Show Notes
Episode Overview
Most building teams have a maintenance plan. Far fewer have rehearsed what happens when a routine change triggers a cross-trade outage. In this episode of Built, Wired & Secured, Alex Morgan talks with Michael Harrington and James Rogers about why short, focused tabletop drills can uncover the real operational risks hiding inside building technology environments before a live incident exposes them.
The conversation opens with a scenario that feels uncomfortably realistic: a vendor pushes a firmware update to a door controller, the device reboots, the BAS flags a sensor fault, chilled water valves close, and half the east wing loses conditioned air during a critical tenant meeting. The front desk is overwhelmed, tickets start piling up, and no one is sure who has the authority to roll back the change. The technical event may be small, but the operational impact becomes immediate.
That is the core point of the episode. The problem is not always the device failure itself. The bigger issue is often the lack of a practiced escalation path. Who contacts the vendor? Who communicates with tenants? Who approves the rollback? Who owns the first three actions? A 60- to 90-minute tabletop drill can surface those questions quickly, often before anyone needs to spend money on new infrastructure.
Why Tabletop Drills Matter
Michael and James make a useful distinction between reliability work and rehearsal. Disciplined maintenance still matters, but maintenance alone does not expose assumptions. A tabletop is valuable because it tests decisions and ownership rather than raw system performance.
- It reveals unclear escalation authority.
- It identifies communication breakdowns between facilities, IT, security, and vendors.
- It surfaces dependencies that are easy to miss during normal operations.
- It highlights unrealistic assumptions about failover, vendor responsiveness, and service restoration.
- It often uncovers low-cost fixes before they become high-cost incidents.
One example shared in the episode involved a simulated single switch failure. The team learned the failover path had not been tested in months. What looked like a one-hour outage scenario turned into the discovery of a two-week capital fix. That is exactly the kind of insight a tabletop can create: not because it proves technical load capacity, but because it exposes gaps in ownership and recovery planning.
Tabletop vs. Live Testing
The episode also draws a clear line between tabletop exercises and live failover testing. If a team needs to verify that a generator can carry a full load, that requires a load test. But if the question is who signs off on switching to generator power and who notifies tenants when that happens, that is a tabletop problem.
That distinction matters for building operators because many disruptions are made worse by handoff failures, not just equipment failures. Tests can validate devices. Tabletop drills validate people, process, sequencing, and communication.
As the guests explain, putting facilities, IT, security, and a vendor representative in the same room and asking each group for their first three actions quickly exposes overlaps, omissions, and conflicting assumptions. That gives teams a faster path to assigning owners, deadlines, and follow-up actions.
Who Should Be in the Room
For organizations running a first drill, the advice is practical: start with the people who make decisions and the people who execute them. The exact mix may vary, but the core participants should usually include the functions most directly tied to building operations and response.
- Facilities
- IT
- Security or access control
- Primary vendors
- Someone responsible for communications
When the incident could affect tenant-facing systems, the episode recommends considering a tenant representative as well. That does not mean exposing tenants to technical minutiae or vulnerability details. Instead, the focus should be on testing expectations, communication timing, and message clarity.
For smaller teams, the recommendation is to begin with a narrower roster such as BAS, IT, and property management, then expand over time.
Best Scenarios for a First Drill
One of the strongest parts of the episode is the emphasis on realistic, manageable scenarios. The guests argue that simplicity is a feature, not a limitation. Teams do not need a sprawling simulation to get value. They need a believable situation that forces practical decisions.
Examples mentioned in the episode include:
- Network switch loss
- Carrier outage
- Generator failover
- BAS controller reboot
- A vendor maintenance window gone wrong
The conversation also highlights the importance of modeling degraded performance, not just hard failure. Slowly failing valves or intermittent chilled water flow can reveal monitoring weaknesses and fuzzy service level objectives long before a system fully stops working.
Failure Modes to Prioritize
For a first tabletop, the guests call out several high-value failure modes that commonly affect building technology operations:
- A localized network failure that takes access control and BAS offline
- Partial power loss where UPS protects servers but not field devices
- A key vendor being unreachable during a maintenance window
- Gradual performance degradation that exposes weak monitoring or unclear thresholds
That last category matters because ambiguity often extends outages. If no one agrees on what “restored” means or when performance has crossed a threshold, even a two-hour technical issue can turn into a much larger operational problem.
Recommended Cadence and Format
The discussion recommends a steady rhythm instead of one-off exercises. A short quarterly drill helps keep decision paths fresh, while a deeper annual exercise can bring in vendors and tenant representatives to test broader coordination and capital assumptions.
