands the roster of roles typically present in a tabletop exercise:

  • A facilitator or moderator who runs the exercise, guides the scenario, and keeps participants engaged.
  • The incident response team, meaning the technical personnel who manage the direct response.
  • Business leaders and decision-makers who approve actions and manage risk.
  • Legal and compliance representatives who assess regulatory implications and guide legal matters.
  • Public relations and communications staff who manage external messaging and public perception.
  • Observers, sometimes an external consultant or internal audit team, who provide feedback.

Bitsight specifically notes that human resources belongs at the table in cases where internal threats or employee data are involved. That is precisely the situation here. Human resources holds the resignation timeline, the employment agreements, and the conduct history. Legal owns questions of monitoring, preservation, and downstream exposure. Security owns detection and containment. The exercise is where these three learn to hand off to one another under time pressure.

GTIA adds a practical touch worth borrowing. In its ChannelCon sessions, each participant was given a persona describing their role along with a few personal biases and feelings. That realism matters for an insider case, where personalities, loyalties, and assumptions about a colleague shape how people react. As one GTIA facilitator put it, everybody has a plan until they get punched in the face, and the point of training is to absorb that first punch in a room instead of in a real crisis.

Structure and run the scenario

Threat Intelligence recommends that before designing an exercise, the security team have a clear understanding of the enterprise security architecture and associated business processes. Facilitators gather information on critical assets, existing security controls and policies, and levels of access. This high-level overview becomes the foundation for a believable scenario and gives participants the context they need.

Build the departing employee scenario as a sequence of injects that escalate. A workable arc looks like this.

The opening inject establishes the resignation. A senior engineer with broad access to cloud infrastructure and sensitive data submits notice, citing a new role at a competitor. The facilitator asks the group what, if anything, changes about this person's access and monitoring status.

A second inject introduces a signal. Security detects unusual data movement, perhaps large downloads or transfers to personal storage, consistent with the exfiltration behavior Threat Intelligence describes for a trusted insider using legitimate privileges. Now the group must decide how to confirm, preserve, and act without tipping off the individual prematurely.

A third inject forces the legal and human resources handoff. The group must weigh what monitoring is permissible, how to preserve evidence properly, and when to move from observation to intervention. This is the coordination test at the heart of the exercise.

A final inject addresses containment and aftermath. Access is revoked, the departure is managed, and the group considers notification obligations and communications. Bitsight notes that exercises walk through detection, containment, mitigation, and recovery, and each of those phases should appear across the injects.

Bitsight puts the typical duration at one to four hours depending on complexity. A multi-phase insider scenario with three departments in the room will sit toward the longer end. Throughout, PreparedEx advises fostering open communication so participants feel comfortable sharing ideas, which produces more useful discussion and better outcomes.

Capture outcomes and close the loop

The exercise only pays off if it ends in documented change. Bitsight describes the expected outcomes as a detailed assessment of preparedness: identified gaps, actionable recommendations such as updated policies or improved communication strategies, better coordination and clearer role definitions, and a formal report of lessons learned.

PreparedEx reinforces the follow-through. Track the progress of identified action items and implement necessary changes, because that is what realizes the full benefit of the exercise. Evaluate the effectiveness of policies and procedures afterward, and use the feedback to adapt the insider threat management strategy. PreparedEx recommends conducting these exercises at least once a year, or more often depending on the organization's risk profile, so that offboarding practices and coordination habits stay current as roles and access change.

Run consistently and documented rigorously, a departing employee tabletop exercise converts an abstract fear into a rehearsed sequence. Human resources, legal, and security stop meeting each other for the first time during a live incident. They meet at the table, learn the handoffs, and fix the gaps while the stakes are still hypothetical.

Written by

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.