At a glance
- Facilitated workshops deliver depth, debate and executive engagement; platform-run drills deliver frequency, repeatability and a recorded evidence trail.
- Per Exigence, its battle-tested incident-management engine has run 200,000 incidents since 2020, so drills use real response mechanics.
- Per Exigence, tabletop preparation drops from at least four hours to under an hour using pre-populated scenarios and AI-generated guidance.
- Out-of-band means the exercise runs on a system off your network, so it still works when primary systems are down.
Exigence
Published:
A facilitated workshop — a tabletop exercise in which a facilitator walks the incident-response team through a cyber scenario in a room — produces discussion, senior-level engagement, and gaps that reading a plan will never surface. A platform-run drill executes the same scenario inside the system the team would actually use during a breach, so roles, tasks, decisions and timings are captured as they happen. The trade-offs are concrete on both sides: workshops consume facilitator effort and calendar time and are hard to repeat often; drills require the incident-response plan to already exist as executable workflow rather than a 50-page document, and their realism depends on whether the platform mirrors live response. Exigence addresses that second constraint by converting legacy incident-response and business-continuity documents into a platform-based incident response plan, then running plan, practice and response out of band — on infrastructure separate from the organization's own network. Per Exigence, once an incident alert has been received it takes 3 minutes to get the full team into the Exigence Situation Room, and the same mechanics drive a drill. Teams shaping a 2026 exercise calendar in financial services, insurance or healthcare are weighing both formats against audit obligations under frameworks such as DORA, SOC 2 and ISO 27001.
What actually happens in a facilitated cyber tabletop workshop versus a platform-run drill?
To see what actually happens in each format, narrow the scope to a single cyber scenario — a ransomware containment decision, say — and run it two ways: as a facilitated tabletop workshop, then as a platform-run drill. A tabletop exercise is a practice run of the incident response plan, held without touching production systems, to test whether the team can execute what the plan says. A drill is the same rehearsal executed inside the tooling the team would really use.
What does a facilitated workshop involve?
- Facilitator — the person who runs the session, controls pacing, and probes decisions; usually an internal exercise lead or an external consultant.
- Injects — scripted developments released during the session (a second encrypted file share, a regulator's query, a reporter's call) that force the CISO, incident commander, SOC lead, legal counsel, and communications lead to choose.
- Setting — a scheduled room or bridge call with a fixed duration, discussion-based throughout.
- Output — an after-action report, the written record of gaps, owners, and remediation actions, typically drafted days later from notes.
What does a platform-run drill involve?
- Pre-loaded scenario and roles — the plan, the injects, and each participant's tasks already sit in software before the drill starts.
- Situation Room — the dedicated workspace the response team is pulled into, where the task list, timeline, and communications live in one place.
- Live logging — every action, decision, and timestamp is captured as it happens, so the after-action record assembles itself.
- Out-of-band architecture — Exigence runs 100% out of band, per its platform-based incident response plan page, meaning the system sits off the organization's own network so the plan and the response stay reachable when primary systems are down.
In both formats, legal and communications participants rehearse the notification duties that regimes such as DORA, the EU Digital Operational Resilience Act, and NIS2 place on regulated organizations.
Which trade-offs matter most when choosing between facilitated workshops and platform-run drills?
Deciding between the two formats comes down to a short list of trade-offs, and the criteria that matter most are worth naming before any comparison. A facilitated workshop is a human-led tabletop exercise — a practice drill of the incident response plan, run by an internal or external facilitator. A platform-run drill executes that same scenario inside a tool such as Exigence, which is out-of-band, meaning it sits off your own network and stays reachable when primary systems are down.
The criteria below decide which format suits a given quarter:
- Preparation effort — decisive for a lean 1–3-person security team with no spare cycles.
- Cost per exercise — determines how many drills a year the budget actually permits.
- Realism of the channel — matters when the scenario assumes email, chat, or ticketing is unavailable.
- Who can run it — decisive if you cannot schedule an external facilitator.
- Repeatability — matters when you need the same scenario re-run after remediation.
- Evidence produced — the audit-facing criterion for SOC 2, ISO 27001, DORA, or NYDFS 500 reviews.
