Xcelus Blog — Compliance Leadership
Cybersecurity Runs Tabletop Exercises. Why Doesn’t Compliance?
By the Xcelus Editorial Team
Editor’s Note
The opening scenario below is the basis for one of our Executive Decision Lab™ kits, The Invisible Insider — a 90-minute facilitated session designed for public company leadership teams who want to practice these conversations before an incident forces them.
Imagine your organization discovers that a vendor employee accessed confidential FDA approval information and shared it with a family member who purchased stock before the public announcement.
The information was material.
The trading activity has already occurred.
The media is calling.
Outside counsel is asking questions.
The board wants answers.
Would your leadership team know what to do next?
Most organizations spend significant time preparing for cybersecurity incidents. They conduct tabletop exercises, incident simulations, and response drills. Teams gather in a room, review realistic scenarios, discuss response options, identify weaknesses, and improve coordination before a real crisis occurs.
The logic is simple: people perform better under pressure when they have practiced beforehand.
Yet many compliance programs take a very different approach. Employees complete annual training. Managers review policies. Leaders receive updates from Compliance and Legal. But few organizations ever sit down and ask:
“What would we actually do if this happened here?”
“Our people would never do this.”
It’s the first thing most leaders think when reading a scenario like this — and it’s usually true. In a calm, fully informed room, no one makes the wrong call. But that’s not where these decisions get made. They get made under deadline pressure, inside a relationship, with incomplete information, on a bad day. This Executive Decision Lab doesn’t test whether your team knows the right answer. It surfaces whether the conditions that make the wrong answer feel reasonable are already present here, before an incident proves they are.
Knowing the Policy Isn’t the Same as Making the Decision
Compliance training plays an important role. Employees need to understand company policies, legal requirements, and reporting expectations.
However, real-world compliance failures rarely begin because someone forgot a policy definition. They occur when people face difficult decisions under pressure.
A manager is trying to meet a quarterly target. An employee discovers a potential conflict of interest involving a high-performing executive. A vendor gains access to sensitive information. A team uploads confidential data to a public AI platform to meet a deadline.
The challenge is not remembering a policy. The challenge is making the right decision when competing priorities, uncertainty, and business pressures are involved.
Cybersecurity leaders recognized this years ago. That is why they practice incidents. Compliance leaders should consider doing the same.
Cybersecurity’s “Practice Before It Happens” Mindset
When organizations conduct a ransomware tabletop exercise, they are not testing whether employees can define ransomware. They are testing:
Who owns the response?
How quickly can leadership make decisions?
What information is available?
Which controls work?
Which assumptions prove false?
What gaps exist?
The exercise often reveals issues that would never appear in a policy review or training course. The same principle applies to compliance risks.
A realistic scenario can quickly uncover questions such as:
Who owns third-party risk?
What would trigger board notification?
How would leadership learn about the issue?
Are escalation processes clear?
Do contracts address the risk?
Are reporting obligations understood?
These discussions often expose governance gaps long before regulators, auditors, or investigators discover them.
Five Compliance Risks Worth Practicing
Many organizations already have policies covering these risks. The question is whether leadership teams have ever discussed how they would respond if one occurred tomorrow.
Risk 01
Third-Party Risk
A vendor employee gains access to material non-public information and shares it with a family member.
Who is responsible? What contractual obligations apply? How would the organization respond?
Related: The Invisible Insider Decision Lab · Vendor MNPI training scenario
Risk 02
AI Governance
Employees use a public AI tool to analyze confidential company data.
What data was exposed? Who should be notified? What controls failed?
Related: Hidden Risks of AI Shortcuts (Ep. 4) · Shadow AI training scenario
Risk 03
Financial Integrity
A business leader pressures employees to “do whatever it takes” to achieve quarterly targets.
Where is the line between performance pressure and misconduct? Who should intervene?
Risk 04
Speak-Up Culture
An employee reports misconduct involving a senior executive.
Would leadership receive the report? Would employees trust the process? Could retaliation be identified?
Risk 05
Data Privacy
Sensitive customer information is exposed through a cloud configuration error.
Who owns the response? What reporting obligations exist? What decisions must be made within the first 24 hours?
