Security Training

Dispatches · Myth and fact

Six cyber tabletop exercise myths, checked against published facts

Field note

Six beliefs that shape how teams exercise do not hold up well against public sources: that tabletops always take weeks to prepare, that they are for executives only, that awareness training covers incident response, that free materials are not worth using, that most incidents start with the security team's own alert, and that phishing emails are the main way in.

Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026

By Security Training assessors · 29 September 2026

7-1Myth 1: a tabletop always takes weeks to prepare

Fact: it depends on how you build it. A self-facilitated tabletop from a template does take weeks of preparation for a session of a few hours: someone has to adapt the scenario, write the injects, brief the players and write the report. Platforms change that. TryHackMe states a 10-minute average launch for its tabletops, Reflex Security describes a scenario built in minutes for a sixty-minute session, and Immersive Labs says its AI Program Builder drafts scenarios in minutes. These are vendor statements; ask how long the full cycle takes including the report.

7-2Myth 2: tabletops are for executives only

Fact: the decisions in a cyber incident run from the SOC to the boardroom, and several platforms put both in one exercise. Hack The Box Crisis Control can drop technical players into hands-on investigation during the tabletop. Cyberbit Crisis Sim 360 has SOC findings trigger decisions for executive, legal, communications and risk teams. A tabletop that only includes executives skips the handoffs between the SOC and the people who decide.

7-3Myth 3: awareness training covers incident response

Fact: they train different people for different jobs. Awareness platforms such as KnowBe4 teach every employee to spot and report threats such as phishing. Incident response exercises prepare the smaller group that runs an incident: the incident commander, technical leads, legal, communications and executives. KnowBe4's free Cybersecurity Awareness Month kit, released in August 2026, does include four tabletop exercise documents, which shows how the two meet, but a poster campaign does not test who decides to take a system offline.

7-4Myth 4: free exercise materials are not worth using

Fact: CISA publishes over 100 free Tabletop Exercise Packages, each with objectives, scenarios, discussion questions, a slide deck, a feedback form and an after-action report template, covering scenarios such as ransomware, insider threats, phishing and industrial control system compromise. They are the baseline every paid option should beat. What they do not do is run the session for you or react to what players decide.

7-5Myth 5: most incidents start with our own alert

Fact: in Mandiant's M-Trends 2026, 52% of intrusions investigated in 2025 were first detected internally, up from 43% the year before. That still means almost half were first reported from outside the organization. An exercise whose first inject is always an internal alert skips the call from a customer, a researcher or a law enforcement agency, and the scramble to verify it.

7-6Myth 6: phishing emails are the main way in

Fact: exploits were the most common initial infection vector in M-Trends 2026 for the sixth year running, at 32%. Voice phishing reached 11%, while email phishing fell to 6%. Prior compromise was the top vector for ransomware, at 30%. Scenarios built only around a phishing email miss the exploited edge device and the help desk call. Our 2026 scenarios article has one of each.

7-7What should you take from this?

Pick the format for the gap, pick the scenario for the decision it forces, and invite the people who make that decision, including the technical team. Start from the free CISA materials if budget is tight, and judge any platform by the preparation time it saves and the evidence it leaves. The rankings compare the seven platforms we score on those terms.

Sources

  1. CISA Tabletop Exercise Packages: https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
  2. Google Cloud, M-Trends 2026: https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
  3. KnowBe4, awareness month kit: https://www.knowbe4.com/press/knowbe4-releases-free-cybersecurity-awareness-month-resource-kit
  4. TryHackMe tabletop exercises: https://tryhackme.com/business/solutions/tabletop-exercises
  5. Hack The Box tabletop exercises: https://www.hackthebox.com/business/tabletop-exercises
  6. Cyberbit Crisis Sim 360: https://www.cyberbit.com/product/crisis-simulation/
  7. Reflex Security: https://reflexsecurity.io/