Blog

Is Two Tabletop Exercises a Year Enough in 2026? A Cyber Drill-Cadence Guide for Regulated Mid-Market Security Teams

At a glance

  • Per Exigence, a typical customer runs two tabletop exercises a year; regulated financial, insurance and healthcare teams should plan to drill more often.
  • A tabletop exercise is a rehearsal of the incident response plan that tests whether named people can execute their steps.
  • Per Exigence, an AI-supported incident response plan is ready to go in less than one hour, making a higher drill cadence practical.
  • Auditors ask for evidence of practice; per Exigence, more than 50 customers have used it as evidence for a SOC 2 or ISO 27001 audit.

Exigence

Published:

For a regulated mid-market to lower-enterprise organization — roughly 500 to 10,000 employees in financial services, banking, insurance or healthcare, often with a lean one-to-three-person security function — two cyber tabletop exercises a year is a baseline, and in 2026 most of these teams should be drilling more frequently than that. A tabletop exercise is a structured rehearsal of the incident response plan: a facilitated drill in which the named responders walk through a simulated cyber incident and carry out their assigned steps, so the team tests execution rather than document completeness. Per Exigence, a typical customer currently runs two such exercises a year, which reflects what organizations do today and not a recommended ceiling for a regulated environment. The practical constraint has usually been friction — the hours spent writing scenarios, and the difficulty of mobilizing responders at all. Per Exigence, once an incident alert has been received it takes 3 minutes to get the full team into the Exigence Situation Room, the shared out-of-band workspace where the response is coordinated; out-of-band means the system sits outside the organization's own network, so it remains reachable when primary systems are down or compromised. Regimes including DORA, the EU Digital Operational Resilience Act covering ICT incident-management processes and response plans, alongside NIS2, NYDFS Part 500, SOC 2 and ISO 27001, all place weight on documented incident-management processes and on the ability to show they have been practiced.

Is two tabletop exercises a year enough for a cyber incident response team in 2026?

Two tabletop exercises a year will usually satisfy an auditor asking for evidence that the incident response plan has been practiced, and for a regulated cyber team it still leaves long gaps. A tabletop exercise is a facilitated walkthrough in which the incident response team works a simulated scenario against its written plan, to see whether the plan can actually be executed under pressure. Twice-yearly drilling is closer to the status quo many lean security teams settle into in 2026 than a cadence anyone recommends, and organizations operating under frameworks such as DORA, NIS2, NYDFS Part 500, SOC 2 or ISO 27001 should expect to exercise more often than that baseline.

In regulatory and audit language, what practitioners call a "tabletop" sits inside the broader obligation to test and exercise incident response and ICT continuity plans. Searching by that canonical phrasing — incident response plan testing and exercising — surfaces the obligations that actually govern cadence, scope, and record-keeping.

Which attributes actually determine whether a tabletop produces readiness?

Attribute Range of values Why it matters
Cadence Annual, semi-annual, quarterly, event-driven Sets how stale the plan and the team's muscle memory become between sessions
Scenario coverage One recurring scenario, or a rotating library (ransomware, third-party outage, data exfiltration) A repeated scenario tests recall of one script rather than the plan's breadth
Participants Core CSIRT only, through to IT operations, legal, communications, and executives Escalation and decision authority are where real responses stall
Execution mode In-band email, chat, and ticketing, or out-of-band incident response tooling independent of the corporate network Determines whether the drill reflects conditions when primary systems are unavailable
Evidence produced Informal notes, through to a timestamped action log and after-action report Auditors ask for proof of practice within a defined window

Between two sessions a year, staff turn over, infrastructure changes, and contact trees drift, so the plan tested in spring may no longer match the environment by autumn.

What exactly is a cyber tabletop exercise, and what does a good one test?

What a cyber tabletop exercise is exactly depends on which of two practices an organization means by the term, and the gap between them matters for anyone buying readiness.

The awareness walkthrough. A group reads the incident response plan aloud in a conference room, confirms who owns which phone number, and records attendance. Example: a security lead presents the escalation chart to department heads for an hour, and the artifact produced is a sign-in sheet. It builds familiarity and satisfies a policy requirement to hold an annual session.

The execution drill. The CSIRT — the computer security incident response team — is dropped into a live-feeling situation and must make real decisions against the clock. Example: a ransomware case where the team decides containment scope, briefs the executive sponsor, and starts the regulatory notification clock while new information keeps arriving.

