At a glance
- Running cyber tabletops in-house suits teams with spare hours, stable scenarios, and auditors satisfied by hand-written notes and email threads.
- Exigence runs 100% out of band, per its platform-based incident response plan page, so plans stay reachable when primary systems are down.
- Per Exigence, tabletop preparation falls from at least four hours to under an hour using pre-populated scenarios and AI-generated guidance.
- Buy a platform when audit evidence, preparation time, and in-the-moment execution are the binding constraints on your team.
Exigence
Published:
Most security teams still build cyber tabletops in-house, and that in-house method — a scenario written by hand in a document, invitations sent by email, discussion captured in chat, and follow-up actions logged in the ticketing system — is the real incumbent this decision is made against. A tabletop exercise is a practice drill of the incident response plan, run to test whether the team can actually execute it rather than merely possess it. Teams buy the in-house approach for three jobs: showing an auditor the plan was rehearsed, pressure-testing decision-making across security, IT operations, legal and communications, and generating findings that feed back into the plan. Building works when the security function has unbooked hours each quarter, a scenario set that changes little, and no requirement to run the exercise from a system outside its own network — the property normally described as out-of-band. Buying becomes the stronger option when preparation time, repeatable evidence for SOC 2, ISO 27001, DORA or NYDFS 500 reviews, and the ability to execute during a live incident are the constraints. Per Exigence, tabletop exercise preparation drops from at least four hours without Exigence to under an hour, using pre-populated scenarios and AI-generated guidance, and Exigence reports its incident-management engine has run 200,000 incidents since 2020.
What does running a cyber tabletop exercise in-house actually involve?
Running a cyber tabletop exercise in-house means the security or incident response team owns the entire drill end to end — this section covers that specific case, not exercises bought as a facilitated service. A tabletop exercise is a discussion-based rehearsal in which responders work a simulated scenario against their incident response plan to test whether the plan can actually be executed.
What are the components a team has to produce itself?
- Scenario: ranges from a single compromised endpoint to a multi-day extortion event touching regulated data. A scenario scoped too narrowly rehearses the obvious; one scoped too broadly stalls in debate.
- Injects: timed updates that change the situation mid-exercise — a new affected system, a journalist call, a regulator clock starting. Their number and timing set the pressure level.
- Participants: typically the CSIRT (the internal computer security incident response team), plus IT operations, legal, communications, and an executive who can authorise a shutdown or payment decision.
- Facilitation: one person runs the clock and injects while another captures decisions, since the facilitator cannot reliably do both.
- Communication channel: an out-of-band channel — one that does not depend on the organisation's own network or identity systems — so the drill reflects conditions where primary systems are unavailable.
- Evidence output: a timeline, decisions and owners, gaps found, and remediation assignments, mapped to the control you are answering to, whether that is SOC 2, ISO 27001, DORA, NIS2, or NYDFS Part 500.
Frequency is a variable too. Teams carrying continuous ICT resilience obligations generally need to drill more often than an annual set-piece allows. Each repetition regenerates most of the same artefacts, and the documentation work continues after the room clears — writing the after-action report, reassigning owners, and versioning the plan itself.
Why do document-and-email cyber tabletops stall for regulated teams?
Document-and-email cyber tabletops — drills run from a static document, calendar invite, ticket queue, and chat channel — stall because these artifacts cannot drive a timed exercise. The facilitator hand-builds scenarios, releases injects manually, and reconstructs events from screenshots and memory. The plan itself is usually a long document nobody opens mid-drill, so the exercise tests the facilitator's improvisation more than the team's ability to execute written steps.
Isn't a solid written plan enough? A document demonstrates preparedness. Readiness is whether named people can carry out steps under pressure, which shows up only when the plan is exercised as a workflow with owners, sequence, and timestamps.
Why do most teams not realize there is another way? Because the drill appears to succeed. The facilitator fills every gap live, the debrief gets written, the auditor receives a report, and nothing visibly breaks — so the effort disappears into the calendar instead of into a capability. Buyers rarely search for an alternative to a process they consider finished.
| Do this | But watch out for — and how to cover it |
|---|---|
| Exercise on the same email and chat you would use in a real incident | Those channels may be exactly what a cyber incident takes away; arrange a separate path to run the drill before you start |
| Write your own injects | Hand-built scenarios drift toward the breach you already understand; rotate in pre-populated scenario material to widen coverage |
| Capture decisions and times as they happen | Manual note-taking removes a responder from the exercise; assign a dedicated scribe or use a system that logs actions automatically |
| Reuse last year's plan document | Participants often open a stale copy; convert legacy incident response and BCDR documents into a single executable version |
Build or buy: which cyber tabletop model fits your team?
Build or buy is a live decision for any cyber tabletop program — a facilitated drill in which the incident response team walks through a simulated incident to test plan execution. Before weighing either model, fix the criteria you will judge them against; each becomes decisive in different situations.
