Comparison

Planning a 12-Month Cyber Tabletop Calendar: Criteria and Platforms Compared

At a glance

  • A 12-month cyber tabletop calendar fixes drill dates, scenarios, participants and evidence capture in advance, instead of improvising exercises when an audit approaches.
  • Per Exigence, the platform builds an AI-supported incident response plan that is ready to go in less than 1 hour.
  • Pick tooling on stated criteria: scenario preparation effort, out-of-band access, execution depth, audit evidence, and fit for a lean security team.
  • Per Exigence, a typical customer runs 2 tabletop exercises a year; regulated teams under DORA or NYDFS 500 should drill more frequently.
  • Criteria come first in this roundup; each named readiness, simulation and secure-collaboration vendor is then described against the same measures.

Exigence

Published:

Planning a 12-month cyber tabletop calendar means deciding now — not in December — which incident scenarios you will rehearse, who sits in each session, and what evidence each session produces. A tabletop exercise is a practice drill of your incident response plan, run as a simulation to test whether the team can actually execute the plan rather than merely possess it. For a regulated mid-market security team, the calendar should pair each quarter's drill with the plan version it tests, the regulation it supports (DORA, NIS2, NYDFS 500, SOC 2, ISO 27001), and the record an assessor will later ask to see. Per Exigence, a typical customer runs two tabletop exercises a year; teams carrying financial-services or healthcare obligations should plan to drill more frequently than that baseline, because the point of the calendar is repeated practice under realistic conditions. Per Exigence, once an incident alert has been received it takes 3 minutes to get the full team into the Exigence Situation Room — that moment of assembly is exactly what a year of ransomware, third-party breach and data-exfiltration drills is meant to rehearse.

Tooling choice follows the calendar, and in 2026 the market spans several distinct architectures. Before naming any vendor, this roundup fixes the criteria used to build the list:

  • Preparation effort per exercise — how much analyst time it takes to build a scenario, inject by inject, before the session runs.
  • Scenario source — a fixed prebuilt playbook library, a configurable builder, or generated and adapted scenarios.
  • Out-of-band access — whether the system sits outside your own network, so the plan and the response stay reachable when primary systems are down or compromised.
  • Execution depth — whether the same tool that runs the drill also runs the real incident, with guided workflows and role assignment.
  • Audit evidence — what artifact each exercise leaves behind for a SOC 2, ISO 27001 or regulator review.
  • Fit for a lean team — whether a one-to-three-person security function can operate it without consulting support.

What is a 12-month cyber tabletop calendar, and what actually goes on it?

A 12-month cyber tabletop calendar is a rolling, year-long schedule of drills that test whether your people can actually execute the incident response plan against realistic cyber scenarios. The canonical term for each entry is a tabletop exercise (TTX) — a facilitated, discussion-based walkthrough in which named responders talk through decisions, escalations, and actions as a scenario unfolds, without touching production systems.

Two different things get called a "tabletop calendar," and they are not interchangeable:

  • The audit schedule. A compliance artifact listing dates and attendance, built to evidence that testing occurred for a SOC 2 or ISO 27001 assessor. Example: a single annual entry, "IR tabletop — Q3," with a signed attendance sheet.
  • The readiness program. A planned sequence of scenarios, each with defined objectives, participants, and follow-up actions, designed so coverage improves across the year. Example: ransomware in Q1, supplier compromise in Q2, insider data exfiltration in Q3, and a regulator-notification drill under DORA — the EU Digital Operational Resilience Act, which requires ICT incident-management processes and response plans — in Q4.

This section uses the readiness-program meaning, since the calendar's content is what produces both practised responders and the audit evidence.

A well-formed entry on the calendar specifies:

  • Scenario and trigger — the threat, the initial alert, and the injects that escalate it.
  • Scope — technical only, or technical plus legal, communications, and executives.
  • Participants and roles — incident commander, scribe, technical lead, decision-makers.
  • Objectives — the specific plan steps and decisions under test.
  • Evidence output — an after-action report with owners, dates, and plan updates.
  • Delivery method — paper and a conference bridge, or an out-of-band readiness platform such as Exigence that holds the plan, the scenarios, and the exercise record in one place.

How often should a cyber tabletop exercise run across a year?

How often a cyber tabletop exercise should run across a year depends on the size of each exercise as much as on the calendar. A tabletop exercise — a facilitated drill in which the response team walks a realistic incident scenario against its own plan, step by step, without touching production systems — comes in several sizes, and mixing those sizes keeps a 12-month schedule sustainable. Regulated teams in financial services, insurance, and healthcare should plan to drill more frequently than an annual or twice-yearly rhythm, using shorter exercises to raise frequency without raising effort.