Related: Why Bosses Cannot Authorize Data Privacy Risks (Ep. 8) · Cloud misconfiguration training scenario
Executive Decision Labs Are Not Compliance Tabletop Exercises
Running tabletop exercises for compliance can sound like simply copying the cybersecurity drill. It isn’t. A traditional cyber tabletop rehearses the response to an incident already underway. An Executive Decision Lab™ rehearses the decisions made long before that point — the ones that determine whether the incident happens at all.
Both have their place. But notice the asymmetry: a tabletop makes a team better at the response. A Decision Lab makes a team less likely to need one.
Why the Labs Work
The Scenario Is Just the Vehicle
Every Executive Decision Lab™ is built around a specific, vivid scenario — an insider trade, a leaked dataset, a side letter, a missed export classification. The scenario is what makes the session memorable. But it is only the vehicle. What the room is actually practicing is a leadership lesson that outlasts the specifics: how authority, pressure, ownership, and accountability behave when the stakes are real. Each Lab can be read twice — once for the situation it depicts, and once for the governance question it is really asking.
The Invisible Insider
Scenario Vehicle
Insider Trading
Leadership Lesson
Third-Party Governance
The real discussion is not about insider trading law. It is about how organizations govern vendors, contractors, and third parties who gain access to sensitive information.
The MSA You Didn’t Read
Scenario Vehicle
Vendor Contract Risk
Leadership Lesson
Contract Ownership and Risk Transfer
The real discussion is not about contract language. It is about who owns critical obligations once the agreement is signed, and how accountability silently disappears across functions.
The Authorization Email
Scenario Vehicle
Data Exposure and Cloud Security
Leadership Lesson
Authority Pressure and AI Governance
The real discussion is not about cloud architecture. It is about how informal executive directives become perceived authorization to bypass established controls.
Grant Access Now, Classify Later
Scenario Vehicle
Export Controls
Leadership Lesson
Executive Authority vs. Statutory Authority
The real discussion is not about export regulations. It is about what happens when leaders assume authority they do not legally possess, and others follow because the directive came from above.
Paper It Clean
Scenario Vehicle
Revenue Recognition
Leadership Lesson
Leadership Pressure and Financial Integrity
The real discussion is not about accounting standards. It is about how performance pressure influences judgment, and how organizations normalize increasingly risky decisions.
The Seam
Scenario Vehicle
A Multi-Function Compliance Incident
Leadership Lesson
Cross-Functional Accountability and Governance Ownership
The real discussion is not about the incident itself. It is about the spaces between departments, where every leader performs their role correctly, yet critical responsibilities fall through the seams because no one owns the handoffs.
The Consulting Fee
Scenario Vehicle
Anti-Bribery / FCPA
Leadership Lesson
Crisis Command and the Self-Disclosure Decision
The real discussion is not about the bribery law. It is about who takes the wheel when a whistleblower’s clock is running, and why a disguised payment cleared every control on its way out the door.
Train the lesson, not just the scenario, and your team is prepared for the version of the crisis we didn’t write — the one that arrives wearing a costume they’ve never seen, carrying a decision they have already practiced.
From Training to Decision Practice
Training helps people recognize risks. Decision practice helps leaders prepare for them.
The goal is not to replace training. It is to add another layer of preparedness.
Pilots use simulators. Cybersecurity teams run tabletop exercises. Emergency responders conduct drills. All are based on the same principle: people make better decisions when they have practiced before the real event occurs.
Compliance leaders face increasingly complex risks involving third parties, artificial intelligence, data privacy, financial integrity, and organizational culture. Many of these issues require coordinated decisions across Legal, Compliance, Risk, IT, Procurement, HR, and business leadership.
At Xcelus, we call this format the Executive Decision Lab™ — a 90-minute facilitated session in which a leadership team works through a developing compliance crisis in real time, using role cards, scripted injections, and a written commitment captured before the room leaves.
Those conversations are often most valuable before an incident occurs.
The Question Every Leadership Team Should Ask
If a significant compliance incident occurred tomorrow, would your leadership team be seeing the situation for the first time? Or would they already have practiced the conversation?
The answer may determine how effectively the organization responds when the stakes are highest.
Built for Exactly This Question
Practice the Conversation Before the Incident Forces It
The Xcelus Executive Decision Lab™ is a 90-minute facilitated executive session built around the exact compliance risks discussed in this article. Three Labs are available now — vendor insider trading, vendor securities risk, and data privacy authorization — with more in development.
© 2005–2026 Xcelus LLC. All rights reserved. Executive Decision Lab™ is a trademark of Xcelus LLC.
© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.