Incident Response Tabletop Exercise Checklist Template

Most tabletop exercises end with a lively discussion and a whiteboard full of gaps. Twelve months later the same gaps turn up in the next exercise, because nobody was given the job of fixing them.

A tabletop exercise is the cheapest way to find out whether your incident response plan works before an attacker tests it for you. A facilitator walks a group of decision-makers through a realistic scenario, adds new developments as the discussion unfolds, and watches where people hesitate, disagree or reach for a phone number that is no longer valid. The session itself takes a morning. The value comes from the preparation before it and, above all, from the follow-through afterwards. This free tabletop exercise checklist covers the whole cycle: setting objectives, writing the scenario and injects, preparing participants, running the session, holding the hot wash, and tracking every improvement action until it is closed. It follows the approach in NIST SP 800-84 and the improvement-planning discipline of HSEEP, and produces the evidence that auditors ask for when they want proof the plan has been tested.

Use This Template Free See Live Example
No Credit Card Required

Talking Through the Plan vs Doing It: Choosing the Right Exercise

NIST SP 800-84 separates discussion-based exercises from ones where people actually carry out their duties. A tabletop is discussion-based: nobody restores a server or isolates a network segment. Participants explain what they would do, who they would call and what they would need to decide. That makes it ideal for testing roles, authority and communication, which is where most real responses stall. A functional exercise goes further and has staff perform their roles in a simulated environment, which costs far more to set up.

NIST also advises exercising senior and operational teams separately at first, then together once each group knows its own part. Executives need to practise decisions such as whether to take a revenue-generating system offline, what to tell customers and when to involve the regulator. Technical responders need to practise containment choices, evidence handling and escalation. Mixing both groups in a first exercise usually means one of them sits in silence for two hours.

Tabletop exercise

Discussion-based, led by a facilitator

Tests: roles, decision rights, communication paths and whether the plan matches reality.

Effort: one to three months of preparation and a session of two to eight hours.

Output: an after-action report and an improvement plan.

Best for: annual plan testing, new teams and executive practice.

Functional exercise

Operations-based, in a simulated environment

Tests: whether people and tools can actually execute the procedures.

Effort: three to six months of design, plus controllers and simulators to run it.

Output: timed performance data plus an after-action report.

Best for: mature teams validating specific procedures such as restoration.

What the Tabletop Exercise Checklist Covers

Six phases run from the decision to hold an exercise to the last improvement action being closed. Two answers along the way add extra tasks only when they are needed.

Phase 1

Phase 1: Set Objectives & Scope

Owned by the exercise lead. Start this phase one to three months before the session; larger exercises need the longer lead time.

  • Record why you are exercising now — annual test, new plan version, a recent incident, a merger or a new security provider
  • Name the plan and playbooks under test — with version numbers, so the report can say exactly what was tested
  • Write three to five objectives — each one specific enough to judge afterwards as met, partly met or not met
  • Choose the audience level — executive, operational or combined
  • Get sponsor approval and fix the date — a senior sponsor makes attendance a priority rather than an optional meeting
Phase 2

Phase 2: Design the Scenario & Injects

Task 4 appears only when Phase 1 sets the audience to executive or combined.

  • Choose a plausible scenario — drawn from your risk register, recent sector incidents or a CISA Tabletop Exercise Package
  • Keep the opening narrative short — long scenarios pull the discussion towards the story and away from the objectives
  • Script injects in timed stages — a ransom note, a journalist’s call, a backup that will not restore, a regulator’s question
  • Add executive decision points — whether to pay, what to disclose, when to shut down a revenue-critical system
  • Set the evaluation criteria before the day — so the note-taker knows what to capture against each objective
Phase 3

Phase 3: Invite & Prepare

  • Appoint a facilitator and a separate note-taker — nobody can steer a discussion and record it properly at the same time
  • Invite everyone with a role in the plan — include the outside parties it depends on, such as your managed service provider, forensic retainer and legal counsel
  • Send a short briefing — purpose, agenda, no-fault ground rules and what participants should bring
  • Prepare the facilitator guide and participant pack — the participant version leaves out the scripted questions
  • Book the room or video call and test the materials — with a backup copy of every slide and inject
Phase 4

Phase 4: Run the Exercise

  • Open with scope and ground rules — the plan is being tested, not the people, and the scenario is fixed
  • Release injects on schedule — let discussion run, then move the scenario forward
  • Record each decision, who made it and how long it took — hesitation is a finding in itself
  • Log every gap the moment it appears — a missing contact, unclear authority, or a tool nobody present can access
  • Steer back to the objectives — park side debates in a list for the report
Phase 5

Phase 5: Hot Wash & After-Action Report

The after-action report is approved by the exercise sponsor, usually the CISO or head of IT.

  • Hold the hot wash straight after the session — what went well, where people felt unsure and what the plan should say differently
  • Collect written feedback within a week — quieter participants often raise the most useful points in writing
  • Draft the after-action report — each objective marked met, partly met or not met, with the observations behind it
  • Build the improvement plan — every gap becomes an action with an owner and a due date, and critical gaps are flagged
  • Approve the report and improvement plan — sponsor sign-off commits the budget and time the fixes need
Phase 6

Phase 6: Close the Improvement Actions

Task 3 appears only when Phase 5 flags a critical gap.

