// FIELD NOTE

One Tabletop a Year Is Not Enough

Incident ResponseTabletop ExercisesComplianceAI Security
By Cameron Reimer, CISSP · GRC Information Security Analyst7 min read

Cybersecurity has spent the last few years throwing money at XDR, AI-assisted analysis, and every buzzword in between. Meanwhile, the exercise meant to prove any of it works under pressure still runs once a year, off a PowerPoint, for a couple of hours.

The annual cadence is not a real stress test. An organization picks ransomware, insider threat, or leaked credentials, and the scenario is probably a repeat from years prior. There is little incentive to improve the exercise until an actual event exposes the gaps.

// 01 — THE THREAT CYCLE CHANGED

Threats move faster than an annual calendar

Defenders are no longer waiting on human operators to try one exploit at a time. AI agents can probe infrastructure, test edge cases, and find attack paths at a scale that was not practical before. A single tabletop around ransomware is not going to cover that threat landscape.

Consider the GPT-5.6 Sol sandbox escape documented by the Cloud Security Alliance. During a reduced-refusal cyber-capability evaluation, OpenAI models escaped their test environment through a previously unknown Artifactory vulnerability and reached Hugging Face infrastructure. The incident crossed organizational boundaries during an internal test. A threat like that can surface overnight. If your annual tabletop ran the week before, you may still have a green compliance checkbox while carrying a new and untested response gap.

"A completed tabletop proves that one exercise happened. It does not prove that your response capability still matches your risk."

// 02 — RISK, NOT ROUTINE

Replace the annual default with a risk-based program

My prediction is that more compliance frameworks will move away from a default annual cadence. They should. The FFIEC Business Continuity Management booklet does not prescribe "one tabletop per year." It expects regulated institutions to base exercises on risk and to validate the continuity of critical operations.

That means stress-testing incident response plans by department and infrastructure instead of treating the entire organization as one audience. Run one exercise for executives, another for technical teams, and another for marketing and crisis communications. Each group has different decisions to make and different failure modes to uncover.

// 03 — SMALLER ROOMS, BETTER TESTS

More exercises do not have to mean more overhead

Stretched cybersecurity teams will hear "multiple tabletops a year" and picture the current workload multiplied several times over. That is not the model. Start with a critical infrastructure component or internal application. Bring in the administrators and employees responsible for those assets, plus the closest manager, director, or executive with decision authority.

The smaller group is easier to schedule, the scenario can target the systems in front of them, and everyone in the room has skin in the game. Compare that with a large annual tabletop where the same few people talk while departments with a loose connection to the scenario contribute a sentence or two. The facilitator does more work and often finds fewer gaps.

// 04 — VERIFY THE FIX

A lesson learned is not closed until it is tested

There is another problem underneath the annual model: lessons learned can take the rest of the year to address, and nobody circles back to verify that the fix holds up. A finding marked complete on paper is not the same as a response capability that works under pressure.

A targeted follow-up exercise closes that loop. Go back to the department where the gap appeared, test the corrected process, and capture the result. The next tabletop should not wait for the next calendar year when the reason to run it already exists.

// 05 — WHAT THE CONTROLS ACTUALLY SAY

CMMC leaves room for continuous improvement

CMMC Level 2 practice IR.L2-3.6.3 gets the emphasis right: "Test the organizational incident response capability." The practice, inherited from NIST SP 800-171, does not prescribe an annual tabletop. Its discussion includes checklists, walkthroughs, tabletop exercises, simulations, and comprehensive exercises as ways to find weaknesses or deficiencies.

That language supports a continuous improvement model: use a focused tabletop to verify a specific fix and aim it at the department where the gap first appeared. My own organization is already moving in this direction. We are keeping our organization-wide BCP tabletop while rolling out departmental tabletops around each department's business processes, functions, and assets.

// 06 — TEST AFTER CHANGE

Major changes should trigger an exercise

The same logic already exists one domain over. PCI DSS Requirement 11.4 calls for internal and external penetration testing at least annually and after significant infrastructure or application changes. Tabletop programs should adopt the same trigger: when a major change alters the risk, run a focused exercise against that change.

A new identity provider, cloud migration, critical vendor, customer-facing application, or AI agent with elevated access can all change how an incident unfolds. Testing those changes with the people who own them will expose more than a company-wide exercise that is a foot deep and three hundred feet wide.

// CHANGE THE CADENCE

Use the hours on the risk in front of you

None of this is about giving security teams more to do. It is about spending the hours they already have on the right people at the right time, instead of repeating the same PowerPoint once a year. Annual made sense when threats and infrastructure changed more slowly. It does not anymore.

The organization-wide tabletop still has a place. It just should not be the only test you run. Keep it for cross-functional coordination, then use smaller risk-based exercises to test major changes, close specific findings, and prove that fixes work. If you need a practical starting point, read our guide to planning and facilitating a BCP/IR tabletop.

// BUILD A TARGETED EXERCISE

Run the next test against your actual risk

Breachday helps teams build focused scenarios, capture decisions and lessons learned, and keep the evidence together for follow-up and audit review.