The suggested structure for a 60-minute pilot is straightforward:
- 10 minutes for setup, objectives, rules of engagement, and attendee roles
- 30 minutes for scenario play
- Two pauses during the scenario to ask about immediate actions and communications
- 10 to 15 minutes to capture decisions and assign owners
- 10 minutes to review and prioritize the action register
Participants should have a one-page template that includes the scenario description, presumed cause, impacted systems, decision triggers, owner, and recommended mitigation. Updating that artifact live creates accountability from the start.
Turning Findings Into Operational Change
The episode stays grounded in outcomes. The goal is not to run an interesting meeting. The goal is to produce actions that stick.
Michael and James describe examples where tabletop drills changed both capital planning and operations. In one case, a drill uncovered an overlooked UPS distribution rack. A modest capital improvement reduced risk to core systems and cut false alarms by preventing transient blips from being treated as critical events. In another, a BAS vendor’s remote access was found to depend on a single dial-out modem. Adding a second path and testing both monthly created inexpensive redundancy that could prevent a multi-day outage.
The guests also introduce a practical planning tool: define one realistic service level objective for each critical system and validate it in a drill. Their example is simple and effective: badge access restored within 30 minutes. If the organization cannot meet that target, leadership has two choices. Adjust the SLO or invest to make it achievable. Either way, the exercise creates clarity for budgeting and prioritization.
Key Takeaway
The final message of the episode is clear. Run a short, realistic rehearsal that tests decisions, not just devices. Start with a pilot this quarter. Publish the action register. Assign owners. Hold a follow-up within 30 days. Keep the tone constructive and focused on reducing friction, building repeatable responses, and improving trust across teams. If tenants feel the impact or operations stop, it is a high-priority risk worth rehearsing now, not after the next outage.
Why Building Technology Teams Need Tabletop Drills Before the Next Outage
Building operations teams are usually good at planning maintenance. They know when equipment should be serviced, when vendors are scheduled on site, and which systems are considered critical. But maintenance planning and outage readiness are not the same thing. A building can have a clean maintenance calendar and still be completely unprepared for the moment a routine change creates a cross-trade failure.
That is the central lesson from this episode of Built, Wired & Secured. Alex Morgan sits down with Michael Harrington and James Rogers to make the case for short, focused tabletop drills designed specifically for building technology environments. Their point is simple: many of the most painful incidents in commercial real estate are not caused by a dramatic catastrophe. They are caused by ordinary technical events that collide with unclear ownership, slow communication, and untested assumptions.
The episode opens with a scenario that illustrates the problem well. A vendor rolls out a firmware update to a door controller. The device reboots. The BAS flags a sensor fault. Chilled water valves close. Suddenly half the east wing loses conditioned air just as a critical tenant meeting begins. The front desk gets flooded with calls. The help desk opens tickets. And the organization loses precious time because nobody is certain who can approve a rollback, who contacts the vendor, or who communicates to tenants.
That is not just a technical issue. It is an operational failure with reputational consequences.
What a Tabletop Drill Actually Tests
One of the most useful distinctions in the conversation is the difference between testing equipment and testing decisions. A live failover test can tell you whether a generator carries load. A tabletop drill tells you who authorizes the switchover, who confirms building priorities, and who is responsible for informing tenants about what is happening.
That distinction matters because real-world incidents are often extended by confusion rather than by the original fault. A device problem may start the event, but an unclear escalation path is what turns 10 minutes into an operational scramble. A tabletop exposes those weak points without requiring a disruptive live exercise.
Michael and James frame tabletops as a way to spotlight ownership, sequence, and communication. If facilities, IT, security, and a vendor representative all describe different first steps for the same outage, that is valuable information. If no one owns tenant messaging, that is a real risk. If a rollback requires approval but the approval path is undefined, that is a gap worth fixing before it is tested under pressure.
In other words, tabletops are not abstract planning sessions. They are a fast way to identify where operational reality does not match institutional assumptions.
Why Short Drills Work
The episode repeatedly emphasizes that teams do not need large, complicated exercises to get real value. In fact, the recommended drill length is only 60 to 90 minutes. That shorter format matters because it lowers the barrier to entry and makes it easier to build a repeatable cadence.
Short drills work because they force focus. Instead of trying to simulate every possible failure, teams can zero in on one realistic scenario and work through the immediate decisions it triggers. The exercise becomes less about theoretical completeness and more about practical readiness.
That format also changes behavior quickly. Put the relevant groups in the same room and ask a simple question: what are your first three actions? According to the episode, the gaps and overlaps become obvious fast. Once those issues are visible, teams can assign owners, set deadlines, and move directly into improvement work.
For organizations that have delayed this kind of rehearsal because it felt too heavy or too disruptive, that should be encouraging. The path forward does not start with a large-scale simulation. It starts with a disciplined conversation around a believable outage.
