Ultimate TTX logo

Ultimate TTX

Plan • Execute • Hotwash • Report

Incident response plan testing—without the overhead

Tabletop Exercises that drive real improvement

Run realistic IR plan tests, capture decisions and gaps, and produce the evidence an assessor asks for. Testing the incident response capability is required by NIST SP 800-171 and CMMC, by PCI DSS, and by every other framework here, and a tabletop exercise is one of the ways those documents name to satisfy it.

Scenario library Facilitator runbook Evidence & decisions log Hotwash guide After-Action Report

Why TTX

Validate execution

  • Roles, escalation paths, decision rights
  • Comms, tooling, and dependencies
  • Vendor and third-party coordination

Find gaps early

  • Missing steps, unclear ownership
  • Fragile assumptions and bottlenecks
  • Policy vs. reality mismatches

Document outcomes

  • Decision timeline + evidence prompts
  • Hotwash notes and action register
  • After-Action Report + improvement plan

What exercises actually find

Three results come back from nearly every exercise. None of them is a missing security product, and none of them is a surprise to the facilitator.

Nobody was coordinating

The room is never leaderless. Something fills the gap within about ninety seconds, and what fills it is the org chart. Somebody who knows the plan raises what it says, the response carries on past them, and afterwards there is no moment where anyone decided to abandon the plan.

The fix is naming a coordinator in the plan, before the day. CISA and five partner agencies reached the same conclusion in Communicating Under Pressure (September 2026), which designates an incident lead, a communications lead and a spokesperson with approval paths agreed in advance.

Most of the fixes are documents

A point missing from a procedure, a step in the wrong place, an instruction that no longer matches the environment. Individually small, cheap, and approved well below the executive the report is addressed to—somebody owns that runbook and can change it this week.

Cheap is not the same as minor. A procedure that starts restoring from backup before anybody has established the date of the initial compromise has its steps in the wrong order—and a team that cannot date the compromise cannot know which backup is clean. Establishing the date first is the difference between restoring the business and restoring the intrusion.

The report is bigger than the exercise

A four-hour exercise took twenty-four hours to report, by a facilitator who was not learning the format on the job. Six hours of reporting for every hour in the room, and six is a floor.

It is also the part that gets cut when a schedule tightens: produced last, invisible while it is late, and the day already happened. And it is the organization's evidence that the exercise took place at all—the thing handed to an assessor who asks when the plan was last tested. A year later it is the only part of the engagement anyone still has. Capturing structured material during the exercise is how that ratio comes down.

These are written up at length on the blog.

Almost every framework requires this

Whatever regime you are in—CUI, cardholder data, protected health information, customer financial records—somebody will ask when your incident response capability was last tested, and will ask to see what the test produced. CMMC is the strictest about the evidence; it is not the only one that asks.

What the requirement says

NIST SP 800-171 Rev. 2, requirement 3.6.3: test the organizational incident response capability. CMMC carries it as practice IR.L2-3.6.3. Revision 3 restates it as 03.06.03.

Both revisions name walk-throughs and tabletop exercises in the requirement's own discussion. This is not a product argued into a requirement from outside it.

It reaches further than CMMC. 800-171's requirement was tailored from NIST SP 800-53 control IR-3, Incident Response Testing, so the same obligation arrives through FedRAMP, the state RAMPs, FISMA, IRS Publication 1075 and the state agency overlays built on 800-53—work done once for one of them counts for the others.

How often

Revision 2 sets no interval. Revision 3 leaves the frequency to the organization—except for defense contractors, where DoD has already defined it.

The DoD parameter memorandum for 800-171 Rev. 3 sets the 03.06.03 frequency at at least every 12 months.

Under CMMC the interval is yours to set, but not without a ceiling. The CMMC Assessment Guide – Level 2, version 2.13, September 2024, defines periodically as occurring at a regular interval as determined by the OSA that may not exceed one year. That is the only interval convention the model states, and IR.L2-3.6.3 asks an assessor to look for whether the incident response policy requires regular testing. An interval longer than a year is one you will be asked to defend.

Outside the defense industrial base the picture is the same shape: most frameworks state no interval, PCI DSS states at least once every 12 months, and three independent regimes arriving at the same number is as close to a settled answer as this gets.

What is examined

The assessment procedures say what gets looked at. 800-171A and 800-171A Rev. 3 both list the incident response test plan and the incident response test results among the objects an assessor may examine.

An exercise that produced no report produced no evidence. That is the same report the section above says gets cut first, which is why this platform is built around producing it.

If you are not a defense contractor

The obligation is not a CMMC peculiarity. Most regimes that govern sensitive data require the incident response plan to be tested; what varies is whether they say how often. Only one of them names the tabletop exercise outright.

PCI DSS says it plainly

Requirement 12.10.2: at least once every 12 months, the security incident response plan is reviewed and the content is updated as needed, and tested, including all elements listed in Requirement 12.10.1.

The Good Practice guidance beside it says the test can include simulated incidents and the corresponding responses in the form of a “table-top exercise” that includes participation by relevant personnel. No other framework here names the method.

Requirement 12.10.4 adds periodic training for the people who respond, at a frequency the entity sets in its own targeted risk analysis under 12.10.4.1—a best practice until 31 March 2025 and required since. Read from PCI DSS v4.0.1, June 2024, page 328, in the PCI SSC document library.

