Confession time. The phishing email is the easiest first slide in any OT tabletop to write, which is exactly why so many of them open with one. A clerk in accounts clicks a link, the security team spots an odd login, and by minute five the two operators you fought to get released from shift are reading their phones.
Nobody in that room did anything wrong. The scenario simply started somewhere they never work. An operator's incident does not begin in a mailbox. It begins when the plant does something it should not: a setpoint that moved on its own, a pump that ignores a stop command, a screen that stops updating. Open there and the operators sit up, because for once the first move belongs to them.
This is for whoever is writing the next tabletop at a site with a control room. If your draft opens in someone's inbox, the three cards below replace your first forty minutes. Print them, swap in your own tag names, and you can run them next month.
Red Trident, an OT security services firm, puts the payoff of an OT tabletop like this:
"They uncover weaknesses in communication between OT engineers, plant managers, and security teams, ensuring that everyone is aligned on roles, responsibilities, and escalation paths."
Read that as vendor guidance from a firm that sells assessments, not as research. Their example of the friction is sharp, though: a CISO who wants to patch now, and a plant manager who wants to wait so production keeps running. A phishing opener never gets that argument onto the table, because the plant manager has nothing to say about a mailbox. Red Trident does not tell you to start with the process. That part is our facilitation call, built on their point: if the gap you are hunting sits between three groups, open on something all three have a stake in.
The cards, ready to print
They are written for a fictional water treatment plant on an early shift: a board operator, a field operator with a radio, a shift supervisor. Hand each card over on paper at its time stamp. The facilitator never says the word cyber. Let the players say it first, and write down when they do.
None of these is far-fetched. At the utility Verizon called Kemuri Water Company, "unusual movements at valves and ducts" were what tipped the company off to call in outside experts. And in late 2023 attackers put a splash page on Unitronics HMIs at US water facilities that, in CISA's words, "prevented operators from reading anything the display screen would normally show, such as input and output readings." Card 3 is that morning, with a supervisor who has rehearsed it.
Quick check before you go further. Could your board operator find who changed a setpoint in the event log in under five minutes? If the honest answer is no, you have your first finding, and you have not reached Card 2.
When you want a full scenario to run after the first forty minutes, CISA's Tabletop Exercise Packages include an industrial control system compromise scenario, with template objectives, scenarios and discussion questions. Use theirs for the middle and these cards for the opening.
"You've cut out how they actually get in"
"I wrote the last tabletop. Phishing is how they get in. Skip it and you're rehearsing the ending without the beginning. And my team sits there for forty minutes with nothing to do."
Your IT security lead is right about the entry path. It belongs in the exercise. It just does not belong at minute zero for these players, because nobody in a control room hears about the phish first. They hear about the setpoint.
So turn the phish into a reveal. At the end of Card 2, the IT lead phones the supervisor: an engineer's credentials were stolen through a phishing email on Tuesday, and that login has been active on the plant network since 05:41. Now the IT finding lands at the exact moment it explains something the operators already saw. Watch whether anyone connects the stolen login to EWS-2. That connection is the thing you are testing.
As for the forty idle minutes, give the IT team their own track in another room, on the same exercise clock, with cards of their own: the odd login, the VPN session nobody expected. Card 3 then pulls both rooms onto one phone call, which is where the real argument starts.
"That's not a cyber drill, that's Tuesday"
"My operators see a setpoint wander three times a week. Show them Card 1 and they'll fix it, call it an instrument fault and go back to their coffee. That's not a cyber drill. That's Tuesday."
Exactly. That is why the card works.
The good response to Card 1 is the Tuesday response, plus one glance at the event log. You are not testing whether operators panic at an odd number. You are testing the moment ordinary explanations stop covering what they see. Instrument fault is a fine first answer and a terrible third one, so Card 2 is built for the ordinary fix to fail twice in a row.
Watch for the sentence "these two are connected". Note the exercise clock when somebody says it. That time is the number you bring back next year, and the year after, because it should shrink. If nobody says it before Card 3 lands, the gap is in what they were taught, not in the operators.
"Ninety minutes, and not my board operator"
"You get ninety minutes. And you're not having my board operator, the unit's running. Find somebody else."
Fine. Take the relief operator, or the board operator from the off shift, and budget the overtime. Here is the ninety minutes: forty for the three cards, twenty for the decisions they raise, thirty for the hot wash. The plant manager only needs to be on the phone for Card 3, about fifteen minutes of it.
Put it to the plant manager that way. Card 3 ends on a decision that is literally theirs: reboot, isolate or preserve, and in what order. They can practise it in a meeting room with coffee, or meet it for the first time at 06:30 on a real morning with two dark screens.
Start where the plant starts
Your operators are not bored by incident response. They are bored by somebody else's incident. Hand them the first move and they will carry the first forty minutes for you, and they will find the gaps your plan hides: the event log nobody checks, the manual switchover with no named owner, the five-minute argument about whether to reboot.
The phishing email still happens. It just arrives as an answer instead of a premise.
Sources: Red Trident, Stress-Testing OT Incident Response (vendor guidance, September 2026) | CISA, Tabletop Exercise Packages | CISA advisory AA23-335A | Water Online, reporting the Verizon 2016 Data Breach Digest on Kemuri Water Company


