NHS Executive Tabletop Exercise: Third-Party Dependency, Decision-Making and Organisational Resilience
- Date: 10th November 2026
- Time: 10:30am - 1:30pm
- Venue: etc.venues, Prospero House, 241 Borough High St, London, SE1 1GA
- Attendance: Complimentary for approved NHS and public sector delegates
- Places: Maximum 15 participants
About the Session
Cyber incidents affecting NHS organisations are no longer solely an IT issue.
A significant cyber event can quickly affect clinical services, operational capacity, communications, workforce deployment, patient safety and critical third-party suppliers.
This private, scenario-led tabletop exercise will bring together a small group of senior NHS leaders to explore how an organisation responds when a major cyber incident begins to disrupt essential services.
Rather than focusing on technical cyber defence, the session will examine the decisions senior leaders may need to make during an incident, how responsibilities are shared across the organisation and how boards and executive teams maintain safe and resilient services under pressure.
A Practical Board-Level Exercise
The centrepiece of the session will be an interactive tabletop scenario designed around a realistic cyber incident affecting an NHS organisation and one or more of its critical third-party dependencies.
Participants will work through the evolving scenario as a leadership group, considering:
- What information is needed before decisions can be made.
- Who should take ownership of different elements of the response.
- How clinical and operational services should be prioritised.
- When and how an incident should be escalated.
- How third-party suppliers should be managed during disruption.
- What the board and executive team need to know.
- How regulatory, governance and assurance responsibilities should be handled.
- How the organisation moves from immediate response into recovery.
The exercise is intended to encourage discussion, challenge assumptions and examine how different senior functions work together during a significant incident.
Key Areas of Focus
Key Areas of Focus
Executive Cyber Decision-Making
Exploring the decisions senior leaders may need to make when normal digital services are disrupted and information remains incomplete.
Clinical and Operational Resilience
Considering how organisations maintain safe patient care, prioritise critical services and manage operational pressures during prolonged digital disruption.
Third-Party and Supplier Risk
Examining what happens when a critical supplier, platform or infrastructure provider becomes part of the incident. This will look beyond data loss alone and consider the wider operational impact created by dependencies across the hospital or healthcare system.
Governance and Accountability
Understanding how responsibilities are shared across boards, executives, clinical leadership, digital teams, operational teams and assurance functions.
Organisational Response and Recovery
Considering escalation, communication, business continuity, recovery priorities and the decisions required as an organisation begins restoring services.
Who Should Attend?
This session is designed for senior NHS and public sector leaders who would have a role in organisational decision-making, governance, clinical continuity or operational response during a significant cyber incident.
Relevant roles may include:
- Board members and Non-Executive Directors.
- Chief Executives and Executive Directors.
- Medical Directors and Deputy Medical Directors.
- Chief Clinical Information Officers.
- Chief Information Officers and Chief Digital Information Officers.
- Directors of Digital and Transformation.
- Directors of Operations.
- Directors of Risk, Governance, Audit or Assurance.
- Senior clinical leaders with digital resilience responsibilities.
- Senior leaders involved in Emergency Preparedness, Resilience and Response.
- Integrated Care System and wider NHS executive leaders.
Delegate Suitability
Places are deliberately limited to ensure a senior, relevant and highly interactive discussion.
Delegates do not need to be cybersecurity specialists.
However, attendees should have some level of responsibility or involvement in the organisational response if a major cyber incident occurs.
This could include responsibility for:
- Executive or senior clinical decision-making.
- Incident escalation or command.
- Business continuity.
- Maintaining safe clinical services.
- Organisational resilience.
- Board-level cyber governance.
- Risk, assurance or regulatory accountability.
- Digital recovery.
- Third-party or supplier dependency.
- Operational response.
All registrations will be reviewed before attendance is confirmed.
Session Format
10:30am - Arrival, Registration and Networking
Tea and coffee on arrival with an opportunity to meet the other participants.
10:45am - Opening Insight: Cyber Risk as an Executive Responsibility
Led by Jessica Figueras.
An opening discussion examining cyber risk through a board and executive leadership lens, including organisational accountability, resilience and the importance of coordinated leadership during an incident.
11:10am - Interactive NHS Cyber Tabletop Exercise
A facilitated, evolving cyber scenario designed to test executive decision-making, clinical and operational priorities, governance, escalation and third-party dependency.
The scenario will develop in stages, requiring participants to consider new information and agree how the organisation should respond.
12:10pm - BlueFort Insight Session
A focused session exploring lessons around cyber resilience, supplier dependency and the practical challenges organisations face when critical technology or infrastructure is disrupted.
12:30pm - Facilitated Board-Level Discussion
A structured discussion reflecting on the exercise and examining:
- What worked
- Where decision-making became difficult
- Potential governance gaps
- Third-party dependencies
- Communication and escalation
- Lessons organisations can take back to their own boards and executive teams
1:15pm - Closing Reflections and Key Takeaways
Final observations and practical actions for participants to consider within their own organisations.
1:30pm - Lunch and Networking
Post-session lunch and informal networking.
Facilitator
Jessica Figueras
Jessica Figueras is a specialist in cyber governance, board-level cyber risk and organisational resilience.
The session will focus on the leadership and governance questions that arise during major cyber incidents rather than technical cybersecurity operations.
Jessica will chair the discussion, introduce the scenario and facilitate the executive tabletop exercise.
Supporting Partner
BlueFort
BlueFort is supporting the development of this private NHS leadership session.
BlueFort will contribute insight around organisational cyber resilience, critical supplier dependencies and the challenges organisations face when technology disruption begins to affect wider service delivery.
Shaping the Scenario
Approved participants will be asked to complete a short registration questionnaire ahead of the session.
Responses will help the facilitators understand:
- Participants' roles during cyber incidents.
- Current organisational priorities.
- Areas of concern.
- Third-party dependencies.
- Governance responsibilities.
- The issues delegates would most value exploring.
This information will be used to help shape the final scenario and discussion so that the exercise reflects the priorities of those attending.
Registration
Attendance is complimentary for approved NHS and public sector delegates.
Due to the interactive format, attendance is strictly limited to 15 participants.
All applications will be reviewed to ensure attendees have an appropriate level of responsibility or involvement in organisational cyber incident response, resilience, governance or continuity.
Request a place to attend.