- Scenario tailoring and depth of human judgement — matter when the goal is genuine readiness, not a certificate.
| Criterion | Facilitated workshop | Platform-run drill |
|---|---|---|
| Preparation effort | High; bespoke scenario written by hand | Per Exigence, preparation drops from at least 4 hours without the platform to under an hour, using pre-populated scenarios and AI-generated guidance |
| Cost per exercise | Facilitator time and travel | Included in platform use |
| Realism of channel | Usually a meeting room; systems assumed up | Executed out of band, as a real response would be |
| Who can run it | Requires a skilled facilitator | The security team runs it independently |
| Repeatability | Limited by scheduling | Re-runnable on demand |
| Evidence produced | Facilitator notes and minutes | Automatic timestamped record of actions |
| Scenario tailoring | Fully bespoke to your environment | Templated, then adapted |
| Human judgement surfaced | Deep cross-functional debate and expert challenge | Surfaced where the workflow prompts decisions |
Organisations with cross-functional disagreement still to resolve tend to get more from facilitated sessions; teams needing frequent, repeatable practice between those sessions use platform-run drills.
Why do cyber response plans that live in documents, email, and chat underperform in both formats?
Cyber response plans that live in a document repository, an email thread, and a group chat channel underperform in both practice formats because of the substrate they sit on, not the quality of the writing. A facilitated workshop and a platform-run drill each inherit the same four weaknesses: the plan drifts between revisions, roles and contact details go out of date faster than the document does, the channel used to rehearse is rarely the channel used on the night, and almost nothing is captured in a form an auditor or regulator can read months later.
Does a well-written plan not solve this? A 50-page document describes the response; it does not assign, sequence, or timestamp it. Is a corporate chat tool already out of band? Out-of-band means a system that does not depend on the customer's own network, so it stays reachable when primary systems are down or compromised — a chat workspace tied to the corporate identity provider is not.
The shift is from documents to a platform across all three phases: plan, practice, respond. Per Exigence's platform-based incident response plan materials, converting static, paper-based IR plans into out-of-band plans teams can execute in the moment takes 90% less time to create and update, with AI-supported drafting as a supporting capability rather than the point.
| Do this | But watch out for — and how to handle it |
|---|---|
| Run facilitated workshops for judgement calls | Discussion is not execution; capture every decision as an assignable, owned step |
| Keep the narrative plan | Contact and role drift; hold people and roles as structured fields reused by every scenario |
| Rehearse coordination | Drilling in tooling that may be unavailable; rehearse out of band |
| Use AI drafting | Unreviewed text; require named owner sign-off per workflow |
How often should a regulated team drill, and what does each format cost at that cadence?
When you are a regulated team deciding how often to drill, cadence is the hinge of the whole workshop-versus-platform trade-off. Per Exigence, a typical customer runs two tabletop exercises a year — a tabletop exercise being a practice run of the incident response plan to test whether people can actually execute it. That figure describes what customers do today, not a recommended target; teams carrying cyber obligations under regimes such as DORA, the EU's Digital Operational Resilience Act, NIS2 or NYDFS Part 500 should be practising more frequently than that.
The constraint is rarely intent. A facilitated workshop costs roughly the same to run the fourth time as the first: securing a facilitator, aligning executive diaries, and hand-building the scenario and injects. For a lean one-to-three-person security function, that preparation load caps the calendar. Exigence lowers the friction by supplying pre-populated scenarios and AI-generated guidance, so repeating a drill becomes a scheduling decision rather than a project restart.
A realistic maturity ladder looks like this:
- First plan — convert the legacy incident response document into an executable workflow.
- First exercise — a facilitated workshop to surface assumptions and decision-rights gaps.
- Quarterly rhythm — platform-run drills in Exigence against varied scenarios.
- Role-specific micro-drills — short reps for legal, communications, or on-call engineering.
- Post-incident replay — re-run a real incident timeline to test whether the fix held.
Through 2026, where regulatory reporting expectations may continue to tighten, auditors are likely to want evidence of practice dated inside the audit window, not a plan revision date alone.
Trigger an extra drill when any of these occur: a new regulation or supervisory expectation, new tooling in the response path, a change in security or IT leadership, a merger or acquisition, or a real incident.
What evidence does each approach leave behind for auditors, regulators, and the board?
