Security Training

University · Evidence and programs · Lesson 11

How to build an annual cyber exercise program

Field note

A program is a calendar of exercises that covers each audience, moves from discussion to operations, and retests the gaps from the last exercise. Start with the audiences in the exercise matrix, schedule the formats each one needs, set a retest date for every finding, and track three measures from one exercise to the next.

Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026

By Security Training assessors · 22 September 2026

L11-1What turns exercises into a program?

NIST SP 800-84 describes a test, training and exercise (TT&E) program: a planned set of events that test plans, train staff and exercise procedures, rather than a single event. The difference in practice is memory. A program carries each exercise's findings into the next one and checks whether they were fixed.

L11-2Who needs exercising, and in what format?

Use the four audiences in our exercise matrix: executives and board, the cross-functional incident response team, SOC analysts, and the whole company. Each needs a different format.

  • Executives and board: tabletop or crisis simulation on the decisions reserved for them.
  • Incident response team: tabletops and crisis simulations, then operations-based drills.
  • SOC analysts: hands-on labs for skills and live-fire range exercises for detection and containment.
  • Whole company: awareness training, which is a separate purchase from everything above.

L11-3How should the year be sequenced?

Discussion before operations. A tabletop agrees who decides; a drill or range exercise then tests whether the team can execute. A simple pattern: a cross-functional tabletop early in the year, operations-based exercises for the technical team after it, a second tabletop on a different scenario later in the year, and a retest of the top gaps before the year ends. Rotate scenarios; our 2026 scenarios article lists five tied to current attack data.

L11-4How often is realistic?

As often as preparation allows, which is why effort to run matters. A hand-built tabletop with a CISA package takes weeks of preparation. Vendors describe much shorter formats: iluminr's microsimulations run 3–5 minutes for an individual and 30–45 minutes for a team; Reflex Security describes a sixty-minute session; TryHackMe states a 10-minute average launch for its tabletops. Treat these as vendor statements, and ask how long the whole cycle takes including the report.

L11-5What should you measure?

  • Objectives met: the share of objectives marked met, compared across exercises of similar difficulty.
  • Time to key decisions: for example, from first alert to severity declaration, or from scoping to a materiality determination.
  • Gaps closed: the share of findings fixed and retested by their due date.

Report these to the executive sponsor after each exercise, and to the board once or twice a year. A before-and-after comparison on the same measures says more than any single exercise score.

L11-6What does a program cost?

The free baseline is CISA's Tabletop Exercise Packages, which cost staff time rather than money. Platforms trade licence cost for preparation time. Most vendors in this guide publish no price; the calculator shows the two that do, and the pricing article sets out what is published.

Sources: csrc.nist.gov/pubs/sp/800/84/final, cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages · Reviewed Sep 2026

Next lesson: Back to the University hub