Next year’s exercise is already scheduled
A recurring schedule opens the checklist weeks before each exercise date and assigns Phase 1 to the exercise lead. The annual test stops depending on someone remembering it in November.
A tabletop exercise is the cheapest way to find out whether your incident response plan works before an attacker tests it for you. A facilitator walks a group of decision-makers through a realistic scenario, adds new developments as the discussion unfolds, and watches where people hesitate, disagree or reach for a phone number that is no longer valid. The session itself takes a morning. The value comes from the preparation before it and, above all, from the follow-through afterwards. This free tabletop exercise checklist covers the whole cycle: setting objectives, writing the scenario and injects, preparing participants, running the session, holding the hot wash, and tracking every improvement action until it is closed. It follows the approach in NIST SP 800-84 and the improvement-planning discipline of HSEEP, and produces the evidence that auditors ask for when they want proof the plan has been tested.
NIST SP 800-84 separates discussion-based exercises from ones where people actually carry out their duties. A tabletop is discussion-based: nobody restores a server or isolates a network segment. Participants explain what they would do, who they would call and what they would need to decide. That makes it ideal for testing roles, authority and communication, which is where most real responses stall. A functional exercise goes further and has staff perform their roles in a simulated environment, which costs far more to set up.
NIST also advises exercising senior and operational teams separately at first, then together once each group knows its own part. Executives need to practise decisions such as whether to take a revenue-generating system offline, what to tell customers and when to involve the regulator. Technical responders need to practise containment choices, evidence handling and escalation. Mixing both groups in a first exercise usually means one of them sits in silence for two hours.
Tests: roles, decision rights, communication paths and whether the plan matches reality.
Effort: one to three months of preparation and a session of two to eight hours.
Output: an after-action report and an improvement plan.
Best for: annual plan testing, new teams and executive practice.
Tests: whether people and tools can actually execute the procedures.
Effort: three to six months of design, plus controllers and simulators to run it.
Output: timed performance data plus an after-action report.
Best for: mature teams validating specific procedures such as restoration.
Six phases run from the decision to hold an exercise to the last improvement action being closed. Two answers along the way add extra tasks only when they are needed.
Owned by the exercise lead. Start this phase one to three months before the session; larger exercises need the longer lead time.
Task 4 appears only when Phase 1 sets the audience to executive or combined.
The after-action report is approved by the exercise sponsor, usually the CISO or head of IT.
Task 3 appears only when Phase 5 flags a critical gap.
Several frameworks expect incident response or recovery plans to be tested, and a documented tabletop is the most common way to show it. The table lists the references most security and GRC teams meet, with the phase that produces the evidence. Treat it as a starting point, not legal or audit advice; your auditor will confirm what counts as sufficient testing for your scope.
| Framework | Reference | What it expects | Evidenced in |
|---|---|---|---|
| NIST SP 800-84 (September 2006) | Section 4, tabletop exercises | Design, develop, conduct and evaluate the exercise; a facilitator and a data collector; an after-action report against criteria set in advance | Phases 1–5 |
| HSEEP (2020 revision) | Evaluation and improvement planning | An after-action report and improvement plan, with corrective actions tracked to completion | Phases 5–6 |
| PCI DSS v4.0.1 | 12.10.2 | The incident response plan is reviewed, updated as needed and tested at least once every 12 months, covering every element in 12.10.1 | Phases 1 and 6 |
| ISO/IEC 27001:2022 | A.5.24, A.5.27, A.5.29, A.5.30 | Incident management is planned and lessons are learned; security is maintained during disruption; ICT readiness is planned, implemented, maintained and tested | Phases 1, 5 and 6 |
| SOC 2 (2017 TSC, revised points of focus 2022) | CC7.4, CC7.5; A1.3 if Availability is in scope | Points of focus include evaluating the effectiveness of incident response and testing the incident recovery plan; A1.3 expects recovery plan procedures to be tested | Phases 4–6 |
| NIST CSF 2.0 / SP 800-61 Rev. 3 | ID.IM-02 | Improvements are identified from security tests and exercises, including those run with suppliers and third parties | Phases 3, 5 and 6 |
| CIS Controls v8.1 | 17.7 | Routine incident response exercises for key personnel that test communication, decision making and workflows, at least annually | Whole checklist |
Annual testing is the common baseline across these references. Some organisations run two sessions a year instead, alternating an executive exercise with an operational one, so that each audience practises annually without one long, crowded session. The framework programmes themselves are covered by the PCI DSS 4.0 Compliance Checklist, the SOC 2 Readiness Checklist and the NIST CSF 2.0 Checklist.
A recurring schedule opens the checklist weeks before each exercise date and assigns Phase 1 to the exercise lead. The annual test stops depending on someone remembering it in November.
Improvement actions are recorded in a table with an owner and due date, and the sponsor approves the plan before it is final. Dashboards show which actions are overdue, so the gaps from this year do not reappear next year.
The scenario, attendance, after-action report and closed actions are attached to the tasks that produced them, each stamped with who completed it and when. Exporting a completed exercise answers the auditor’s request in one step.
CheckFlow does not run the simulation or generate scenarios; the facilitator does that. It runs the planning, sign-off and follow-through that turn a good conversation into fixed gaps. For SOC 2 teams, CheckFlow’s SOC 2 compliance software shows how exercise evidence sits alongside the other recurring controls your auditor samples.
The plan you are testing should itself be a working checklist. The Cybersecurity Incident Response Checklist gives responders the step-by-step version, so the exercise tests the same document people will use on the day. If the scenario ends in a major outage, the Disaster Recovery Audit Checklist checks that the recovery side holds up too.
Exercises about a major outage rather than an attack belong in the Business Continuity Plan Testing Checklist, with the Backup Verification & Restore Test Checklist proving the restores behind it. When a real incident happens, the Incident Postmortem Template is the after-action report’s real-world counterpart.
It is a facilitated discussion in which the people named in your incident response plan work through a simulated incident. The facilitator introduces the scenario in stages and asks what each person would do, decide and communicate. Nothing is switched off or restored for real. The aim is to find gaps in the plan, in decision rights and in communication before a genuine incident exposes them.
At least once a year is the usual baseline: PCI DSS v4.0.1 requirement 12.10.2 and CIS Controls v8.1 safeguard 17.7 both set an annual minimum for testing. NIST SP 800-84 also suggests exercising after organisational changes or updates to the plan. Many teams add a short follow-up session when an exercise exposes a critical gap, so the fix is proven rather than assumed.
Everyone with a role in the plan being tested, and no one without one. For an operational exercise that means security, IT operations, service owners and any outside provider the plan relies on. For an executive exercise it means the leadership team, legal, communications and the data protection officer. Keep numbers manageable; a large audience turns a discussion into a presentation.
A short debrief held immediately after the exercise, while the discussion is still fresh. The facilitator asks participants what went well, where they felt unprepared and which parts of the plan should change. It is not the after-action report; it is one of the inputs to it, alongside the note-taker’s observations and written feedback.
CISA publishes Tabletop Exercise Packages (CTEPs) covering cyber scenarios such as ransomware, insider threat and phishing. Each package includes template objectives, a scenario, discussion questions and an after-action report template. Adapt a package to your own systems, suppliers and people; a scenario that names your real finance platform produces far better discussion than a generic one.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.