Xcelus Blog — Compliance Leadership

Cybersecurity Runs Tabletop Exercises. Why Doesn’t Compliance?

By the Xcelus Editorial Team

Editor’s Note

The opening scenario below is the basis for one of our Executive Decision Lab™ kits, The Invisible Insider — a 90-minute facilitated session designed for public company leadership teams who want to practice these conversations before an incident forces them.

Imagine your organization discovers that a vendor employee accessed confidential FDA approval information and shared it with a family member who purchased stock before the public announcement.

The information was material.

The trading activity has already occurred.

The media is calling.

Outside counsel is asking questions.

The board wants answers.

Would your leadership team know what to do next?

Most organizations spend significant time preparing for cybersecurity incidents. They conduct tabletop exercises, incident simulations, and response drills. Teams gather in a room, review realistic scenarios, discuss response options, identify weaknesses, and improve coordination before a real crisis occurs.

The logic is simple: people perform better under pressure when they have practiced beforehand.

Yet many compliance programs take a very different approach. Employees complete annual training. Managers review policies. Leaders receive updates from Compliance and Legal. But few organizations ever sit down and ask:

“What would we actually do if this happened here?”

“Our people would never do this.”

It’s the first thing most leaders think when reading a scenario like this — and it’s usually true. In a calm, fully informed room, no one makes the wrong call. But that’s not where these decisions get made. They get made under deadline pressure, inside a relationship, with incomplete information, on a bad day. This Executive Decision Lab doesn’t test whether your team knows the right answer. It surfaces whether the conditions that make the wrong answer feel reasonable are already present here, before an incident proves they are.

Knowing the Policy Isn’t the Same as Making the Decision

Compliance training plays an important role. Employees need to understand company policies, legal requirements, and reporting expectations.

However, real-world compliance failures rarely begin because someone forgot a policy definition. They occur when people face difficult decisions under pressure.

A manager is trying to meet a quarterly target. An employee discovers a potential conflict of interest involving a high-performing executive. A vendor gains access to sensitive information. A team uploads confidential data to a public AI platform to meet a deadline.

The challenge is not remembering a policy. The challenge is making the right decision when competing priorities, uncertainty, and business pressures are involved.

Cybersecurity leaders recognized this years ago. That is why they practice incidents. Compliance leaders should consider doing the same.

Cybersecurity’s “Practice Before It Happens” Mindset

When organizations conduct a ransomware tabletop exercise, they are not testing whether employees can define ransomware. They are testing:

Who owns the response?

How quickly can leadership make decisions?

What information is available?

Which controls work?

Which assumptions prove false?

What gaps exist?

The exercise often reveals issues that would never appear in a policy review or training course. The same principle applies to compliance risks.

A realistic scenario can quickly uncover questions such as:

Who owns third-party risk?

What would trigger board notification?

How would leadership learn about the issue?

Are escalation processes clear?

Do contracts address the risk?

Are reporting obligations understood?

These discussions often expose governance gaps long before regulators, auditors, or investigators discover them.

Five Compliance Risks Worth Practicing

Many organizations already have policies covering these risks. The question is whether leadership teams have ever discussed how they would respond if one occurred tomorrow.

Risk 01

Third-Party Risk

A vendor employee gains access to material non-public information and shares it with a family member.

Who is responsible? What contractual obligations apply? How would the organization respond?

Related: The Invisible Insider Decision Lab · Vendor MNPI training scenario

Risk 02

AI Governance

Employees use a public AI tool to analyze confidential company data.

What data was exposed? Who should be notified? What controls failed?

Related: Hidden Risks of AI Shortcuts (Ep. 4) · Shadow AI training scenario

Risk 03

Financial Integrity

A business leader pressures employees to “do whatever it takes” to achieve quarterly targets.

Where is the line between performance pressure and misconduct? Who should intervene?

Related: When “Whatever It Takes” Triggers Fraud (Ep. 1)

Risk 04

Speak-Up Culture

An employee reports misconduct involving a senior executive.

Would leadership receive the report? Would employees trust the process? Could retaliation be identified?

Related: One Casual Question Sinks Investigations (Ep. 2)

Risk 05

Data Privacy

Sensitive customer information is exposed through a cloud configuration error.

Who owns the response? What reporting obligations exist? What decisions must be made within the first 24 hours?

Related: Why Bosses Cannot Authorize Data Privacy Risks (Ep. 8) · Cloud misconfiguration training scenario

Executive Decision Labs Are Not Compliance Tabletop Exercises

Running tabletop exercises for compliance can sound like simply copying the cybersecurity drill. It isn’t. A traditional cyber tabletop rehearses the response to an incident already underway. An Executive Decision Lab™ rehearses the decisions made long before that point — the ones that determine whether the incident happens at all.

