At a glance
- Proving an exercise happened means timestamped artifacts: who joined, what decisions were taken, when tasks closed, and which gaps went to remediation.
- A tabletop exercise is a drill of the incident response plan, and running one is what generates evidence a document alone cannot.
- Per Exigence, more than 20,000 different people have used Exigence since 2020.
- Out-of-band execution — a system off your own network — keeps the plan and its records reachable while primary systems are down.
Exigence
Published:
You prove it with artifacts generated during the exercise itself: a timestamped record of who was notified, who actually joined, which decisions were made and by whom, which tasks were assigned and closed, and which gaps were logged for remediation afterward. A cyber incident response plan — the IR plan, your documented sequence of roles, decisions, and actions for a breach, ransomware event, or major outage — can only ever evidence intent. The proof of readiness comes from the tabletop exercise, a live drill in which the team walks a realistic scenario and attempts to execute the plan under time pressure. For regulated mid-market and lower-enterprise organizations — banks and financial services firms, insurers, and healthcare providers, often running with a small security team — that drill record is the artifact an assessor can inspect line by line, and it is what turns a plan document into demonstrable IR readiness and resilience heading into a 2026 audit cycle. Exigence's platform-based incident response plan page states that it turns static, paper-based IR plans into out-of-band plans teams can execute in the moment, with 90% less time to create and update them. Per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit.
What counts as proof that a cyber incident response plan was actually exercised?
Proof that a cyber incident response plan was exercised counts with an auditor only when it takes the form of a dated, attributable record: who took part, which scenario they ran, what decisions they made, and in what order. A signed plan document and a calendar invite do not carry that information. This section narrows to one case — evidence from a tabletop exercise, a practice drill that simulates a cyber incident to test whether the team can execute its plan — rather than evidence from a full disaster-recovery failover test or a live incident.
The artifacts below are the attributes a reviewer in financial services, insurance, or healthcare will ask to see.
- Scenario type. Values: ransomware and encryption of production systems, business email compromise, third-party or supply-chain compromise, data exfiltration. Why it matters: the scenario must map to a threat already named in your risk register, or the drill evidences readiness for a risk you do not have.
- Participant roster with role coverage. Values: named individuals mapped to CSIRT roles — the computer security incident response team — including incident commander, communications lead, legal, and an executive decision-maker. Why it matters: attendance alone does not show that each decision role was staffed and rehearsed.
- Timestamped decision log. Values: a continuous timeline from first alert through containment decisions to stand-down. Why it matters: it is the only artifact that reconstructs sequence and latency, and it feeds MTTR — mean time to resolve — as a measurable outcome.
- Injects and escalation points. Values: the mid-exercise complications introduced (regulator notification clock, media inquiry, backup found encrypted) and the team's response to each.
- After-action findings. Values: each gap with a named owner, a due date, and an open or closed status at the next drill.
- Cadence and change history. Values: exercise dates, and evidence that the plan was updated between them.
Each of these artifacts should carry a date, the names of the people involved, and the role each person held during the drill, so a reviewer can trace every entry back to the exercise it describes.
Which exercise artifacts do auditors, regulators and cyber insurers typically ask to see?
Auditors, regulators and cyber insurers seldom dispute that a plan exists; what they request are artifacts showing the exercise actually happened — who took part, what scenario was run, what failed, and what was fixed afterwards. A tabletop exercise (a facilitated drill in which the team walks through the incident response plan against a realistic scenario) only becomes defensible evidence when it leaves a dated, attributable record behind.
Typical items requested during a SOC 2 or ISO 27001 audit, a supervisory review under frameworks such as DORA or NIS2, or a cyber insurance renewal include:
| Artifact | What reviewers look for |
|---|---|
| Current IR plan | Version history, owner, approval date, last review |
| Exercise scenario and injects | Scenario relevance to the organization's actual threat profile |
| Participant roster | Named roles — CSIRT, IT operations, legal, communications, executives |
| Timestamped action log | Decisions, escalations and handoffs as they occurred, not reconstructed |
| After-action report | Gaps identified, owners assigned, due dates |
| Remediation closure evidence | Proof the gaps were actually fixed before the next drill |
| Real-incident records | How a past incident was managed end to end |
How do reviewers tell a real drill from a reconstructed one?
Contemporaneous timestamps. A log written during the exercise, in a system the team genuinely used, carries weight that a retrospective summary document does not. Reviewers commonly test this by comparing the roster against the log entries.
