Glossary

Tabletop Exercise

A tabletop exercise is a discussion-based rehearsal of your incident response plan: the response team walks through a realistic scenario — ransomware in production, a leaked credential, a vendor breach — making the decisions they’d make, without touching real systems. Two hours, a facilitator, and honest notes.

Why auditors love them

Plans are cheap; operation is evidence. If your observation window contained no real incidents (congratulations), the tabletop record is what proves the plan isn’t shelf-ware. SOC 2 auditors ask for it, ISO assessors expect exercises as part of the ISMS loop, and regulators like MAS treat untested response plans as unmanaged risk.

Running one that’s actually useful

Pick a scenario that’s plausible for your architecture, not a generic movie plot. Inject complications mid-exercise (“the person who owns that system is on a plane”). Assign a note-taker to capture decisions, timing, and — the real product — friction: the escalation path nobody remembered, the customer-notification template that didn’t exist, the on-call rotation that had a hole. Then track those gaps to closure like any other finding.

The minimum viable cadence

Once a year, recorded, with remediations tracked. That single artifact answers the audit question, and it’s the difference between a team executing a rehearsed play and a team reading the playbook for the first time during a real SEV-1 — which is the most expensive possible time to learn your plan has holes.

Related Terms

Business Continuity Plan (BCP) — A business continuity plan keeps the business running through disruption; disaster recovery restores the systems. Auditors expect both — and a test record.

Incident Response Plan — An incident response plan defines how you detect, triage, contain, and learn from security incidents — with the records SOC 2 auditors and regulators sample.