Healthcare and financial services

HIPAA today: the Security Rule requires security incident procedures at 45 CFR 164.308(a)(6), and (a)(7)(ii)(D) requires procedures for periodic testing and revision of contingency plans. Periodic, not annual, and addressable rather than required—which means a covered entity that does not do it has to write down why.

The proposed rule would end all three of those hedges. HHS's January 2025 notice of proposed rulemaking (90 FR 898) would require a written incident response plan and would review and test it at least once every 12 months, document the results, and modify it accordingly; it would require the same annual test of contingency plans; and it would remove the addressable-versus-required distinction entirely. Proposed, not final—but every interval in it is twelve months.

GLBA: the Safeguards Rule requires a written incident response plan at 16 CFR 314.4(h), and (d)(1) requires regular testing or monitoring of the effectiveness of key controls. It fixes intervals for penetration testing and vulnerability assessment and none for the response plan.

ISO 27001 and Sarbanes–Oxley

ISO/IEC 27001:2022 carries incident management planning and preparation at Annex A control 5.24 and requires ICT continuity plans to be tested at 5.30. Neither states a frequency. The standard is sold rather than published, so it is named here and not linked.

Sarbanes–Oxley reaches this through internal control over financial reporting: an issuer is expected to have incident response planning and to train the people who carry it out. A tabletop exercise is a good way to meet the training expectation, and it produces the record that the training happened.

You can start for free, and you should know that

CISA publishes Tabletop Exercise Packages—over a hundred of them, covering ransomware, insider threats, phishing, ICS compromise and much else, each with template objectives, a scenario, and discussion questions. They cost nothing, they are good, and an organization that has never run an exercise should go and look at them. Anyone selling you a tabletop exercise who does not mention they exist is selling you the scenario.

The UK's National Cyber Security Centre publishes Exercise in a Box on the same terms—free, twenty exercises across twelve topics, and open to organizations of any size or country. It is the better starting point of the two if nobody in your organization has facilitated anything before: the exercises are smaller, several are designed to run in a single short session, and the packages are written to be picked up and used rather than adapted first.

Where our scenarios differ is not effort. It is kind. A package hands the room a situation and a set of questions to discuss. Ours do that and then keep going:

They hold what actually happened

Every scenario carries ground truth: what the proxy recorded, what the backup really restores, what the vendor says when called at 22:40. So when somebody says “I would go and look at the logs,” the facilitator tells them what they find. A discussion where nobody can be told what they would have found is a discussion about intentions. One where they can be told turns into an investigation, and an investigation is what you are actually testing.

They are fitted before they are run

Planning answers select the scenario, not just its wrapper—your environment, your obligations, and what your own plan actually says. Dozens of settings per scenario do this, and one example gives the shape of it: the ransomware scenario holds six mutually exclusive forms of the same evidence and shows only the one matching the visibility you actually have—proxy logs, DNS filtering, or nothing at all. Whether the attacker disabled logging and cleared it is another. So is how long your vendor really takes to answer a support case. The room works against its own environment rather than a generic one.

The findings are designed in

The findings a scenario is built to surface, the criteria they are judged against, and the hotwash questions that draw them out are authored with the scenario rather than improvised afterwards. That is what makes the report reproducible instead of a record of how sharp the facilitator was feeling that day.

The rest of what a free package cannot include:

Someone who is not you A facilitator with no stake in the answer, who can let a silence run instead of filling it.
Capture as it happens Decisions, timing and evidence recorded during the day rather than reconstructed after it.
The report Findings, what each one means, and what would close it—the artifact an assessor examines. The platform captures the day and drafts it; a person writes the judgment.

None of that makes a free package the wrong choice. An organization can run a CTEP, run it well, and come away better for it. The claim here is narrower and, we think, fair: you will learn more from the same four hours using this platform, and more again with somebody facilitating who has watched other organizations work through the same morning.

Options

Facilitated • CMMC Assessor-led

Higher realism, stronger outcomes

External leadership that drives tempo, challenges assumptions, and delivers a crisp remediation plan.

  • Tailored scenario to your environment and constraints
  • Firm facilitation to keep focus and decision quality high
  • Findings ranked by what it takes to act on them
  • Executive readout + documentation package

Lifecycle

End-to-end: pre-TTX → hotwash → report

The platform supports the full workflow so your exercise produces measurable, documented improvements.

1) Pre-TTX planning Scope, objectives, roles, rules, and scenario setup.
2) Execute the TTX Timed injects, decision points, evidence prompts, and capture.
3) Hotwash Guided debrief: what worked, what didn’t, what changes.
4) Report Findings and what would close each one. Who does what by when is yours, in a document you own.

Deliverables: What You Get

Each exercise produces facilitator-ready materials, execution evidence, and a report the facilitator completes from what the platform captured.

Facilitator package

  • Runbook + inject schedule
  • Prompts and evaluation cues
  • Participant role cards

Execution capture

  • Decision log and timeline
  • Evidence prompts and notes
  • Capability gaps recorded as they surface

Assessment evidence

  • Hotwash summary
  • After-Action Report, drafted by the platform and finished by the facilitator
  • Findings ranked, each with what would close it