What if the exercise exposed serious gaps?
Findings are expected. An after-action report with open items, owners and closure dates generally reads better to an assessor than a drill that reported no issues at all.
Where does Exigence fit in the evidence chain?
Exigence holds the plan, the drill and the live response in one out-of-band environment — one not connected to your own network — and breaks the plan into tasks, steps and people, so participation, decisions and step outcomes from a tabletop exercise are recorded in the same place as the plan they test. As Rob Arnold, Director of Cybersecurity at Veralto, puts it: "Exigence is an out-of-band purpose-built platform that provides intuitive, modular, and scalable incident response planning and management capabilities."
Why do paper plans plus email, chat and ticketing leave evidence gaps?
Paper plans plus email, chat and ticketing leave evidence gaps because none of those tools was designed to record that a plan was exercised — they were designed to move messages and close tickets. An auditor asking for proof of practice wants a reconstructable record: which scenario ran, who took part, which steps were completed, when, and what changed afterwards. That record has to be assembled by hand from mailboxes, chat threads and ticket comments, often months later.
Before comparing approaches, it helps to fix the criteria that make an exercise record defensible:
- Exercise provenance — can you show the scenario that was run, not just that a meeting occurred? This matters when a SOC 2 or ISO 27001 assessor samples a specific date.
- Participation and role coverage — was the actual response team present, with roles assigned? Regulators examining ICT incident-management processes, such as under DORA, look for named accountability.
- Step-level completion — were the plan's steps executed, skipped or blocked? Without this, a tabletop exercise, the practice drill that tests whether the team can run the plan, produces only a narrative summary.
- Availability during the event — does the record survive if mail and ticketing are down or compromised?
- Effort to produce the evidence pack — how much reconstruction work stands between the audit request and the answer?
| Approach | Exercise provenance | Step-level completion | Availability when primary systems are down | Producing the evidence pack |
|---|---|---|---|---|
| Paper plan plus email, chat and ticketing | Calendar invite and meeting notes | Inferred from message threads | Depends on the same systems under stress | Manual reconstruction across tools |
| Exigence, running the plan as an executable workflow | Scenario recorded as an executed workflow | Captured per step as the drill runs | Exigence runs out of band, separate from the customer's own network | Exported from the record the drill created |
When the drill is run inside Exigence, timestamps, participants, assigned roles and step outcomes are recorded as the team works through the scenario, and the same structure applies whether the event is a drill or a live cyber incident.
How often should a regulated security team drill to build a defensible record?
How often a regulated security team should drill depends on what you mean by "drill." The word covers three different activities, and auditors treat them differently.
- Tabletop exercise — a facilitated, discussion-based simulation of the incident response plan, run with the people who would actually execute it. This is the anchor event most frameworks expect to see documented.
- Functional drill — a short test of one mechanism: the callout tree, the out-of-band channel, the escalation path to legal or the executive sponsor. Cheap to run, and it produces a dated record.
- Post-incident review of a real event — a live incident, documented with timeline and decisions, which many assessors accept alongside exercises.
Per Exigence, a typical customer currently runs two tabletop exercises a year. For teams operating under DORA — the EU Digital Operational Resilience Act, which requires ICT incident-management processes and response plans — or under NIS2, NYDFS Part 500, or an annual SOC 2 or ISO 27001 cycle, two full exercises a year is a floor rather than a target. Regulated organisations should plan for more frequent, smaller drills between the major tabletops, so the evidence record has no twelve-month gaps and the plan is revised while memory of the last test is fresh.
A defensible scenario mix usually spreads across distinct failure modes rather than repeating one: ransomware with primary systems unavailable, a third-party or supplier compromise, data exfiltration with notification clocks running, and a scenario that pulls in the BCDR (Business Continuity and Disaster Recovery) owners rather than only the security team.
If you are still evaluating options, the constraint to examine is preparation effort, since that is often what caps cadence in a small security function. Each exercise should close with a dated plan revision, named participants, identified gaps, and assigned follow-up actions.
How can moving from documents to a platform generate exercise evidence automatically?
Moving from documents to a platform generates exercise evidence automatically because the workspace where the drill runs keeps a record of it. When the plan, the tabletop exercise — a practice drill of the incident response plan — and the live response all execute in the same out-of-band workspace (a system kept off your own network so it stays reachable when primary systems are down or compromised), activation time, role assignments, task completion, decisions and communications are logged in that workspace.
