Security Training

University · Glossary

Cyber exercise and security training glossary

Field note

50 terms that appear in tabletop exercises, crisis simulations, cyber ranges and the rules that ask for them, defined in one to three sentences each. Terms that come from a standard or regulator link to it. Each term has its own anchor so it can be linked.

Editorial assessment · Assessed from vendor sites, product pages and published pricing, September 2026

Adaptive scenario
A scenario that changes in response to what players decide, rather than following a fixed script. Several platforms in this guide describe AI that adapts injects or plays the adversary.
After-action report (AAR)
The written record of an exercise: objectives, what happened, what worked, gaps found, and the actions assigned to fix them.Source: CISA Tabletop Exercise Packages
Asynchronous exercise
An exercise that participants complete at different times rather than together in one session. Useful when teams span time zones or shifts.
Attack chain
The sequence of steps an attacker takes from initial access to their objective. Exercises often release injects along it.
Blue team
The defenders in an exercise or organization, usually the SOC and incident responders.
Capture the flag (CTF)
A competition in which players solve security challenges to find hidden strings called flags.
Containment
The actions that stop an incident from spreading, such as isolating hosts or disabling accounts, taken before the threat is fully removed.Source: NIST SP 800-61 Rev. 3
Controller
The member of the exercise team who releases injects on schedule and keeps the scenario on track. In small exercises the facilitator also acts as controller.
Crisis simulation
An exercise in which decision-makers respond to a scenario that reacts to their choices, often through simulated emails, calls and media.
Cyber drill
A short operations-based exercise that practises one procedure or technical response. Immersive Labs uses the name Cyber Drills for exercises that bring technical and business teams together.Source: Immersive Labs
Cyber range
A controlled environment that simulates networks and tools so teams can practise detecting and responding to attacks.
Decision log
The timed record of who decided what during an exercise or incident, and on what information. It is the raw material for the after-action report.
Discussion-based exercise
An exercise in which players talk through what they would do, such as a tabletop, rather than performing actions on systems.
DORA (Digital Operational Resilience Act)
The EU regulation on ICT risk management, incident reporting and resilience testing for financial entities. Several vendors in this guide say their exercise evidence maps to it.
Dwell time
The time between an attacker's first access and its detection. Mandiant's M-Trends 2026 puts the global median for 2025 intrusions at 14 days.Source: Google Cloud, M-Trends 2026
Evaluator
The person who watches players against the exercise objectives and records evidence for the after-action report. An evaluator does not play or steer.
Executive sponsor
The senior leader who commissions an exercise, approves its scope and owns the follow-up actions. Without one, findings tend to stall.
Exercise objective
A statement of what an exercise tests, written so an evaluator can mark it met, partly met or not met. See the lesson on writing exercise objectives.
Facilitator
The person who runs an exercise, releases injects, keeps time and steers discussion toward decisions. The facilitator does not play.
Form 8-K Item 1.05
The SEC filing item a US public company uses to disclose a material cybersecurity incident, including its nature, scope, timing and impact. It is generally due four business days after the company determines the incident is material.Source: SEC press release 2023-139
Hotwash
A short debrief held immediately after an exercise to capture observations while they are fresh.
Incident commander
The person with overall authority for managing an incident response.
Incident response plan
The document that sets out how an organization detects, escalates, manages and recovers from security incidents, including who has authority for which decisions.Source: NIST SP 800-61 Rev. 3
Initial infection vector
The method an attacker first uses to gain access, such as an exploit, a phishing email or a phone call. M-Trends 2026 lists exploits as the most common vector for the sixth year running, at 32%.Source: Google Cloud, M-Trends 2026
Inject
A piece of information released during an exercise, such as an alert, a ransom note or a journalist's question, designed to force a decision.
ISO 22301
The international standard for business continuity management systems. It expects continuity arrangements to be exercised and tested.
ISO/IEC 27001
The international standard for an information security management system (ISMS). Exercise records are one kind of evidence that controls are operating.
Live-fire exercise
An exercise in which defenders respond to an attack actually running in a range.
Master scenario events list (MSEL)
The timed list of injects and expected player actions that drives an exercise.
Materiality determination
The decision on whether an incident is material. For US public companies it starts the clock on Form 8-K Item 1.05 disclosure, generally due four business days later.Source: SEC press release 2023-139
Microsimulation
A very short exercise, a few minutes long, for an individual or small group. iluminr uses the term for its 3–5 minute simulations.Source: iluminr
NIS2
The EU directive that sets cybersecurity risk management and incident reporting duties for essential and important entities. It replaced the original NIS Directive.
NIST Cybersecurity Framework (CSF) 2.0
NIST's framework for managing cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond and Recover. NIST SP 800-61 Rev. 3 is a CSF 2.0 Community Profile for incident response.Source: NIST SP 800-61 Rev. 3
Operational resilience
An organization's ability to keep delivering important services through a disruption, cyber or otherwise. iluminr, for example, lists UK operational resilience rules and APRA CPS 230 among its frameworks.
Operations-based exercise
An exercise in which players perform real actions, such as a drill or a range exercise, rather than discussing them.
Playbook
A step-by-step procedure for one type of incident, such as ransomware or a compromised account. Tabletop exercises often test whether the playbook matches what people actually do.
Purple team
A collaborative exercise in which attackers (red) and defenders (blue) work together to test and improve detections.
Readiness score
This site's editorial score from 0 to 10 for how well a platform helps a CISO exercise the people who respond to an incident. It is a weighted total of seven criteria, explained on How we assess.
Red team
People who emulate an attacker to test defences.
Regulation S-K Item 106
The SEC rule requiring US public companies to describe, in their annual report, their processes for managing material cybersecurity risk, the board's oversight of that risk, and management's role and expertise.Source: SEC press release 2023-139
Scenario
The storyline of an exercise: the incident, the affected systems and how it develops.
Scripted scenario
A scenario whose injects arrive in a fixed order whatever players decide. Easier to prepare and compare between sessions, but players can learn the script.
Security awareness training
Training for all employees on recognizing and reporting threats such as phishing.
Severity level
A rating that sets how serious an incident is and so who must be told and which procedures apply. Declaring it is often the first decision an exercise tests.
SOC (security operations center)
The team that monitors, detects and investigates security events.
Tabletop exercise (TTX)
A discussion-based exercise in which participants work through a scenario and decide what they would do.Source: CISA Tabletop Exercise Packages
Tabletop Exercise Package (CTEP)
CISA's free set of templates for running your own exercise: objectives, scenarios, discussion questions, a slide deck, a feedback form and an after-action report template.Source: CISA Tabletop Exercise Packages
Telemetry
Data from security tools, such as logs and alerts, used to detect and investigate activity.
Test, training and exercise (TT&E) program
NIST's term for a program of events that test plans, train staff and exercise procedures. NIST SP 800-84 (September 2006) is its guide to designing, conducting and evaluating TT&E events.Source: NIST SP 800-84
Threat actor
The person or group behind an attack, from criminal ransomware crews to state-backed groups. Scenarios are often based on how a named actor operates.

Sources: cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages, sec.gov/newsroom/press-releases/2023-139, iluminr.io, cloud.google.com/blog/topics/threat-intelligence/m-trends-2026, csrc.nist.gov/pubs/sp/800/84/final · Reviewed Sep 2026