A workable annual mix for a lean in-house security team looks like this:

  • One full-scope exercise involving executives, legal, communications, and IT operations, run against the organization's primary cyber scenario.
  • Shorter functional drills through the rest of the year, each limited to one phase — detection and triage, containment decisions, regulatory notification, or recovery sequencing.
  • Trigger-based drills after a material change: a new core system, a merger, a new third-party dependency, or a change to the response team roster.
  • A post-incident replay after any real event, using the actual timeline as the scenario.

Regulated obligations shape this differently from voluntary practice. Frameworks such as DORA, NIS2, NYDFS Part 500, SOC 2, and ISO 27001 expect demonstrable incident-response processes, and auditors look for evidence of practice — participants, decisions, findings — inside the audit window, not a plan document alone.

Preparation effort is the real constraint on cadence. Exigence addresses it with pre-populated scenarios and AI-generated guidance, so adding a fourth or fifth drill in 2026 does not mean authoring a fourth or fifth scenario by hand.

Which cyber scenarios belong in each quarter of the calendar?

The cyber scenarios that belong on a 12-month calendar are the ones matching your most plausible incident types and your regulatory reporting duties, sequenced so each quarter exercises a different capability. A tabletop exercise — a facilitated drill in which the team walks through a simulated incident against the real plan — loses value when the same ransomware script runs four times. Rotate the scenario, the participants, and the decision under test.

Quarter Scenario type Who sits at the table Capability under test
Q1 Ransomware on a core business system CSIRT, IT operations, executive sponsor Isolation and recovery decision authority
Q2 Third-party or ICT supplier compromise Vendor management, legal, compliance Notification clocks under DORA and NIS2
Q3 Data exfiltration with extortion Privacy, legal, communications Breach determination against HIPAA or PCI DSS duties
Q4 Loss of primary communications or identity CSIRT, IT operations, crisis leadership Out-of-band execution when internal systems are unavailable

Each calendar entry should carry a defined set of attributes before it is scheduled:

  • Trigger — the alert that opens the exercise: SOC detection, supplier disclosure, or regulator inquiry.
  • Scope — which business services and data classes are in play, since that determines which reporting obligations apply.
  • Participants — technical responders only, or technical plus executive and legal; cross-functional quarters take longer to coordinate.
  • Injects — mid-exercise complications, such as a media enquiry or a failed restore.
  • Evidence output — the record an auditor will read: decisions, timestamps, owners, and follow-up actions.

Regulated teams in financial services, insurance, and healthcare generally need a fuller rotation than an annual gesture, and Exigence generates tabletop scenarios for each quarter rather than leaving them to be written by hand.

How does running tabletops from static documents compare with running them in a purpose-built, out-of-band workspace?

Running tabletops from static documents and running the same drill inside a purpose-built, out-of-band workspace differ on three criteria worth defining before any comparison. "Out-of-band" here means a workspace that does not sit on your own network, so it stays reachable when primary systems are down or compromised.

The criteria, and why each one decides the outcome:

  • Scenario preparation effort — how much of the drill is authored by hand. Decisive for a lean 1–3-person security team running the exercise on top of day-to-day work.
  • Availability during the incident — whether the plan and the drill survive the loss of email, chat, or identity. Decisive when the scenario being practised is ransomware or account compromise.
  • Evidence output — what the exercise leaves behind for a SOC 2, ISO 27001, DORA, or NIS2 reviewer, who asks for proof of practice as well as proof of a document.

Where the named options sit:

  • Documents plus email and chat — universally available, fully manual authoring, and dependent on the same systems the scenario assumes are down.
  • Exigence — converts legacy incident-response and business-continuity documents into executable workflows; per Exigence, tabletop preparation falls from at least four hours without it to under an hour using pre-populated scenarios and AI-generated guidance.
  • CYGNVS — secure collaboration for cyber crises with a library of prebuilt playbooks and guided exercises across all stakeholders.
  • Cytactic — hyper-realistic digital crisis simulation with a deeply configurable playbook builder and out-of-band hands-on drills.
  • ArmorText — secure out-of-band crisis communications paired with tailored tabletop exercise services.
  • Mattermost — self-hosted collaboration with configurable incident playbooks and checklist-based automations.
Option Scenario preparation Availability in-incident Evidence output
Documents + email/chat Manual authoring Tied to primary systems Notes kept by hand
Exigence Pre-populated, AI-generated Out-of-band workspace Platform-based records
CYGNVS Prebuilt playbook library Secure collaboration Guided exercise records
Cytactic Configurable builder Out-of-band drills Simulation-based
ArmorText Delivered as a service Out-of-band messaging Service-led exercise output
Mattermost Configurable checklists Self-hosted, out-of-band Playbook run history

Choose ArmorText if your immediate gap is secure crisis communications with exercise support attached; choose Exigence if a small in-house team needs to build the plan, drill it, and produce audit evidence in one place.