  • Update the incident response plan and playbooks — new version number, with a note of which exercise finding drove each change
  • Close each improvement action with evidence — a corrected contact list, a new runbook, a granted permission
  • Schedule a focused retest of critical gaps — a short follow-up session on the one scenario that failed
  • File the evidence pack — invitation, attendance, scenario, after-action report and closed actions together
  • Set the next exercise date and scenario theme — a different threat and, where useful, a different audience

Which Frameworks Expect an Exercise, and What They Want to See

Several frameworks expect incident response or recovery plans to be tested, and a documented tabletop is the most common way to show it. The table lists the references most security and GRC teams meet, with the phase that produces the evidence. Treat it as a starting point, not legal or audit advice; your auditor will confirm what counts as sufficient testing for your scope.

Framework Reference What it expects Evidenced in
NIST SP 800-84 (September 2006)Section 4, tabletop exercisesDesign, develop, conduct and evaluate the exercise; a facilitator and a data collector; an after-action report against criteria set in advancePhases 1–5
HSEEP (2020 revision)Evaluation and improvement planningAn after-action report and improvement plan, with corrective actions tracked to completionPhases 5–6
PCI DSS v4.0.112.10.2The incident response plan is reviewed, updated as needed and tested at least once every 12 months, covering every element in 12.10.1Phases 1 and 6
ISO/IEC 27001:2022A.5.24, A.5.27, A.5.29, A.5.30Incident management is planned and lessons are learned; security is maintained during disruption; ICT readiness is planned, implemented, maintained and testedPhases 1, 5 and 6
SOC 2 (2017 TSC, revised points of focus 2022)CC7.4, CC7.5; A1.3 if Availability is in scopePoints of focus include evaluating the effectiveness of incident response and testing the incident recovery plan; A1.3 expects recovery plan procedures to be testedPhases 4–6
NIST CSF 2.0 / SP 800-61 Rev. 3ID.IM-02Improvements are identified from security tests and exercises, including those run with suppliers and third partiesPhases 3, 5 and 6
CIS Controls v8.117.7Routine incident response exercises for key personnel that test communication, decision making and workflows, at least annuallyWhole checklist

Annual testing is the common baseline across these references. Some organisations run two sessions a year instead, alternating an executive exercise with an operational one, so that each audience practises annually without one long, crowded session. The framework programmes themselves are covered by the PCI DSS 4.0 Compliance Checklist, the SOC 2 Readiness Checklist and the NIST CSF 2.0 Checklist.

Why Run Your Tabletop Exercises in CheckFlow?

1

Next year’s exercise is already scheduled

A recurring schedule opens the checklist weeks before each exercise date and assigns Phase 1 to the exercise lead. The annual test stops depending on someone remembering it in November.

2

Findings get owners, not just minutes

Improvement actions are recorded in a table with an owner and due date, and the sponsor approves the plan before it is final. Dashboards show which actions are overdue, so the gaps from this year do not reappear next year.

3

An evidence pack auditors can follow

The scenario, attendance, after-action report and closed actions are attached to the tasks that produced them, each stamped with who completed it and when. Exporting a completed exercise answers the auditor’s request in one step.

CheckFlow does not run the simulation or generate scenarios; the facilitator does that. It runs the planning, sign-off and follow-through that turn a good conversation into fixed gaps. For SOC 2 teams, CheckFlow’s SOC 2 compliance software shows how exercise evidence sits alongside the other recurring controls your auditor samples.

The plan you are testing should itself be a working checklist. The Cybersecurity Incident Response Checklist gives responders the step-by-step version, so the exercise tests the same document people will use on the day. If the scenario ends in a major outage, the Disaster Recovery Audit Checklist checks that the recovery side holds up too.

Exercises about a major outage rather than an attack belong in the Business Continuity Plan Testing Checklist, with the Backup Verification & Restore Test Checklist proving the restores behind it. When a real incident happens, the Incident Postmortem Template is the after-action report’s real-world counterpart.

Frequently Asked Questions

What is an incident response tabletop exercise?

+

It is a facilitated discussion in which the people named in your incident response plan work through a simulated incident. The facilitator introduces the scenario in stages and asks what each person would do, decide and communicate. Nothing is switched off or restored for real. The aim is to find gaps in the plan, in decision rights and in communication before a genuine incident exposes them.

How often should we run a tabletop exercise?

+

At least once a year is the usual baseline: PCI DSS v4.0.1 requirement 12.10.2 and CIS Controls v8.1 safeguard 17.7 both set an annual minimum for testing. NIST SP 800-84 also suggests exercising after organisational changes or updates to the plan. Many teams add a short follow-up session when an exercise exposes a critical gap, so the fix is proven rather than assumed.

Who should take part?

+

Everyone with a role in the plan being tested, and no one without one. For an operational exercise that means security, IT operations, service owners and any outside provider the plan relies on. For an executive exercise it means the leadership team, legal, communications and the data protection officer. Keep numbers manageable; a large audience turns a discussion into a presentation.

What is a hot wash?

+

A short debrief held immediately after the exercise, while the discussion is still fresh. The facilitator asks participants what went well, where they felt unprepared and which parts of the plan should change. It is not the after-action report; it is one of the inputs to it, alongside the note-taker’s observations and written feedback.

Where can we find ready-made scenarios?

+

CISA publishes Tabletop Exercise Packages (CTEPs) covering cyber scenarios such as ransomware, insider threat and phishing. Each package includes template objectives, a scenario, discussion questions and an after-action report template. Adapt a package to your own systems, suppliers and people; a scenario that names your real finance platform produces far better discussion than a generic one.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Find the Gaps in a Meeting Room, Not in a Real Incident

Free trial — no credit card required.