One tabletop a year is not a program. It is a compliance checkbox that happens to look like a program, and most organizations that run exactly one exercise annually have convinced themselves the box and the program are the same thing. They are not, and the gap between them is where breaches turn expensive.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
What the Data Actually Shows
A 2021 Ponemon Institute survey of 3,600 IT and security professionals worldwide, cited by Statista, found that only 35% of organizations review or test their cybersecurity incident response plan on an annual cadence, and just 13% do so more often than that (7% quarterly, 6% semiannually). Meanwhile 40% review on no set schedule at all, and 12% had not reviewed their plan since it was written. Read that carefully. Annual testing is not the floor most organizations sit at. It is closer to the ceiling. The plurality of organizations test less than once a year or not at all, which means the "minimum" framing in most industry conversations already flatters the actual state of practice.
NIST addressed this directly in Special Publication 800-61 Revision 3, its updated incident response framework. The revision restructures the traditional post-incident phase into what it calls a persistent Improvement category rather than a terminal step that closes out after each incident. NIST does not mandate a specific exercise frequency in the document, but the structural change is the point. A framework built around continuous improvement is not compatible with an exercise cadence that touches the plan once a year and leaves it untouched for the other eleven months. If your improvement process only runs annually, you do not have a continuous improvement process, you have an annual one wearing different language.
Why Annual Fails on Its Own Terms
Set aside the AI-driven threat acceleration for a moment and the case against annual-only cadence still holds, for three separate reasons that compound each other.
The first is organizational turnover. Most companies see meaningful staff movement within a twelve-month window, in security teams, in IT, in the executive roles who make crisis-level decisions during an incident. An exercise run in January tells you nothing reliable about how the team assembled in October will perform, because it is not the same team, or not entirely.
The second is plan drift. Systems change, vendors change, cloud architecture changes, and incident response plans reference specific tools, specific escalation paths, and specific contacts that go stale continuously, not on an annual schedule. A plan tested once a year is validated against an environment that, by month eight or nine, may no longer exist in the form the plan describes.
The third is skill decay. Tabletop performance is a skill, not a one-time credential. The specific behaviors an exercise is meant to build, calm decision-making under pressure, knowing who to call and in what order, resisting the urge to skip verification steps under time pressure, degrade over months without practice the same way any infrequently used skill does. An organization that trains a muscle once a year and expects it to hold for the other fifty-one weeks is applying a fitness standard nobody would accept in any other high-stakes discipline.
The Worked Example
Consider a 400-person financial services firm that ran a single ransomware tabletop every January for three years running, always with strong debrief scores and a clean after-action report. In September of the third year, a real incident hit, a compromised vendor credential led to unauthorized access to a document repository. The incident response lead who ran point in every prior tabletop had left the company in June. His replacement, three months into the role, had reviewed the plan but never exercised it. The legal escalation contact listed in the plan had changed roles internally and the plan still listed her old title and reporting line. Containment, which the January tabletop consistently completed in under two hours, took closer to nine, largely because the team spent the first ninety minutes figuring out who had authority to make containment decisions. Every element that failed had been tested successfully in January. None of it held by September.
The Cadence Worth Recommending
Run a full tabletop exercise at minimum twice a year, spaced roughly six months apart, with at least one additional lightweight exercise, a shorter functional drill or a partial-scope walkthrough of a single process, in between. Twice a year is not an arbitrary compromise. It is short enough to catch turnover and plan drift within a single cycle, and long enough that most organizations can sustain it without treating every exercise as a fire drill that exhausts goodwill. Add a third trigger-based exercise whenever a major change occurs, a new executive in an incident response role, a significant infrastructure migration, or a new attack pattern relevant to your sector becoming active. Cadence should respond to change, not just the calendar.
The Strongest Case for Staying Annual
The honest counterargument deserves full weight. Tabletop exercises are expensive in ways that do not show up cleanly on a budget line. They pull senior executives, legal counsel, and technical leads out of their actual jobs for half a day or more, multiple times, and the opportunity cost for a lean security team running a dozen other priorities is real. A security leader defending a single annual exercise can reasonably argue that the marginal value of a second exercise is lower than the marginal cost of pulling the same executives away from revenue-generating or risk-reducing work twice, and that budget is better spent on prevention, detection tooling, or headcount than on repeated rehearsal.
That argument holds when it is comparing two full-scale, all-hands exercises. It collapses once you separate the format from the depth. The second and third exercises in a twice-a-year-plus-trigger cadence do not need to be full-scale. A ninety-minute functional walkthrough with the incident response core team, without pulling in every executive stakeholder, tests turnover and drift at a fraction of the cost of a full exercise, and it is the format that actually catches the failure modes described above. The cost argument is a strong reason to vary exercise scope. It is not a strong reason to run the deepest version only once a year and nothing else.
Monday Questions for Leadership and the Board
When was our incident response plan last tested against the team as it exists today, not as it existed at the start of the year.
How many of the people who ran point in our last exercise are still in the same role.
What is our plan for the eight to ten months between exercises when nothing is being tested at all.
If a real incident hit next week, would the first ninety minutes look like our last tabletop, or like something we have never actually rehearsed.
The Line That Matters
An incident response plan tested once a year is a photograph of readiness, not a measure of it, and photographs go out of date the moment the picture is taken.