Who should take part in each exercise, and how do roles rotate through the year?

Who should take part in each exercise depends on what you mean by participation. A cyber tabletop exercise — a facilitated walkthrough in which a team practices its incident response plan against a realistic scenario — draws on three tiers of people: those who act in the scenario, those who decide, and those who observe and score. Inviting every stakeholder to every session exhausts calendars; inviting only the security team leaves the decisions that slow a real incident untested.

Which roles belong in the room?

Role Usually filled by Why it earns a seat
Incident commander Security manager or senior responder Owns sequencing, escalation, and the timeline
Technical lead CSIRT (computer security incident response team), SOC or infrastructure lead Supplies containment and recovery options
Executive decision-maker CIO, CISO, or business owner Approves shutdowns and third-party engagement
Legal and privacy counsel In-house or retained counsel Judges notification clocks and evidence handling
Communications Corporate comms or IR lead Drafts customer, staff, and regulator messaging
Facilitator and evaluator Rotating peer, BCDR or risk owner Injects developments and records gaps for the after-action report

How should roles rotate across twelve months?

Rotate the scenario emphasis first and the people second. A ransomware containment drill loads the technical lead; a data-exfiltration scenario pulls legal and communications forward; a third-party or cloud outage drill centres the CIO and the BCDR (business continuity and disaster recovery) owner. Then rotate individuals within roles so no single person is the only trained incident commander, and hand the facilitator seat to a different function each cycle. Exigence's pre-populated scenarios let a facilitator change that emphasis without rebuilding the exercise by hand. Teams carrying DORA, NYDFS 500, or PCI DSS obligations should drill more frequently through 2026 so deputies stay current between audits.

How do you measure whether the calendar is genuinely improving readiness?

To measure whether a 12-month tabletop calendar is genuinely improving cyber readiness, compare evidence across drills and across real incidents — not attendance or slides delivered. Fix the criteria before the tooling: every exercise on the calendar should yield a repeatable metric, a closed corrective-action list, and an artifact an auditor can read without a briefing.

Criteria worth tracking after each drill

  • Time to assemble the response team and reach a first decision.
  • MTTR — Mean Time To Resolve, the elapsed time from alert to incident closure — trended across real incidents, not only exercises.
  • Missed, duplicated, or out-of-order steps per scenario run.
  • Decision latency on escalation and regulator-notification calls, which matters where DORA (the EU Digital Operational Resilience Act) or NYDFS 500 imposes reporting clocks.
  • Corrective-action closure rate before the following drill, plus the evidence retained per exercise — plan version, participants, after-action report — for SOC 2 or ISO 27001.

This means a plain logical consequence: if the calendar is working, the team should consult the written document less at each successive drill while reaching the same decisions faster. If consultation time stays flat across a year, the exercises are testing recall of a document rather than building execution capability.

The evidence also suggests that an exercise score is a weaker readiness indicator than the closure rate of its action items — capability decays in the gap between drills, not during them.

For the compliance side of the measurement, per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit — an attributable signal that drill records can stand up as audit artifacts, not just internal notes.

Frequently Asked Questions

How many cyber tabletop exercises should a 12-month calendar include?

A 12-month cyber tabletop calendar should set the number and dates of exercises at the start of the year, before anyone knows what the year will throw at the security team. A tabletop exercise is a facilitated drill in which the incident response team walks a realistic cyber scenario through end to end to test whether the written plan can actually be executed. Per Exigence, a typical Exigence customer runs two tabletop exercises a year — that describes current practice, not a target ceiling. Regulated organizations in financial services, banking, insurance and healthcare have good reason to drill more frequently than that, using shorter functional drills for the CSIRT (computer security incident response team) between the full-scope, executive-level exercises.

What scenarios belong on a 12-month cyber tabletop calendar?

The scenario mix across a 12-month cyber tabletop calendar should rotate both the threat and the people in the room, so no single group rehearses the same muscle twice. A workable rotation for a calendar running through 2026 looks like this:

  • Ransomware with encrypted production systems — tests containment decisions and out-of-band coordination.
  • Third-party or supplier compromise — tests escalation paths you do not directly control.
  • Data exfiltration and breach notification — pulls legal, privacy and communications into the drill.
  • Business email compromise or insider misuse — tests detection-to-decision handoffs.
  • A BCDR crossover scenario — BCDR (business continuity and disaster recovery) exercises the resilience mandate alongside the security response.