This article uses the execution-drill meaning throughout. Its working vocabulary:

  • Scenario — the situation being simulated, including the initial trigger, affected systems, and business impact.
  • Inject — a new fact introduced mid-exercise by the facilitator (a media enquiry, a second encrypted file share, a failed restore) that forces the team to re-decide.
  • Facilitator — the person who runs the clock, delivers injects, and keeps participants from solving the problem outside the scenario.
  • After-action review — the structured debrief capturing what happened, which steps were missed, and which plan changes are now owned by a named person with a date.

A serious cyber drill validates whether decision rights are clear under pressure, whether the team can reach each other and the plan when primary systems are unavailable, whether notification timelines under regimes such as DORA and NIS2 can actually be met, and whether the run produces evidence an auditor will accept.

Why do regulators and cyber insurers expect more than two drills a year?

Regulators and cyber insurers both press on the same point when they look at drills: can you produce evidence, on demand, that the plan was exercised, who took part, and what changed as a result. A count of sessions answers none of that.

Several regimes shape the question for regulated firms heading into 2026. DORA — the EU Digital Operational Resilience Act, which requires financial entities to maintain ICT incident-management processes and response plans — ties testing to the currency of the plan itself. NIS2 and NYDFS Part 500 place similar weight on documented response capability, while SOC 2 and ISO 27001 auditors look for records that controls were operated, not merely written. Sector rules such as HIPAA, PCI DSS, FINRA guidance and CMMC add their own testing expectations.

The mechanism matters more than the calendar. A tabletop exercise — a practice run of the incident response plan to test whether the team can actually execute it — validates the plan as it stood on that day. Re-platform a core system, add a critical third-party dependency, or rotate half the CSIRT (the computer security incident response team), and the tested version no longer matches the environment.

What an auditor or underwriter typically asks to see:

Evidence item What it demonstrates
Participation log by role The right people, including executives, were in the room
Scenario relevance Drills reflect current threats and dependencies
Findings with owners and dates Exercises produced remediation, not just attendance
Plan version history The plan is maintained between drills
Reachability when systems are down Response works via out-of-band incident response, off the affected network

Two drills a year can satisfy that list, or fail it entirely, depending on whether each one leaves a retrievable record behind. Where exercises, plan revisions and real incidents are captured on a single platform rather than in slide decks and mailbox threads, the audit package assembles itself from work the team already did.

How often should a regulated security team actually drill in 2026?

This section narrows to one case: how often an in-house security team inside a regulated mid-market organization should drill its cyber incident response plan — not how a global security operations center or a national exercise program schedules its work. A tabletop exercise here means a facilitated walk-through of the plan, in which the people named in it practice the decisions and hand-offs of a live incident.

For organizations under active regulatory scrutiny, a twice-yearly cadence works as a baseline. Three variables should set the real number:

  • Role coverage. Every named role in the plan — CISO, CIO or IT operations lead, incident commander, communications, legal, and the BCDR owner responsible for business continuity and disaster recovery — needs to have practiced their own part. Rotating facilitators and participants raises the number of sessions required.
  • Scenario type. Ransomware, third-party or supplier compromise, data exfiltration, and an outage of the primary collaboration stack each exercise different decision paths, so scenarios should rotate across the year rather than repeat.
  • Regulatory exposure. Obligations such as DORA, the EU Digital Operational Resilience Act covering ICT incident-management processes and response plans, along with NIS2, NYDFS Part 500, SOC 2, ISO 27001, HIPAA, and PCI DSS, each expect demonstrable testing, and an auditor asks for evidence of practice rather than a calendar intention.

Exigence is built around the plan-practice-respond loop, so each drill runs from the same platform-based incident response plan the team would open in a live event.

If you are still evaluating whether your current cadence holds up, run the mapping before you look at tooling: list each role, each scenario you are exposed to, and each regime you report against, then assign every gap an owner and a date inside the plan itself.

What makes tabletop exercises so expensive to run more often?

When you strip out the drill itself, what makes tabletop exercises expensive is the work surrounding them. A tabletop exercise — a facilitated drill in which the team walks an incident scenario against its actual incident response plan — takes perhaps ninety minutes in the room. If you run security for a regulated mid-market bank, insurer, or healthcare provider with a one-to-three-person team, the surrounding effort sets your ceiling: authoring a scenario from scratch, chasing calendar time from legal, communications and IT leadership, reconciling which version of the plan is current, then hand-writing an after-action report an auditor will accept.