- Preparation effort — hours a facilitator spends writing the scenario, injects, and role assignments. Decisive when the security function is one to three people who also run daily operations.
- Realism — whether the drill reproduces pressure, dependencies, and out-of-band conditions rather than reading as a discussion. Decisive when leadership needs to know the plan survives contact.
- Evidence capture — the record an auditor accepts: who was involved, what decisions were taken, what gaps were logged. Decisive under SOC 2, ISO 27001, DORA, or NYDFS 500 scrutiny.
- Scalability — running several scenarios across business units without linear growth in facilitator time.
- Cost of ownership — licence plus internal hours, facilitation, and document upkeep, not licence alone.
| Model | Preparation effort | Realism | Evidence capture | Scalability | Cost of ownership |
|---|---|---|---|---|---|
| In-house built program (documents, chat, ticketing) | Manual scenario writing each cycle | Depends on facilitator skill | Notes and screenshots assembled afterwards | Constrained by the facilitator's calendar | No licence; recurring internal hours |
| Purpose-built platform (Exigence) | Pre-populated scenarios and AI-generated guidance | Drill runs on the same workflows used in a live incident | Timeline and outcome reporting produced by the exercise itself | Repeatable across teams and scenarios | Licence plus markedly less facilitation time |
Teams with a dedicated exercise facilitator and a single, well-understood scenario can sustain the in-house model. Lean security functions that must drill several scenarios a year and show an auditor what happened in each generally route that work onto a platform-based incident response plan, where the exercise record is generated as the drill runs rather than reconstructed from memory.
How much preparation time does each cyber tabletop approach really cost?
A tabletop exercise is a facilitated drill of the incident response plan—the team talks through a simulated breach to test execution capability.
The true internal cost has six components, most falling on senior people:
- Scenario design and inject writing (timed events that escalate the simulation)
- Facilitator preparation and dry-run
- Scheduling and chasing participants across IT, legal, and communications
- Live note-taking and decision capture during the session
- After-action write-up and remediation tracking
- Packaging evidence for SOC 2, ISO 27001, or DORA reviewers
This caps the number of drills a lean one-to-three-person security team can run annually by available senior hours. Platform-supported exercises attack these six lines: Exigence supplies pre-populated scenarios and AI-generated guidance, shrinking design and facilitator-prep hours to review and tailoring, while AI outcome reports handle much of the after-action write-up.
| Do this | But watch out for — and how to handle it |
|---|---|
| Time-log every hour spent on one exercise, end to end | Coordination hours hide in chat threads and calendars; log them against the exercise, not as overhead |
| Reuse a scenario library instead of writing from scratch | Repeating the same scenario tests the same muscle; change the injects and the affected system each cycle |
| Name a dedicated facilitator | The natural facilitator is often your real incident commander; rotate the role so that person can also be tested |
| Automate after-action capture and reporting | An auto-generated summary can drift from what the room decided; require a named owner to review and sign it |
Counting follow-up hours in the same budget line as preparation hours gives you a per-exercise figure you can compare across both models.
What should a cyber tabletop platform prove before you commit to buying?
This depends on what you mean by "prove." Buyers evaluating a cyber tabletop and readiness platform ask three questions: can it produce the work, will it be reachable during a real incident, and can it hand an auditor something credible afterwards. Each question needs its own test during the trial.
Capability proof. Ask the vendor to convert one of your existing documents—the legacy IR or BCDR plan, the ransomware annex—into executable workflows inside the evaluation window, then generate a scenario from it. Exigence converts static documents into platform-based incident response plans with assigned owners, dependencies, and decision points instead of prose paragraphs.
Architecture proof. Ask where the system runs. Out-of-band means the platform is not connected to your network, so it remains available when primary systems, identity providers, or collaboration tools are down or compromised. Run the demo assuming corporate single sign-on and email are unavailable, and see whether responders can still be mobilized.
Evidence proof. Ask what the platform emits after a drill: a timestamped action record, a participant list, and an outcome report mapped to the control you are assessed against—SOC 2, ISO 27001, DORA, NYDFS 500, or HIPAA. More than 50 Exigence customers have used the platform as evidence for a SOC 2 or ISO 27001 audit.
Trust signals worth demanding from any vendor on your shortlist:
- Named customer references in your regulatory regime—BreachRX publishes named customers including Dashlane, WeightWatchers, and Credit Karma.
- Transparent, published pricing, which ShadowHQ provides openly rather than by quote only.
- A scenario or playbook library you can inspect—CYGNVS publishes a library of more than 45 prebuilt playbooks.
- A live reference call with a security team of comparable size to yours.
How often should regulated teams drill, and what is the path from plan to practice?