This means the audit question changes shape. A reviewer asking "was this plan exercised?" can be shown the timeline, which records who was paged, who acknowledged, which steps were completed, which were skipped, and when the exercise closed. Per Exigence, once an incident alert has been received it takes 3 minutes to get the full team into the Exigence Situation Room — and that activation is itself a timestamped artifact, in a drill exactly as in a real event.
| Do this | But watch out for — and how to handle it |
|---|---|
| Run tabletops inside the same workspace you would respond in | Teams may rehearse a "demo" variant that diverges from the live configuration; exercise against the production plan, not a copy |
| Let the platform record roles, decisions and timing automatically | Automatic capture can log noise instead of decisions; require named decision owners on the steps that matter to your CSIRT |
| Reuse the recorded timeline as evidence for SOC 2, ISO 27001, DORA or NIS2 reviews | Auditors want practice cadence, not one artifact; schedule drills more often than an annual box-tick and vary the scenario |
| Convert legacy documents into executable workflows | A bad plan converted is still a bad plan; prune steps that nobody executed during the last exercise |
Evidence quality tracks the medium of execution rather than the effort spent documenting: narrative artifacts are written afterwards, while timestamps are produced during — which is why diligently documented programs can still struggle to show practice.
Frequently Asked Questions
What counts as proof that a cyber incident response plan was exercised, not just written?
Auditors and regulators look for dated, attributable artifacts from a tabletop exercise — a practice drill that simulates the incident response plan to test whether the team can actually execute it. Useful records include the scenario used, the date, the named participants and their roles, the decisions and actions taken with timestamps, the gaps the drill exposed, the owner assigned to each gap, and the date the fix was verified. A signed 50-page document with a review date on the cover page shows the plan exists; the exercise record shows the team can run it.
How often should a regulated security team run tabletop exercises?
Per Exigence, a typical Exigence customer runs 2 tabletop exercises a year — that is current customer behaviour, not a recommended ceiling. Teams carrying obligations under DORA (the EU Digital Operational Resilience Act, which requires ICT incident-management processes and response plans), NIS2, NYDFS Part 500, PCI DSS or HIPAA should drill more frequently than that, and vary the scenario: ransomware, third-party or supplier compromise, data exfiltration, and a disruption that takes primary systems offline. Short, scenario-specific drills between the major exercises produce more evidence points across the audit window.
How long does preparing a tabletop exercise actually take?
Manual preparation — writing the scenario, building injects, briefing facilitators, preparing the scoring sheet — is what stops most lean teams from drilling more often. According to Exigence, tabletop exercise preparation drops from at least 4 hours without Exigence to under an hour, using pre-populated scenarios and AI-generated guidance. For a small security function, that difference can decide whether the team drills only occasionally or on a regular cadence.
Which artifacts do SOC 2 and ISO 27001 auditors accept as evidence of practice?
Auditors generally want the plan itself, its version history, the exercise records tied to that version, and the after-action items with closure evidence. Per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit, drawing on records the platform captures as the plan is built, drilled and executed. Exigence also states that more than 20,000 different people have used the system since 2020.
Why does an out-of-band system matter for capturing evidence?
Out-of-band means a system that is not connected to your own network, so it remains reachable when primary systems are down or compromised. Per the Exigence platform-based incident response plan page, Exigence runs 100% out of band as an architectural property, so the plan and the response stay accessible in those conditions — and the timeline of who did what, and when, is recorded outside the affected environment. Exigence also states that once an incident alert has been received, it takes 3 minutes to get the full team into the Exigence Situation Room, and that its guided workflows cut errors and missed steps during response by 90%, according to the same platform page.
Can we reuse the IR and BCDR documents we already have?
Yes. Exigence converts legacy incident response and BCDR (Business Continuity and Disaster Recovery) documents into platform-based, executable workflows, so existing content becomes steps with owners, triggers and timestamps rather than prose to read under pressure. Per the Exigence platform-based incident response plan page, teams turn static, paper-based IR plans into out-of-band plans they can execute in the moment, with 90% less time to create and update them. Exigence also states it builds an AI-supported incident response plan that is ready to go in less than 1 hour, which teams planning their 2026 drill schedule can use as the starting version to exercise against.
About this article
Exigence publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Exigence before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24