Show Notes
Why Tabletop Exercises Matter for Building Technology
Building technology failures rarely stay contained to one system. A power event can affect access control, elevators, networks, tenant communications, and vendor response at the same time. This episode of Built, Wired & Secured explains why tabletop exercises are one of the most practical ways property teams can prepare for those moments before they become tenant-facing incidents.
The discussion begins with a realistic outage scenario: a storm knocks out a transformer, the backup generator does not start, access control goes offline, elevators stop, and tenants cannot badge into the building. Without a consolidated playbook, facilities, IT, security, property management, and vendors may all work from different assumptions. The result can be hours of avoidable confusion.
A tabletop exercise does not require teams to shut down production systems or run risky live failovers. It is a structured, discussion-based drill that tests how people make decisions, communicate, escalate issues, and recover services when something important fails.
Three Gaps Tabletop Exercises Expose
- Undocumented dependencies: A card reader depends on PoE switches, which depend on a network closet, which may be maintained on a different schedule than the access control system it supports.
- Untracked single points of failure: A component may work reliably until it becomes the one device, power source, or connection that brings down multiple services.
- Operational silos: IT, facilities, security, property management, and vendors may have different contact lists, escalation paths, and assumptions about ownership.
One example in the episode involved a simulated partial power loss. Facilities believed the UPS protected the access control servers, while IT believed those servers were cloud-hosted. The drill showed that the access control database was actually local to a rack served by one UPS that was not on the critical maintenance list. That finding led to a plan for redundant UPS coverage and updated maintenance windows.
How to Design a Safe, Useful Exercise
Start small. The recommended format is a 60- to 90-minute discussion-based exercise focused on one subsystem or one failure mode. Use scenarios such as a power loss, partial network outage, or credential replication failure. Avoid live system toggles and production failovers during early exercises; the goal is to test decisions without creating tenant disruption.
Include the people who have a real role in the response:
- Facilities lead
- IT lead
- Security lead
- Relevant vendor representative
- Tenant representative when tenant-facing services are involved
A simple exercise timeline can work as follows:
- Minutes 0-10: Brief the scenario and assign roles.
- Minutes 10-40: Introduce the primary failure and add an inject every 10 minutes.
- Final 20 minutes: Conduct an after-action review and capture decisions, unknowns, and immediate mitigations.
Useful injects include delayed vendor arrival, conflicting advice from vendors, tenant escalation, incomplete staffing, and time-of-day constraints. Each inject should force a real operational decision: who makes the call, who contacts the vendor, what is logged, and who owns the tenant message.
Metrics That Turn Drills Into Business Decisions
Keep measurement operational and simple. Track time to decision for critical calls, time to first vendor contact, the number of undocumented dependencies discovered, and the percentage of injects with a clearly identified owner. Teams should also assess communication clarity, role understanding, and whether runbook steps can actually be used under pressure.
These measures help leadership see whether readiness is improving. They also provide evidence for capital decisions. In one office example, an exercise identified a single PoE switch in a riser serving two floors. Replacing it and adding a small redundant uplink reduced similar badge-related incidents from monthly occurrences to nearly zero. The investment was approved because the drill connected the technical issue to saved operational hours.
Another example involved a campus with mixed vendor contracts and no single escalation path for generator testing. A tabletop exercise led to a single on-call vendor rotation and documented testing checklist. Vendor response improved, while emergency labor costs decreased.
From Findings to a Living Runbook
Every exercise should produce two outputs. First, create a one-page executive summary with the top three risks, recommended fixes, rough cost estimates, and expected downtime reduction. Second, create or update an operational runbook with step-by-step actions, roles, primary and backup contact numbers, decision trees, safe-state procedures, and quick fallbacks.
Runbooks must remain living documents. Version them, schedule re-walks, and assign owners to close findings within 30, 60, or 90 days. A document that has not been tested against real operational constraints is still an assumption.
A 30-60-90 Day Starting Point
- Within 30 days: Convene cross-functional leads for a one-hour tabletop exercise using a power-loss scenario.
- Within 60 days: Produce a one-page summary with three prioritized fixes and accountable owners.
- Within 90 days: Convert the highest-priority fix into a runbook step and schedule a follow-up tabletop to validate it.
The central question for every building team is simple: What breaks if this goes down? Tabletop exercises help answer it before an outage forces the answer in real time.
Building Technology Resilience Requires Practice, Not Assumptions
A building technology outage does not have to begin as a major disaster to become one. A storm, transformer failure, missed generator startup, partial network outage, or access control problem can quickly affect tenants, facilities teams, security operations, and vendors at once. The technical fault may be only one part of the problem. The larger issue is often that the people responsible for recovery have not practiced how they will work together.
That is where tabletop exercises matter. A tabletop exercise is a structured, discussion-based simulation that allows a property team to rehearse a response without touching production systems. It gives facilities, IT, security, property management, vendors, and sometimes tenant representatives a safe environment to answer the questions that matter during an outage: What is impacted? Who owns the decision? Who contacts the vendor? What gets communicated to tenants? What happens if the first recovery option fails?
For commercial properties, this kind of preparation can turn a chaotic, tenant-facing incident into a controlled recovery process. It can also reveal which operational improvements and capital investments will have the greatest effect on downtime.
The Human Side of Recovery Is Often the Weakest Link
Consider a power-related event at 3:00 a.m. A storm knocks out a transformer, the backup generator does not start, the building loses power, access control goes offline, elevators stop, and the help desk begins receiving calls from tenants who cannot badge in. If every department has a different call list, escalation path, and view of the building environment, the response becomes improvised.