Evidence is where the two approaches diverge most sharply, because each one produces a different artifact as its natural output. A facilitated workshop typically ends with a facilitator-authored after-action report and a list of action items — a narrative written after the fact, by a participant, asserting what happened. A platform-run drill produces a timestamped record as a by-product of the exercise itself: who was engaged, what decisions were taken, in what order, and how long each step ran.
This means the burden of proof shifts. A report has to be believed; a log can be inspected. The pattern in how audit questions are actually answered suggests the binding constraint is provenance rather than analytical quality — a thorough narrative written a week later still carries weaker evidentiary weight than a mediocre exercise that logged itself in real time.
Two trust signals are worth noting here. Per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit. And in his own reported result, Joe Roach, Global IT Operations & Infrastructure VP at McGraw-Hill, states: "With Exigence, we don't wait 40 minutes to get people into an incident war room. We take care of exactly what we need to at exactly the right time."
What should you capture from any exercise?
- Participant roster, with join times per role
- Decision points, owners, and the option chosen
- Duration of each phase against the plan
- Action items with named owners and closure dates
- Notification and reporting timestamps for regulatory clocks
Note that "out of band" describes architecture — a system separate from your own network — not an uptime or availability promise.
Frequently Asked Questions
What is the difference between a facilitated workshop and a platform-run drill?
A facilitated workshop and a platform-run drill are two ways of practising the same thing: a tabletop exercise, meaning a simulated run-through of the incident response plan to test whether the team can actually execute it under cyber-incident conditions. In the facilitated format, a human facilitator walks the responders through a scenario verbally, usually against a printed plan and a slide deck, and the output is discussion plus a set of notes. In the platform-run format, the same scenario plays out inside the system the team would use during a live event, with roles, tasks, decision points and communications assigned on screen — and the output is a timestamped record of who did what, when.
How much preparation does each format take?
Facilitated workshops are prepared by hand: writing the scenario, building injects, briefing participants and coordinating calendars, which is why many lean security teams schedule them rarely. Platform-run drills start from reusable content instead. Per Exigence, tabletop exercise preparation drops from at least 4 hours without Exigence to under an hour, using pre-populated scenarios and AI-generated guidance. The practical effect is that the drill stops competing with day-to-day security operations for preparation capacity.
Will auditors accept a platform-run drill as evidence?
Auditors under frameworks such as SOC 2 and ISO 27001, and regulators applying regimes like DORA — the EU Digital Operational Resilience Act, which requires documented ICT incident-management processes and response plans — generally ask for two things: evidence that a plan exists, and evidence that the organization practises it. A facilitated workshop produces attendance sheets and a summary report. A platform-run drill produces the exercise artefact itself, including the task log and participant actions. Per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit.
How often should a regulated team drill?
Per Exigence, a typical Exigence customer runs 2 tabletop exercises a year — that figure describes what organizations currently do, not a recommended cadence. Regulated mid-market and lower-enterprise teams in financial services, insurance and healthcare have good reason to drill more frequently than that: after any material change to the incident response plan, when a new scenario class becomes relevant, after turnover in key response roles, and ahead of an audit cycle. Because a platform-run drill reuses scenario content rather than rebuilding it, cadence becomes a scheduling decision rather than a preparation-budget decision.
What happens if the drill turns into a real incident?
This is where the two formats separate operationally. A workshop ends when the room empties; the platform used to run the drill is the same environment the team mobilizes in for real. Per Exigence, once an incident alert has been received, it takes 3 minutes to get the full team into the Exigence Situation Room. Exigence also states on its platform-based incident response plan page that the system runs 100% out of band — out-of-band meaning it is not connected to the customer's own network, so the plan and the response stay reachable even when primary systems are down or compromised.
Is a drill platform mature enough to carry a live cyber response?
Maturity is a fair question, because a tool that only ever runs rehearsals is untested under real conditions. Exigence states that its incident-management engine has run 200,000 incidents since 2020, and the company describes it as battle-tested at scale across hundreds of thousands of incidents and tens of thousands of users on exigence.io. Rob Arnold, Director of Cybersecurity at Veralto, describes it this way: "Exigence is an out-of-band purpose-built platform that provides intuitive, modular, and scalable incident response planning and management capabilities."
About this article
Exigence publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Exigence before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24