The Right Scenarios for a First Exercise
The guests advise teams to choose realistic scenarios tied to actual building operations. The best first drill is not the most dramatic one. It is the one most likely to expose real handoff problems.
The scenarios discussed in the episode include network switch loss, carrier outage, generator failover, BAS controller reboot, and a vendor maintenance window gone wrong. Those are strong starting points because they combine technical dependency with clear operational impact.
The conversation also adds an important wrinkle: teams should not only drill catastrophic failure. They should also model degradation. Slowly failing valves or intermittent chilled water flow may not trigger an immediate emergency, but they can expose weak monitoring, unclear thresholds, and vague expectations about what acceptable service looks like.
That matters because ambiguous performance is often where organizations lose time. If no one agrees on when a system has crossed from “degraded” to “action required,” response slows down, communication becomes inconsistent, and service restoration targets become hard to defend.
Who Should Be in the Room
The recommended participant list is practical and grounded in building operations. At a minimum, the table should include decision makers and doers from facilities, IT, and security or access control, along with primary vendors and someone responsible for communications.
That communications role is especially important. Many teams are comfortable discussing technical recovery but much less prepared to answer the operational question of who says what, to whom, and how quickly. In tenant-facing environments, that is not a side issue. It is a core part of service delivery.
The episode handles tenant participation carefully. The guests acknowledge that involving tenants can backfire if done poorly. Sharing a raw technical vulnerability discussion is not the goal. But excluding tenants completely can also create a trust problem when a real incident occurs and communication feels slow or uncoordinated. Their recommendation is controlled participation, such as using a de-identified tenant representative or running a communication-specific exercise rather than a deeply technical review.
That is a useful middle ground for commercial real estate teams. It protects sensitive details while still testing how tenant expectations are managed during service disruption.
What Teams Commonly Discover
The practical examples in the episode show why this work matters. In one drill, a team discovered that a failover path tied to a switch failure had not been tested in months. What looked like a one-hour outage scenario ultimately pointed to a two-week capital fix. In another case, a modest investment in a UPS-related issue reduced risk to core systems and cut false alarms. In a third, a BAS vendor’s remote access was found to depend on a single dial-out modem, leading to an inexpensive redundancy improvement with meaningful risk reduction.
These are not theoretical insights. They are examples of how a short exercise can affect both operational discipline and capital planning. A tabletop can reveal where a relatively small investment prevents a much larger outage. It can also show where process changes, not equipment purchases, deliver the fastest gain.
How Often to Run Them
The cadence recommended in the episode is sensible: a short quarterly tabletop with a small roster and one deeper annual exercise that includes broader coordination across vendors and tenant representatives. That split works because it balances repetition with scale. Quarterly drills keep decision paths fresh. Annual exercises test larger assumptions about coordination, communication, and recovery capability.
Just as important, the guests stress that outcomes must be made visible. The drill should produce an action register with owners and deadlines. Those actions should show up in staff meetings as one-line status updates. Without follow-through, the exercise risks becoming performative. With follow-through, it becomes part of how the organization improves resilience over time.
A Practical 30-60-90 Approach
The episode closes with a useful planning model. In 30 days, choose a realistic scenario and schedule a 60-minute pilot with core stakeholders. In 60 days, run the drill and publish an action register with clear owners. In 90 days, review progress, close quick wins, and schedule the next drill with a broader roster.
There is also a strong recommendation to define one realistic service level objective for each critical system and then validate it in a drill. The example given is badge access restored within 30 minutes. That kind of clarity helps teams make better budgeting decisions. If the SLO is unrealistic, leadership can adjust expectations or fund the changes needed to meet them. Either outcome is better than discovering the mismatch during a live incident.
The Business Value Behind the Exercise
The broader takeaway is that tabletop drills are not just a technical best practice. They are a business discipline. They reduce friction between teams, shorten outage duration, improve tenant communication, and reveal where low-cost fixes create outsized operational value. They also give leadership a clearer basis for prioritizing capital work instead of relying on assumptions or anecdotes.
For commercial real estate and building operations teams, that is the real opportunity. A compact rehearsal can improve resilience without requiring a major project launch. It can align facilities, IT, security, and vendors around the same recovery playbook. And it can turn hidden assumptions into visible decisions while the stakes are low.
If this episode leaves listeners with one practical next step, it is this: run a short, realistic drill that tests decisions, not just devices. Start this quarter. Publish the actions. Assign owners. Then follow up within 30 days to make sure the exercise changed something real.
If you want the full conversation and the sample scenario template mentioned in the episode, listen to this installment of Built, Wired & Secured and use it as the starting point for your first tabletop session.