What you get from an incident-response tabletop exercise
An exercise is only worth running if something useful leaves the room. Here is what you actually walk away with, and what you don’t.
Every exercise leaves you with three things.
The session
A live debrief
A written summary
When the exercise is for evidence: an evidence pack
Some exercises are run specifically to evidence an obligation under NIS2, ISO/IEC 27001, or ISO/IEC 27035. When that’s the point, you also get an evidence pack. It records that the exercise happened and what it found, in a form you can put in front of an auditor.
Inside it: a map from the exercise to the controls it touched, an attendance record, the owners and dates for anything that needs following up, a sign-off, a note on how long to keep it, and a plain statement of what the pack does and doesn’t show.
It is deliberately not a certificate. Nobody can certify that you’re ready by watching you run one exercise. What the pack gives you is an honest record that you exercised your plan, what held, and what didn’t.
When the point is a formal assessment: a capability read
A smaller number of engagements are capability assessments, where a formal read of how your team performs is the actual goal. These are available by application, not the standard offering. When I run one, the capability is scored privately after the session, either from a recording or by a second person who observed it. Never live, never in the room. You get a capability-read report out of it.
Scoring it away from the table is deliberate. It keeps the guide-not-judge principle intact even when an assessment is the whole point, so the people in the room can still make mistakes safely.
That’s what leaves the room. For how the exercise itself runs, see the overview. To run one, tell me where your team is and what you need out of it, and we’ll find a date.