In that situation, the lack of a consolidated playbook can extend the impact well beyond the original failure. Facilities may be trying to determine what systems lost power. IT may be checking network connectivity. Security may be managing access concerns. Property management may be deciding what to tell tenants. Vendors may be on separate contact lists with unclear responsibilities.
A tabletop exercise exists to rehearse this human part of recovery. It does not eliminate the need for resilient power, networking, or access control design. It does, however, show where decisions slow down, where ownership is unclear, and where the recovery plan depends on assumptions rather than documented facts.
Three Operational Gaps That Commonly Surface
The first recurring gap is undocumented dependencies. Building systems depend on other systems in ways that are easy to overlook during normal operations. A card reader may depend on a PoE switch. That switch depends on a network closet. The network closet may be subject to a maintenance schedule that is separate from the access control environment. If those relationships are not documented, teams may not know what must be restored first.
The second gap is an untracked single point of failure. A single device, power source, switch, uplink, or local server can support more than one critical business function. It may appear reliable for years, which makes it easy to ignore. But when it fails, the organization discovers that redundancy was assumed rather than confirmed.
The third gap is operational silos. IT, facilities, security, property management, and vendors may all be competent within their own responsibilities, yet still struggle during a shared event because their escalation contacts and recovery assumptions do not align.
A partial power-loss exercise illustrates how quickly these gaps can emerge. In the example discussed on the episode, facilities assumed the UPS covered access control servers. IT assumed those servers were cloud-hosted. During the drill, the team found that the access control database was actually local to a rack served by one UPS. That UPS was not included on the critical maintenance list. The outcome was not a theoretical lesson: the team had a clear reason to pursue redundant UPS coverage and revise maintenance windows before an actual failure occurred.
Design a Drill That Is Realistic Without Disrupting Tenants
Early tabletop exercises should be discussion-based. There is no need to toggle systems, fail over production services, or create a live disruption to test decision-making. Realism comes from the scenario design and the constraints introduced during the exercise.
Keep the scope narrow. Select one subsystem or one failure mode for each exercise. A focused power-loss scenario, partial network outage, or credential replication failure can reveal more useful information than a broad scenario that tries to cover every building system at once. A 60- to 90-minute exercise is enough to test roles, communication, escalation, and recovery priorities without becoming an all-day meeting.
The participant list should reflect real operating responsibilities. At a minimum, include the facilities lead, IT lead, security lead, and relevant vendor representative. If the outage would affect tenant-facing services, include a tenant representative. Their presence helps the team consider communications and operational consequences that may otherwise be missed.
A simple format is effective. Begin with 10 minutes for a scenario briefing and role assignments. Spend the next 30 minutes working through the primary incident. Add a new inject every 10 minutes to force decisions under changing conditions. Examples include a delayed vendor arrival, conflicting vendor advice, a tenant escalation, incomplete vendor staffing, or time-of-day constraints. End with a 20-minute after-action discussion to document decisions, unknowns, and immediate mitigations.
Measure Operational Readiness in Practical Terms
Tabletop exercises become more valuable when teams measure outcomes. The metrics do not need to be complicated. Track the time to decision for critical calls, time to first vendor contact, number of undocumented dependencies discovered, and percentage of injects that received a clearly identified owner.
Qualitative measures matter as well. Was communication clear? Did participants understand their roles? Were the documented runbook steps actionable? Could the team identify who owned the tenant message? These questions show whether a recovery plan is useful in practice rather than simply complete on paper.
Operational metrics also help property leaders make better investment decisions. In one office example, an exercise exposed a single PoE switch in a riser serving two floors. The finding connected repeated peak-hour badge failures to a specific point of failure. Replacing that switch and adding a small redundant uplink reduced similar incidents from monthly occurrences to nearly zero. The capital request was easier to defend because it was based on expected operational hours saved, not vendor hype.
In another example, a campus with mixed vendor contracts discovered it had no unified escalation path for generator testing. The response was a documented vendor on-call rotation and a test checklist. Vendor response times improved, and the facilities team reduced emergency labor costs. The improvements were low- to moderate-spend changes, but they were grounded in evidence from the exercise.
Convert Exercise Findings Into Runbooks and Capital Plans
A successful tabletop exercise should result in two practical deliverables. The first is a short executive summary. Keep it to one page and identify the top three risks, recommended fixes, rough cost estimates, and expected downtime reduction. This gives leadership an understandable basis for prioritizing work and approving investment.
The second deliverable is an operational runbook. A useful runbook includes step-by-step actions, roles, primary and backup contact numbers, decision trees, safe-state procedures, and quick fallback options. It should establish who owns each action and what conditions trigger escalation.
Just as important, the runbook must be maintained. Version it, schedule re-walks, and assign owners to close findings within 30, 60, or 90 days. When the highest-priority fix is complete, schedule a follow-up tabletop to verify that the change actually improved the response path.
Start With a 30-60-90 Day Plan
Within 30 days, bring cross-functional leads together for a one-hour tabletop using a simple power-loss inject. Within 60 days, produce a one-page summary with three prioritized fixes and named owners. Within 90 days, convert the highest-priority fix into a runbook step and schedule a follow-up exercise to validate it.
The question that drives this work is straightforward: What breaks if this goes down? Asking it consistently changes how teams prioritize maintenance, redundancy, vendor coordination, and capital spending.
Listen to this episode of Built, Wired & Secured for the full discussion of scenario design, practical metrics, runbook development, and how small drills can produce measurable improvements in building technology readiness.