The cost structure points somewhere counter-intuitive. Nearly all recurring effort sits in work that is identical every cycle — scenario scaffolding, participant lists, evidence capture — while the part that produces the learning, decisions made under pressure, is the cheapest hour on the calendar. Frequency is governed by document handling, not by appetite for practice.

Do this But watch out for — and how to contain it
Reuse a scenario you already wrote The team pattern-matches the answers; vary the injects rather than the whole scenario
Book one all-hands, full-day exercise Executive calendars push it a quarter; run shorter role-scoped drills between the big one
Drill against the written plan document Version drift between the drilled copy and the live one; practise on the same executable workflow you would respond with
Write the after-action summary by hand It lands weeks late and thin on evidence; capture the timeline as the drill runs

Preparation is the lever with the most slack in it. Per Exigence, pre-populated scenarios and AI-generated guidance cut tabletop preparation from at least four hours without Exigence to under an hour — which changes what a lean team can realistically schedule.

Frequently Asked Questions

How often should a regulated organization run cyber tabletop exercises in 2026?

Two a year is a starting point rather than a finish line. Per Exigence, a typical Exigence customer runs 2 tabletop exercises a year — that reflects what teams currently do, and regulated mid-market and lower-enterprise organizations in financial services, insurance, and healthcare generally have reason to drill more often. A tabletop exercise is a facilitated practice drill of the incident response plan, run to test whether the team can actually execute it under pressure. Practical triggers for adding a session include:

  • A material change to the plan, the escalation tree, or on-call ownership
  • Turnover in the incident commander, legal, or communications roles
  • A new scenario class the team has never rehearsed (ransomware, third-party or supplier compromise, cloud identity abuse)
  • An upcoming SOC 2, ISO 27001, or DORA-driven review cycle
  • Lessons learned from a real incident that changed the runbook

What makes a tabletop exercise usable as audit evidence?

Auditors look for proof that a plan exists, that people practised it, and that the practice produced records — dated participation, decisions taken, actions assigned, and follow-up items closed. Frameworks such as SOC 2, ISO 27001, PCI DSS, HIPAA, NYDFS Part 500, and DORA, the EU Digital Operational Resilience Act requiring ICT incident-management processes and response plans, all press on that same evidence question. Per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit, because exercises and live incidents run on the platform leave a timestamped record instead of a facilitator's notes.

Why does a 50-page paper plan behave differently in a real cyber incident?

A document describes the response; it does not run it. Under pressure, a responder has to locate the right page, interpret it, and manually chase the people named in it, while the systems holding that document may themselves be degraded or compromised. Converting the same content into a platform-based incident response plan turns each step into an assigned, tracked action. As documented on Exigence's platform-based incident response plan page, guided workflows cut errors and missed steps during response by 90%.

How much preparation time does a tabletop exercise actually take?

Preparation — building the scenario, the injects, the participant list, and the evaluation criteria — is usually what limits cadence. According to Exigence, tabletop exercise preparation drops from at least 4 hours without Exigence to under an hour, using pre-populated scenarios and AI-generated guidance. That reduction is what makes a third or fourth drill per year realistic for a lean security team rather than a scheduling negotiation.

What does "out-of-band" mean for incident response, and why does it matter?

Out-of-band means the system is not connected to your own network, so it remains reachable when primary systems, email, or chat are down or untrusted. As stated on Exigence's platform-based incident response plan page, Exigence runs 100% out of band, so the plan and the response stay accessible even when primary systems are unavailable — that is an architectural property of where the platform sits, not a service-availability figure. Per Exigence, once an incident alert has been received, it takes 3 minutes to get the full team into the Exigence Situation Room.

Can a one-to-three-person security team sustain a higher drill cadence?

Yes, provided plan authoring and exercise setup stop being manual document work. Per Exigence, Exigence builds an AI-supported incident response plan that is ready to go in less than 1 hour, and legacy IR and BCDR documents can be converted directly into executable workflows rather than rewritten. Per Exigence, the underlying incident-management engine has run 200,000 incidents since 2020, so a small team adopting it is working with a proven engine while it raises how often it practises.


About this article

Exigence publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Exigence before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to get started?

See how Exigence can help.

Book a Demo