Cyber Resilience  tabletop

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness

Table of Contents

“Nothing is certain except death, taxes, and cyber attacks.”

An insightful talk, presented by GRC Senior Consultant Shepherd Gonera, explores the evolving cybersecurity landscape and the strategies businesses need to adopt to stay ahead. Referencing Benjamin Franklin’s famous quote, “Nothing is certain except death and taxes,” Shepherd playfully adapts it to today’s digital reality: “Nothing is certain except death, taxes, and cyber attacks.” 

Watch the full presentation below or read on for the summary.

Current CyberSecurity Trends

The presentation opened with a snapshot of the current threat landscape, including these critical statistics:

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

Cyber attacks have surged by 40% in 2023, with supply chain breaches being the most significant contributor

Darryl Roberts 

64% of companies that experienced cyber attacks had never conducted a cyber tabletop exercise

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

In the Asia-Pacific region, the average cost of a cyber attack is estimated at $4.5 million

charles sturt university logo clients

20% of businesses targeted by cyber attacks over the last year shut down due to financial and reputational damage

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

Cyber attacks have surged by 40% in 2023, with supply chain breaches being the most significant contributor

Darryl Roberts 

64% of companies that experienced cyber attacks had never conducted a cyber tabletop exercise

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

In the Asia-Pacific region, the average cost of a cyber attack is estimated at $4.5 million

charles sturt university logo clients

20% of businesses targeted by cyber attacks over the last year shut down due to financial and reputational damage

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

Cyber attacks have surged by 40% in 2023, with supply chain breaches being the most significant contributor

Darryl Roberts 

64% of companies that experienced cyber attacks had never conducted a cyber tabletop exercise

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

In the Asia-Pacific region, the average cost of a cyber attack is estimated at $4.5 million

charles sturt university logo clients

20% of businesses targeted by cyber attacks over the last year shut down due to financial and reputational damage

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro
Darryl Roberts 
From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro
charles sturt university logo clients

Cyber attacks have surged by 40% in 2023, with supply chain breaches being the most significant contributor

64% of companies that experienced cyber attacks had never conducted a cyber tabletop exercise

In the Asia-Pacific region, the average cost of a cyber attack is estimated at $4.5 million

20% of businesses targeted by cyber attacks over the last year shut down due to financial and reputational damage

The Need for Preparedness

Shepherd underscored the limitations of traditional annual ransomware tabletop exercises. He noted that these static approaches fail to keep up with the evolving threat landscape, including AI-driven attacks and deepfakes. To counter this, organisations must involve all departments in cyber preparedness, as incidents often disrupt the entire organisation – not just IT.

#1 Conduct Frequent, Immersive and Evolving War Rooms

Shepherd proposed dynamic and regular training exercises to ensure playbooks stay relevant:

  1. Conduct quarterly tabletop exercises to maintain an up-to-date playbook
  2. Rotate focused war-room exercises tailored to specific departments or threats
  3. Immediately refine and adjust playbooks after each exercise based on findings

Remarking how many tabletop exercises tend to revolve around ransomware attacks, Shepherd pointed out that AI-related attacks, and attacks on third party partners and vendors in a supply chain are significant real-life threats, and should thus be included in scenario training.

#2 Foster a Culture of Automatic, Cross-department Cyber Resilience

Effective incident response relies on organisation-wide preparedness. Shepherd recommended cyber awareness training for all staff, from reception to executives:

  1. Include all departments and staff in incidence response training, even the receptionist
  2. Have smaller cybersecurity table top exercises across business units, such as Finance and HR – not just IT
  3. Ensure every department and team is aware of their critical role in incidence response

With relation to the third point, Shepherd gives examples of how successful resolutions of incidents could include pro-active collaboration between HR or even the call-centre, depending on the particular circumstance.

#3 Stay Ahead

Shepherd emphasised the importance of updating response strategies to reflect modern challenges:

  1. Incorporate AI-driven threats like deepfake, phishing and automated ransomware attacks
  2. Simulate third-party supply chain breaches and vendor compromises – for example, go through the formulation of a joint-incident response team
  3. Continuously evolve exercises to reflect emerging real-world cyber challenges

In addition, Shepherd also talked about the importance of involving the executive leadership, engaging them in board-level tabletop exercises, so they know their role in an incident.

From Practice to Performance: Building Cyber Resilience through Continuous Preparedness | Sekuro

Learn how Sekuro’s Strategy & Architecture team delivers clear, realistic, beneficial, and actionable strategies tailored to your organisation’s needs.

Shepherd Gonera, Senior Consultant, GRC
Shepherd Gonera

Senior Consultant, GRC, Sekuro

Sekuro's Latest Insights

Get in Touch

Discover the Smarter Way to Transform Your Organisational Security – Connect with Our Experts Today.

Complete the form and we will get in touch within 24 hours. 










    Alarming Cyber Threats in 2025 and How to Stay Secure?

    Download our expert paper on cyber security strategies to combat 2025’s evolving digital threats.

    Alarming Cyber Threats in 2025