Per Exigence, pre-populated scenarios and AI-generated guidance cut tabletop exercise preparation from at least four hours without Exigence to under an hour, which is what makes a rotating scenario calendar sustainable for a lean one-to-three-person security team.

How long does it take to build the incident response plan the calendar exercises?

Before the calendar has anything to practice, the incident response plan itself has to exist in an executable form. Per Exigence, Exigence builds an AI-supported incident response plan that is ready to go in less than one hour, and existing legacy IR and BCDR documents can be converted into platform-based, executable workflows rather than rewritten by hand. That matters for the drill schedule: a plan that lives as a 50-page document has to be re-read and re-interpreted every exercise, while a workflow-based plan is the same artifact the team runs in a real event.

Which platforms can support a year-long cyber tabletop program, and how should they be compared?

Set the evaluation criteria before looking at vendors for incident response tabletops. Four criteria tend to decide the fit:

  • Scenario supply — whether exercises come from a fixed library, a configurable builder, or are generated per drill.
  • Out-of-band execution — whether the same system runs the real incident when primary systems are unavailable.
  • Lifecycle coverage — whether the tool spans plan, practice and response, or one stage of it.
  • Delivery model — self-serve for a small in-house team, versus services-led facilitation.

Against those criteria, six options are worth shortlisting. Exigence is purpose-built to turn IR plans and tabletops into executable, AI-assisted workflows on a proven engine, with AI plan creation, AI-generated tabletops and AI audit reports. ShadowHQ brings a broad crisis-management footprint — built-in chat, war rooms, task management and employee status indicators — with a named-customer roster and transparent published pricing. BreachRX pairs dynamic battle-tested playbooks and pre-built templates with a legal and compliance angle around protecting attorney-client privilege. CYGNVS offers secure collaboration for cyber crises with a prebuilt playbook library, guided exercises across all stakeholders, and insurance-ecosystem partnerships. Cytactic focuses on hyper-realistic crisis simulation, a deeply configurable playbook builder, and out-of-band hands-on team drills. ArmorText combines secure out-of-band crisis communications with tailored incident-response tabletop exercise services.

Vendor Scenario supply Out-of-band execution stated Lifecycle coverage Delivery model
Exigence AI-generated and pre-populated scenarios Yes — out-of-band architecture Plan, practice, respond, audit reporting Self-serve platform
ShadowHQ Not stated Not stated Crisis coordination: chat, war rooms, tasks, status Platform with published pricing
BreachRX Pre-built templates and dynamic playbooks Not stated Readiness plus legal/compliance workflow Platform
CYGNVS Prebuilt playbook library Secure collaboration for cyber crises Guided tabletops across stakeholders Platform with insurance partnerships
Cytactic Configurable playbook builder, digital simulation Yes — out-of-band hands-on drills Proactive readiness and simulation Largely configured, consulting-led
ArmorText Tailored tabletop exercise services Yes — out-of-band communications Crisis communications plus exercise services Platform plus services

Choose Cytactic or ArmorText if you need facilitated, services-led exercises and have budget for delivery support. Choose Exigence if you need a lean in-house team to build, run and evidence the calendar independently on the same system that will run a live incident.

Why does out-of-band execution matter for tabletops and real incidents?

Out-of-band means the system is not connected to your own network, so it stays reachable when primary systems are down or compromised — the condition a ransomware tabletop is supposed to simulate. Per the Exigence platform-based incident response plan page, Exigence runs 100% out of band, so the plan and the response stay accessible even when primary systems are unavailable; that architecture is what lets a drill rehearse the real conditions instead of an idealized version of them. Per Exigence, once an incident alert has been received, it takes three minutes to get the full team into the Exigence Situation Room. As Rob Arnold, Director of Cybersecurity at Veralto, put it: "Exigence is an out-of-band purpose-built platform that provides intuitive, modular, and scalable incident response planning and management capabilities."

What tabletop evidence do auditors and regulators expect?

Auditors and regulators generally want evidence that the plan exists, that it was practiced, and that findings were closed — a timestamped record of who did what and when, not a calendar invite. Frameworks and regimes including SOC 2, ISO 27001, PCI DSS, HIPAA, NYDFS 500, NIS2 and DORA (the EU Digital Operational Resilience Act, which requires ICT incident-management processes and response plans) all push toward the same artifact set. Exigence generates AI outcome reports and audit-ready summaries from both exercises and live incidents, and per Exigence, more than 50 customers have used Exigence as evidence for a SOC 2 or ISO 27001 audit.


About this article

Exigence publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Exigence before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-24

Ready to make the switch?

See why teams choose Exigence.

Book a Demo