What is a BEC Tabletop Exercise
A business email compromise tabletop exercise is a structured, discussion-based practice session where your team walks through a realistic BEC attack scenario and works out exactly what they would do before it happens for real.
No systems get shut down. No money actually moves. No emergency is created. The goal is to find out whether your team knows how to respond to a fake invoice, a vendor banking change request, or an urgent wire transfer demand before those things show up in someone’s actual inbox.
Most organizations find out they have gaps during a real incident. A business email compromise tabletop exercise is how you find them during a conference room conversation instead.
Why Business Email Compromise Tabletop Exercises Matter
According to the FBI Internet Crime Complaint Center, business email compromise caused over three billion dollars in losses in 2025. It was the highest-dollar cybercrime category for the third consecutive year. The organizations that lose money to BEC are not unsophisticated. They are busy, trust-based, and operating with informal payment processes that attackers know how to exploit.
The reason BEC works is not because organizations are careless. It is because nobody has ever walked through what happens when a payment request looks slightly wrong. A business email compromise tabletop exercise forces that conversation before someone is standing at a wire transfer screen trying to decide in real time.
What a Business Email Compromise Tabletop Exercise Actually Looks Like
A business email compromise tabletop exercise typically runs two to four hours. A facilitator presents a series of realistic injects, which are situation updates that escalate the scenario. Participants discuss what they would do at each decision point.
A typical business email compromise tabletop exercise might unfold like this:
The Setup
Your accounts payable person receives an email from a known vendor. The message explains that the vendor has changed banks and all future payments should go to a new account. The email looks legitimate. The vendor name is correct. The invoice number matches. Nothing stands out as obviously wrong.
The Pressure
An hour later, a second email arrives appearing to come from leadership. It references the vendor change and says the payment needs to go out today. The tone is professional. The request is urgent but not extreme.
The Decision Points
Now the facilitator pauses the scenario and the team has to discuss:
- Who has authority to approve a vendor banking change?
- How do we verify this is legitimate?
- What phone number do we use to call the vendor?
- What if the vendor confirms it but the email was actually from a compromised account?
- Who approves the payment?
- Who do we notify if something seems wrong?
- What if the payment already went out?
The discussion that follows those questions is where the value of a business email compromise tabletop exercise lives. Most teams discover they do not have clear answers. The business email compromise tabletop exercise gives them the opportunity to build those answers in a low-stakes environment.
What a Business Email Compromise Tabletop Exercise Should Include
A well-designed business email compromise tabletop exercise covers the full lifecycle of an attack, not just the initial recognition stage. That means the exercise should include injects covering:
- Initial suspicious email recognition
- Vendor banking change verification procedures
- Executive impersonation and urgency pressure
- Payment approval authority and escalation
- Decision to pause or proceed with payment
- Notification and internal escalation
- Bank contact and wire recall procedures if money moved
- Evidence preservation
- External communication, vendors, customers, insurers
- After action review and improvement
The exercise should also include a facilitator guide that walks whoever is running the session through each inject, discussion prompts, what good responses look like, and a hot wash structure for capturing findings at the end. Without that guide, the exercise is just a conversation. With it, the exercise produces documented gaps and an improvement plan.
Who Should Participate in a Business Email Compromise Tabletop Exercise
The right participants for a business email compromise tabletop exercise depend on your organization, but the core group should include the people who actually handle payments, approve vendors, communicate with leadership, and manage the bank relationship.
That typically means:
- Accounts payable and finance staff
- Finance director or CFO
- Office manager or operations lead
- IT contact or managed service provider
- Executive or owner
- Anyone else who approves payments or manages vendor relationships
You do not need your entire organization in the room. You need the people who would actually be making decisions during a real BEC incident.
Who Needs a Business Email Compromise Tabletop Exercise
Any organization that handles invoices, vendor payments, payroll, wire transfers, or purchasing should run a business email compromise tabletop exercise at least once a year. That includes:
- Small businesses with lean finance teams
- Healthcare organizations and medical practices
- Nonprofits with donor and grant payment processes
- Law firms and professional services firms
- Real estate companies and title agencies
- Construction companies with large vendor payment volumes
- Schools and municipalities
- Any organization where one person can approve and send a payment
What Happens After a Business Email Compromise Tabletop Exercise
The exercise itself is not the end product. What matters is what you do with what you find. A good business email compromise tabletop exercise produces a hot wash discussion immediately after the exercise ends, followed by a written after action report documenting what the team did well, where the gaps were, and what needs to change.
That after action report should translate directly into an improvement plan with specific corrective actions, assigned owners, and deadlines. The most common improvements that come out of a business email compromise tabletop exercise include:
- A written vendor banking change policy requiring independent verification
- A defined payment approval matrix by dollar amount
- A documented escalation path for suspicious requests
- A payment change checklist that finance staff keep at their desk
- Bank fraud contact information posted and accessible
- A wire recall procedure that everyone knows exists
Those improvements exist on paper after the exercise. The business email compromise tabletop exercise is what motivated the organization to actually create them.
How to Run a Business Email Compromise Tabletop Exercise
You do not need to be a cybersecurity expert to facilitate a business email compromise tabletop exercise. You need a realistic scenario, a clear inject sequence, good discussion prompts, and a structure for capturing what you learn.
A ready-to-run business email compromise tabletop exercise package gives you all of that. The facilitator guide walks you through each inject and provides discussion questions. The participant workbook gives your team the scenario materials and worksheets. The after action report template captures findings immediately after the hot wash. The improvement plan translates those findings into specific corrective actions.
Forward Security Labs builds practical readiness tools for organizations that need to prepare before something happens. Based in Wolcott, Connecticut. Founded by a U.S. Army combat veteran and paramedic supervisor with 20+ years in emergency healthcare. SDVOSB pending. SAM.gov registered. CAGE: 1AFL4.
