GLOSSARY
The exercise vocabulary.
The terms that come up in scoping, running, and scoring a cyber tabletop exercise — grouped by where they show up in the process.
Terms by exercise phase
Roles & planning
- Tabletop Exercise (TTX)
- A discussion-based exercise in which participants walk through a simulated incident scenario to evaluate plans, roles, and decision-making without touching live systems.
- Executive Sponsor
- The senior leader who commissions the exercise, sets objectives and scope, and receives the after-action report. Owns the outcome, not the mechanics.
- Operator (Facilitator)
- Runs the exercise in real time: pacing injects, prompting discussion, keeping the scenario on the clock, and adjudicating how the situation evolves based on participant decisions.
- Participant (Player)
- A member of the team being exercised who responds to the scenario as they would in a real incident, using their own judgment rather than a scripted answer.
- Planning Guidance
- The upfront scope document — objectives, threat scenario, participants, and constraints — that shapes what the exercise will and will not test.
- Training Objective
- A specific, measurable capability or behavior the exercise is designed to evaluate, such as "validate the decision to notify regulators within the required window."
Exercise mechanics
- Situation Manual
- The reference document given to participants describing the exercise's purpose, ground rules, and background scenario before play begins.
- Master Scenario Events List (MSEL)
- The facilitator's master timeline of injects, expected discussion points, and pacing notes used to drive the exercise.
- Inject
- A discrete piece of scenario information — an email, alert, news clip, or phone call — introduced at a specific point to advance the situation and prompt a decision.
- Situation Update
- A short narrative addition that reveals how the simulated incident has progressed since the last inject, giving participants new facts to react to.
- Decision Point
- A moment in the exercise where participants must make and record a concrete choice, which the facilitator uses to branch or continue the scenario.
- ENDEX (End of Exercise)
- The formal end of exercise play, after which the scenario clock stops and the group transitions into hotwash and debrief.
- Hotwash
- An immediate, informal debrief held right after ENDEX to capture first impressions, standout moments, and gaps while they are still fresh.
Assessment
- After-Action Review / Improvement Plan (AAR/IP)
- The formal deliverable summarizing what happened, how it compared to objectives, and the specific corrective actions the organization commits to, with owners and timelines.
- Corrective Action
- A concrete, assigned follow-up task generated from an exercise finding — such as updating a runbook or clarifying an escalation path — tracked to closure.
Frameworks
- NIST Cybersecurity Framework (CSF) 2.0
- The National Institute of Standards and Technology (NIST) Cybersecurity Framework version 2.0, organizing cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, and Recover functions used to structure exercise objectives.
- Special Publication (SP) 800-61r3
- NIST's Incident Response Recommendations and Considerations, the primary federal guidance for building and exercising incident response processes.
- SP 800-84
- NIST guidance on Test, Training, and Exercise programs for information technology (IT) plans and capabilities, including how to design and evaluate tabletop exercises.
- SP 800-53 Incident Response (IR) family
- The Incident Response control family within NIST SP 800-53, covering requirements such as incident response training, testing, and plan maintenance that tabletop exercises help satisfy.
- Homeland Security Exercise and Evaluation Program (HSEEP)
- The Homeland Security Exercise and Evaluation Program, a Department of Homeland Security (DHS) / Federal Emergency Management Agency (FEMA) methodology for designing, conducting, and evaluating exercises across sectors.
- Cyber Tabletop Exercise Package (CTEP)
- The Cybersecurity and Infrastructure Security Agency (CISA)'s set of ready-made tabletop scenarios and facilitation guides for sector-specific cyber incidents.
Acronyms in full
- AI
- Artificial intelligence — used here for planning support, inject drafting, response evaluation, and after-action drafting.
- TTX
- Tabletop exercise — a discussion-based rehearsal of an incident, with no live systems touched.
- AAR
- After-action review — the written record of what happened in the exercise and what the organization will change.
- MFA
- Multi-factor authentication — requiring more than a password, such as an app prompt or hardware key, to sign in.
- SaaS
- Software-as-a-service — business applications delivered over the internet by a vendor rather than run in your own data center.
- OT
- Operational technology — the computers and controllers that run physical processes such as manufacturing, energy, or water treatment.
- ICS
- Industrial control system — the specific control equipment inside an operational technology environment.
- DDoS
- Distributed denial of service — flooding a service with traffic from many sources so legitimate users cannot reach it.
- BEC
- Business email compromise — fraud in which an attacker impersonates an executive, supplier, or colleague to redirect a payment.
- API
- Application programming interface — the machine-to-machine connection that lets one system call another.
- RMM
- Remote monitoring and management — the tools a service provider uses to administer customer computers remotely.
- EDR
- Endpoint detection and response — security software on laptops and servers that detects and blocks malicious activity.
- IR
- Incident response — the plan, team, and process for handling a security incident.
- SOC
- Security operations center — the team that monitors alerts and triages suspected incidents.
- UAC
- User Account Control — the Windows prompt that asks for approval before software gains administrator rights.
- CVE
- Common Vulnerabilities and Exposures — the public catalog that assigns each known vulnerability an identifier.
- PII
- Personally identifiable information — data that identifies a specific person, such as a name paired with a government number.
- RTO / RPO
- Recovery time objective and recovery point objective — how quickly a service must be restored, and how much recent data may be lost.
- SITREP
- Situation report — a short, timed status update issued during an incident or exercise.
- CSF
- Cybersecurity Framework — the National Institute of Standards and Technology model that organizes security outcomes into six functions.
Threat language
- Threat Actor
- The individual, group, or organization responsible for a malicious activity, often characterized by motive, capability, and typical targets.
- Attack Vector
- The specific path or method a threat actor uses to gain unauthorized access, such as phishing, an exposed remote service, or a compromised third party.
- Kill Chain
- A model describing the sequential stages of an attack, from reconnaissance through actions on objectives, used to frame where defenses and decisions apply.
- Dwell Time
- The length of time a threat actor remains undetected inside an environment between initial compromise and discovery.
- Breakout Time
- The time it takes an attacker to move from an initial compromised host to other systems on the network, a key metric for how fast defenders must respond.
- Double / Triple Extortion
- Ransomware tactics that add data theft (double) and pressure on victims' customers or partners (triple) on top of encrypting systems, increasing leverage over the victim.
- Recovery Denial
- An attacker action, such as deleting or encrypting backups, intended to remove an organization's ability to restore systems without paying or negotiating.
- Materiality (Securities and Exchange Commission, SEC)
- The Securities and Exchange Commission (SEC) standard for whether a cybersecurity incident is significant enough to a reasonable investor that it must be publicly disclosed, a judgment exercises can help rehearse.
- Notification Clock
- The regulatory or contractual countdown — often 72 hours or less — that starts once an incident is identified, within which breach notifications must be made.