The key is in the scenario design and facilitation. Experienced facilitators (internal or external) develop a plausible storyline of a crisis that unfolds in phases, imitating the uncertainty and tempo of an actual incident. In CRE, this often means blending cyber and physical elements to mimic how a threat would play out in a smart building environment. For example, a tabletop scenario might start with an innocuous IT alert (“SOC analysts detect odd traffic from a building management server”). As participants investigate, the situation escalates: lobby entry systems malfunction, HVAC controls freeze on a hot day, and CCTV cameras go offline – classic signs that building OT systems have been compromised. Then a ransom note appears demanding payment or else sensitive building data will be leaked. By layering these events, the exercise forces teams to address both cybersecurity (stopping the attack) and operations (ensuring safety/comfort for tenants) in tandem, just as they would in an actual attack situation.
Scenarios are typically drawn from real-world threat intelligence and past incidents, tailored to the organization’s environment. A CRE company might run a scenario about a major city power outage combined with a network attack (to see how backup generators and cybersecurity teams coordinate), or a phishing-induced ransomware that spreads from HQ to property management offices. The details will use the company’s actual systems and terminology – e.g. referencing the specific access control software used, or the names of key vendors – to make the simulation as authentic as possible.
Participants often report that a well-crafted scenario feels “eerily real” in the moment, compelling them to engage fully. The facilitator will introduce new information (“Update: the hackers used a vendor’s VPN credentials to get in”) and observe how the team reacts. If the group is unsure what to do next, the facilitator might guide them with probing questions or additional clues, ensuring the exercise keeps moving forward while still letting the team drive decisions.
A hallmark of tabletop exercises is that they encourage creative problem-solving without the pressure of live consequences. Teams can discuss options openly: Do we pull the building offline immediately or wait? Who needs to be notified first – tenants, or just our internal chain? This surfaces a range of perspectives and often educates everyone involved. Facilities managers might learn about cyber forensics, and IT staff might learn protocols for on-site emergency response.
A well-crafted scenario will typically incorporate curveballs: perhaps a key decision-maker is “on vacation” (to test ownership and communication), or a minor secondary incident flares up (to stretch the team’s capacity). These twists add realism – in real life, crises often involve inconvenient timing and multiple issues at once.
Crucially, tabletop simulations are discussion-based – no actual systems are harmed. This means they can be conducted without risk to operations. It also means success isn’t measured in binary terms (like “did we block the attack?”) but rather qualitatively: Did the right people come together quickly? Was information shared effectively? What decisions were made and why?
The exercise typically ends with a debrief where the facilitator and participants review what happened and what could be improved. Because everything was simulated, participants can be candid about mistakes or uncertainties – a learning mindset rather than blame. The entire process gives a realistic sense of “what it’s like” to face a given crisis, building muscle memory for when a similar scenario arises in reality.
IRL Example: In one high-rise CRE company’s tabletop, the scenario involved hackers breaching an Internet-exposed building automation controller(a real risk the company had) and using it as a pivot into the corporate network. During the exercise, as the IT team scrambled to contain the digital attack, the facilitators also injected physical consequences: temperature spikes in buildings (simulated tenant complaints of heat) and false rumors on social media about a “data breach,” to test the communications team. This multifaceted approach required the group to consider technical fixes, tenant management, and public relations simultaneously – just as would be required if a smart-building breach occurred. Participants later commented that the scenario “really opened our eyes” to how a cyber incident would ripple into operational and reputational domains, underscoring the need for tight coordination between property management and IT security.
In summary, tabletop exercises employ realistic, tailored scenarios and skilled facilitation to recreate the pressures of a major disruption without the damage. By doing so, they allow CRE organizations to practice like they play – so when an incident does strike, it feels a bit like a scenario they’ve conquered before, rather than plunging them into completely uncharted chaos.




.webp)