Traditional Cyber Tabletop
Executive Decision Lab™

Simulates an incident already in progress
Simulates the decisions that create incidents

Focuses on response and containment
Focuses on prevention and governance

Tests incident response plans
Tests leadership assumptions

Evaluates operational readiness
Evaluates decision readiness

Measures execution under pressure
Identifies governance gaps under pressure

Asks “What do we do now?”
Asks “Why would this happen here?”

Both have their place. But notice the asymmetry: a tabletop makes a team better at the response. A Decision Lab makes a team less likely to need one.

 

Why the Labs Work

The Scenario Is Just the Vehicle

Every Executive Decision Lab™ is built around a specific, vivid scenario — an insider trade, a leaked dataset, a side letter, a missed export classification. The scenario is what makes the session memorable. But it is only the vehicle. What the room is actually practicing is a leadership lesson that outlasts the specifics: how authority, pressure, ownership, and accountability behave when the stakes are real. Each Lab can be read twice — once for the situation it depicts, and once for the governance question it is really asking.

The Invisible Insider

Scenario Vehicle

Insider Trading

Leadership Lesson

Third-Party Governance

The real discussion is not about insider trading law. It is about how organizations govern vendors, contractors, and third parties who gain access to sensitive information.

The MSA You Didn’t Read

Scenario Vehicle

Vendor Contract Risk

Leadership Lesson

Contract Ownership and Risk Transfer

The real discussion is not about contract language. It is about who owns critical obligations once the agreement is signed, and how accountability silently disappears across functions.

The Authorization Email

Scenario Vehicle

Data Exposure and Cloud Security

Leadership Lesson

Authority Pressure and AI Governance

The real discussion is not about cloud architecture. It is about how informal executive directives become perceived authorization to bypass established controls.

Grant Access Now, Classify Later

Scenario Vehicle

Export Controls

Leadership Lesson

Executive Authority vs. Statutory Authority

The real discussion is not about export regulations. It is about what happens when leaders assume authority they do not legally possess, and others follow because the directive came from above.

Paper It Clean

Scenario Vehicle

Revenue Recognition

Leadership Lesson

Leadership Pressure and Financial Integrity

The real discussion is not about accounting standards. It is about how performance pressure influences judgment, and how organizations normalize increasingly risky decisions.

The Seam

Scenario Vehicle

A Multi-Function Compliance Incident

Leadership Lesson

Cross-Functional Accountability and Governance Ownership

The real discussion is not about the incident itself. It is about the spaces between departments, where every leader performs their role correctly, yet critical responsibilities fall through the seams because no one owns the handoffs.

The Consulting Fee

Scenario Vehicle

Anti-Bribery / FCPA

Leadership Lesson

Crisis Command and the Self-Disclosure Decision

The real discussion is not about the bribery law. It is about who takes the wheel when a whistleblower’s clock is running, and why a disguised payment cleared every control on its way out the door.

Train the lesson, not just the scenario, and your team is prepared for the version of the crisis we didn’t write — the one that arrives wearing a costume they’ve never seen, carrying a decision they have already practiced.

From Training to Decision Practice

Training helps people recognize risks. Decision practice helps leaders prepare for them.

The goal is not to replace training. It is to add another layer of preparedness.

Pilots use simulators. Cybersecurity teams run tabletop exercises. Emergency responders conduct drills. All are based on the same principle: people make better decisions when they have practiced before the real event occurs.

Compliance leaders face increasingly complex risks involving third parties, artificial intelligence, data privacy, financial integrity, and organizational culture. Many of these issues require coordinated decisions across Legal, Compliance, Risk, IT, Procurement, HR, and business leadership.

At Xcelus, we call this format the Executive Decision Lab™ — a 90-minute facilitated session in which a leadership team works through a developing compliance crisis in real time, using role cards, scripted injections, and a written commitment captured before the room leaves.

Those conversations are often most valuable before an incident occurs.

The Question Every Leadership Team Should Ask

If a significant compliance incident occurred tomorrow, would your leadership team be seeing the situation for the first time?  Or would they already have practiced the conversation?

The answer may determine how effectively the organization responds when the stakes are highest.

Built for Exactly This Question

Practice the Conversation Before the Incident Forces It

The Xcelus Executive Decision Lab™ is a 90-minute facilitated executive session built around the exact compliance risks discussed in this article. Three Labs are available now — vendor insider trading, vendor securities risk, and data privacy authorization — with more in development.

Explore the Decision Labs →
Talk to Xcelus

© 2005–2026 Xcelus LLC. All rights reserved. Executive Decision Lab™ is a trademark of Xcelus LLC.

© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.