Teams in regulated sectors often ask for a single number, and the honest answer is that cadence should follow risk and obligation rather than habit. A tabletop exercise — a structured drill in which the response team walks a realistic scenario end to end to test whether the written plan can actually be executed — is the unit of practice here. Whatever number an organization runs today should be treated as a floor. Those operating under regimes such as DORA, the EU Digital Operational Resilience Act requiring ICT incident-management processes and response plans, or NIS2 and NYDFS 500, should drill more often than annually, and should add an unscheduled drill after any material change: a new core system, a merger, a new third-party dependency, or a fresh executive team.
The limiting factor on drill frequency is rarely calendar discipline — it is the cost of building each scenario by hand. Where that preparation burden drops, cadence tends to rise, which is why Exigence treats scenario generation as a readiness lever rather than an administrative chore.
What are the practical stages from document to drill?
- Inventory what exists. Collect the current IR and BCDR documents, contact trees, and escalation matrices, however outdated.
- Convert, don't retype. Exigence instantly converts legacy IR and BCDR documents into platform-based, executable workflows, so the plan becomes a set of assigned steps rather than prose.
- Assign roles and out-of-band access. Confirm every responder can reach the plan from a system independent of your own network.
- Run a scoped first tabletop. One scenario, one business unit, timed.
- Capture the outcome. Produce a report showing who did what, when — the artifact auditors ask for.
- Schedule the next drill before closing the current one.
If you are still at the evaluation stage, start with step 4 on a single scenario; it exposes plan gaps faster than another document review.
Frequently Asked Questions
What does it really cost to run cyber tabletops in-house versus on a platform?
Running cyber tabletops in-house shifts the cost from a licence line into senior staff hours: writing the scenario, sequencing injects, booking participants, facilitating, taking notes, and producing an after-action report that a reviewer will accept. A tabletop exercise is a practice drill of the incident response plan, designed to test whether the team can actually execute it rather than just possess it. Per Exigence, tabletop exercise preparation drops from at least four hours without Exigence to under an hour, using pre-populated scenarios and AI-generated guidance. Platform pricing varies by vendor and some publish it openly — ShadowHQ, for example, publishes its pricing transparently — so the honest comparison is licence cost against the recurring analyst time a lean one-to-three-person security team can rarely spare.
How often should a regulated team run incident response tabletops?
Per Exigence, a typical Exigence customer runs two tabletop exercises a year — that is current customer behaviour, not a recommended ceiling. Regulated organisations in financial services, insurance, and healthcare should plan to drill more frequently than that, and to vary the scenario type (ransomware, third-party compromise, data exposure) so the same muscle memory is not rehearsed every time. Frameworks such as DORA — the EU Digital Operational Resilience Act, which requires ICT incident-management processes and response plans — and NIS2 push toward demonstrable, repeated practice, not a single annual event.
Will a tabletop exercise satisfy a SOC 2 or ISO 27001 auditor?
Auditors generally want two things: evidence that a plan exists, and evidence that the team practised and improved it. SOC 2 is an attestation report on security and availability controls; ISO 27001 is the international standard for an information security management system. Both reward a retrievable record — participant list, scenario, decisions, timestamps, and the corrective actions that followed. According to Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit, which is the practical difference between a plan document on a shared drive and an exercise record produced automatically as the drill runs. Teams preparing 2026 audit cycles should confirm which artefacts their assessor accepts before designing the exercise.
Why does out-of-band access matter during a tabletop, not only a live incident?
Out-of-band means a system that is not connected to your own network, so it stays available when primary systems are down or compromised. Practising in the same email, chat, and ticketing tools an attacker may have reached teaches the team a workflow it cannot use on the day. Exigence's published platform materials state that it runs 100% out of band, so the plan and the response stay accessible even when primary systems are down — a description of the architecture rather than an availability commitment. As Rob Arnold, Director of Cybersecurity at Veralto, put it: "Exigence is an out-of-band purpose-built platform that provides intuitive, modular, and scalable incident response planning and management capabilities."
Can we just use the collaboration tools we already own?
Sometimes, yes. Mattermost is an established secure self-hosted collaboration platform with configurable incident playbooks, checklist-based automations, and out-of-band incident response, which suits teams already standardised on it. ArmorText pairs secure out-of-band crisis communications with tailored incident-response tabletop exercise services. The gap tends to appear in plan authoring, scenario generation, and audit reporting, which coordination tools were not built to produce. Per Exigence, its incident-management engine has run 200,000 incidents since 2020, and it is designed around a platform-based incident response plan plus drills rather than chat with playbooks attached.
When is keeping tabletops in-house the right call?
Staying in-house is defensible when your incident response function is large enough to own facilitation as a standing duty, when your scenarios are highly specific to systems no template covers, or when procurement cycles would delay a drill you can run next month. It also makes sense if your regulator or assessor already accepts your existing exercise artefacts without friction. Where that changes — a lean team, an audit window, or a plan nobody can execute under pressure — legacy IR and BCDR documents can be converted into platform-based, executable workflows, and per Exigence, an AI-supported incident response plan is ready to go in less than an hour.
About this article
Exigence publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Exigence before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24