Ga naar inhoud

NIS2 ·

Tabletop cyber exercise: NIS2 and ISO evidence in 2026

An incident response plan in a drawer is worthless the moment things go wrong. NIS2 and ISO 27001 therefore do not just ask for a plan on paper, but for demonstrable exercise. The cheapest and most effective way to do that is the tabletop exercise: a facilitated discussion in which you play through a cyber incident without anything actually breaking. In 90 minutes you test whether leadership, IT, legal and communications know what to do — and you produce audit evidence along the way.

What exactly is a tabletop?

In a tabletop the key roles sit around a table and a facilitator walks through a scenario step by step. At set moments the facilitator introduces “injects” — new information that escalates the situation (“the backup turns out to be encrypted too”, “a journalist is calling”). Participants decide out loud what they would do. It is not about technical heroics, but about decision-making under pressure: who may take down production, when do you notify the regulator, who talks to the press?

Scenarios that matter in 2026

Choose scenarios that match your biggest risks. Four that are almost always relevant:

  • Ransomware with a backup dilemma: your systems are encrypted — do you restore from backup, and does your recovery time (RTO) actually hold?
  • Outage of a critical SaaS vendor: your most important cloud service is down; what is your fallback and how do you inform customers?
  • Breach with a notification duty: personal data has leaked — the GDPR clock (72 hours) and the NIS2 notification chain run at the same time.
  • Chain incident at a tier-1 vendor: a supplier is hacked; which of your data or services does that affect, and what can you demand contractually?

Who is at the table?

The strength of a tabletop is that it is not an IT party. Invite at least: a board member or director (for the calls that touch money or reputation), IT/security, someone who knows the legal and privacy obligations, and communications. It is precisely the friction between those roles — “we must go public now” versus “contain it first” — that surfaces the lessons.

How to prepare

A good exercise stands or falls with preparation. Write the scenario and injects in advance (usually three to five injects of increasing severity). Draw up a timeline, appoint a facilitator who does not play along, and make sure someone takes minutes. For an SME, 90 minutes is ample; do not over-complicate it, because the first time mostly exposes the basic reflexes.

The documentation is your evidence

This is where the audit value sits. Afterwards, record: the agenda and scenario, the participants, the decisions taken, the gaps that emerged, and a corrective action plan (CAP) with an owner and deadline per gap. Link this to your NIS2 file, your incident management process and your business continuity plan (BCM). Without that report, as far as the certification body is concerned, the exercise did not happen.

What a tabletop almost always exposes

The recurring lessons are remarkably constant: no one is sure who may decide to take systems offline; notification deadlines are underestimated; customer communication is not prepared; and the backup has never actually been restored. Those are exactly the things you would rather discover during an exercise than during a real attack.

Common mistakes

  • Inviting only IT — you then miss the board and communication decisions that make the difference.
  • No injects — without escalation it stays a pleasant chat without pressure.
  • No report — then there is no evidence and no follow-up.
  • One-off — an exercise from two years ago no longer counts; schedule it as a fixed rhythm.

Frequency and rhythm

Schedule a tabletop at least annually; vital sectors and organisations in the stricter NIS2 category more often. Vary the scenario so you do not rehearse the same thing every year. Follow up the open actions from the previous CAP in the next session — that shows regulators and the board that exercising is a living process, not a checkbox.

Getting started

Start small: pick one scenario, invite the four core roles, and block 90 minutes. That alone raises your incident readiness and your audit evidence a level. Want to know more about the link with supervision? See our page on NIS2 or take the free readiness scan.

Deep dive in the knowledge base

Run the NIS2 readiness scan

Align NIS2 expectations with your existing management system.

Start NIS2 scan

← Back to overview