Organisations conduct cybersecurity exercises for one fundamental reason:
To find out how prepared they really are before a real attacker tests them. But not all cybersecurity exercises test the same thing.
A tabletop exercise can help an organisation evaluate decision-making, communication, governance and coordination during a simulated cyber incident. A cyber drill can go further by testing how teams actually detect, investigate, contain and recover from a simulated attack.
Understanding the difference matters because an organisation can have a well-written incident response plan and still discover that its teams, processes or technical controls do not perform as expected under pressure.
A cyber drill is a controlled simulation of a cybersecurity incident designed to test an organisation’s ability to respond to an evolving attack.
Depending on the exercise objectives, participants may be required to:
Cyber drills can therefore test practical response capabilities rather than simply discussing what the organisation would do.
Cyberdrill programmes are commonly designed around simulated cyberattacks and the ability of an organisation to detect and respond appropriately.
A tabletop exercise is generally discussion-based. Participants are presented with a simulated incident and work through the scenario by discussing their roles, responsibilities and decisions.
NIST defines tabletop exercises as discussion-based exercises, while functional exercises allow personnel to validate operational readiness in a simulated operational environment. CISA similarly describes tabletop exercises as facilitated scenario discussions designed to help organisations identify problems and work through them before an actual crisis.
The distinction is important.
A tabletop asks:
“What would we do?”
A cyber drill can ask:
“Can we actually do it?”
Area | Tabletop Exercise | Cyber Drill |
Primary focus | Decision-making and coordination | Practical response |
Format | Discussion-based | Simulation/operational |
Technical execution | Limited | Can be hands-on |
Incident response | Discussed | Practised |
Detection | Discussed or simulated | Can be tested |
Containment | Discussed | Can be practically evaluated |
Leadership | Strong focus | Can be included |
Business continuity | Can be tested | Can be tested |
Technical teams | Discuss response | Can execute response |
Environment | Meeting/simulation | Controlled technical environment |
Neither is inherently better. They answer different questions.
Imagine an organisation has a ransomware incident response plan. During a tabletop exercise, leadership may correctly determine that:
That is valuable but several questions remain unanswered.
Can the SOC actually identify the attack quickly? Can analysts determine which systems are compromised? Can the team isolate affected endpoints? Can responders investigate the attack? Can the organisation restore systems securely?
A cyber drill provides an opportunity to test these practical capabilities.
A well-designed cyber drill can evaluate the incident lifecycle from initial detection through recovery.
1. Detection
Can the organisation recognise indicators of compromise? Can SOC analysts identify suspicious activity among legitimate events?
2. Investigation
Can the team determine:
What happened? How did the attacker gain access? Which systems are affected? What accounts were compromised? Has data been accessed or exfiltrated?
3. Containment
Can responders prevent the attack from spreading? Can affected systems or accounts be isolated appropriately?
4. Eradication
Can the underlying cause of the compromise be identified and removed?
5. Crisis Management
Can technical and business teams coordinate while the incident is evolving?
6. Recovery
Can affected systems and services be restored securely?
7. Lessons Learned
What worked? What failed? Where were the bottlenecks? Which controls or processes need improvement?
Ransomware provides a useful example of why practical testing matters.
A ransomware cyber drill can simulate:
Initial compromise → Persistence → Lateral movement → Encryption → Business disruption → Incident response → Recovery
Participants may need to:
The exercise can therefore expose weaknesses that may remain invisible during a policy review. The key question becomes:
If ransomware hit today, could we actually respond?
A cyber drill can be designed around the threats most relevant to the organisation.
Ransomware
Test detection, containment, business continuity and recovery.
Phishing and Credential Compromise
Evaluate how quickly compromised credentials are detected and contained.
Advanced Persistent Threats
Simulate a sophisticated attacker maintaining persistence and moving through the environment.
Insider Threats
Evaluate response to malicious or compromised legitimate accounts.
Data Breach
Test detection and investigation of unauthorised access and potential data exfiltration.
Business Email Compromise
Simulate compromise of executive or finance accounts and test the organisation’s response.
Critical Infrastructure Attacks
Test cyber resilience where disruption of critical systems can have significant operational consequences
Cybersecurity incidents rarely remain isolated to the SOC. Depending on the objectives, a cyber drill may involve:
The right participants depend on what the exercise is designed to test.
Cybersecurity readiness cannot be established by policies alone. An organisation can have excellent documentation, sophisticated security tools and experienced professionals and still encounter problems when an attack begins.
That is why exercises matter. A tabletop exercise can help organisations rehearse decisions, communication and coordination. A cyber drill can help them test practical response capabilities in a controlled environment.
The strongest cybersecurity programmes can use both because the goal is not simply to know how the organisation should respond. It is to know whether the organisation can respond when it matters.
TISS Cyber Drills use realistic attack scenarios and the Cydea Range cyber simulation environment to test cybersecurity teams in a controlled setting. Exercises can be customised around ransomware, phishing, credential compromise, APTs, insider threats, data breaches, business email compromise and critical infrastructure scenarios.