GLOSSARY

The exercise vocabulary.

The terms that come up in scoping, running, and scoring a cyber tabletop exercise — grouped by where they show up in the process.

Terms by exercise phase

Roles & planning

Tabletop Exercise (TTX)
A discussion-based exercise in which participants walk through a simulated incident scenario to evaluate plans, roles, and decision-making without touching live systems.
Executive Sponsor
The senior leader who commissions the exercise, sets objectives and scope, and receives the after-action report. Owns the outcome, not the mechanics.
Operator (Facilitator)
Runs the exercise in real time: pacing injects, prompting discussion, keeping the scenario on the clock, and adjudicating how the situation evolves based on participant decisions.
Participant (Player)
A member of the team being exercised who responds to the scenario as they would in a real incident, using their own judgment rather than a scripted answer.
Planning Guidance
The upfront scope document — objectives, threat scenario, participants, and constraints — that shapes what the exercise will and will not test.
Training Objective
A specific, measurable capability or behavior the exercise is designed to evaluate, such as "validate the decision to notify regulators within the required window."

Exercise mechanics

Situation Manual
The reference document given to participants describing the exercise's purpose, ground rules, and background scenario before play begins.
Master Scenario Events List (MSEL)
The facilitator's master timeline of injects, expected discussion points, and pacing notes used to drive the exercise.
Inject
A discrete piece of scenario information — an email, alert, news clip, or phone call — introduced at a specific point to advance the situation and prompt a decision.
Situation Update
A short narrative addition that reveals how the simulated incident has progressed since the last inject, giving participants new facts to react to.
Decision Point
A moment in the exercise where participants must make and record a concrete choice, which the facilitator uses to branch or continue the scenario.
ENDEX (End of Exercise)
The formal end of exercise play, after which the scenario clock stops and the group transitions into hotwash and debrief.
Hotwash
An immediate, informal debrief held right after ENDEX to capture first impressions, standout moments, and gaps while they are still fresh.

Assessment

After-Action Review / Improvement Plan (AAR/IP)
The formal deliverable summarizing what happened, how it compared to objectives, and the specific corrective actions the organization commits to, with owners and timelines.
Corrective Action
A concrete, assigned follow-up task generated from an exercise finding — such as updating a runbook or clarifying an escalation path — tracked to closure.

Frameworks

NIST Cybersecurity Framework (CSF) 2.0
The National Institute of Standards and Technology (NIST) Cybersecurity Framework version 2.0, organizing cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, and Recover functions used to structure exercise objectives.
Special Publication (SP) 800-61r3
NIST's Incident Response Recommendations and Considerations, the primary federal guidance for building and exercising incident response processes.
SP 800-84
NIST guidance on Test, Training, and Exercise programs for information technology (IT) plans and capabilities, including how to design and evaluate tabletop exercises.
SP 800-53 Incident Response (IR) family
The Incident Response control family within NIST SP 800-53, covering requirements such as incident response training, testing, and plan maintenance that tabletop exercises help satisfy.
Homeland Security Exercise and Evaluation Program (HSEEP)
The Homeland Security Exercise and Evaluation Program, a Department of Homeland Security (DHS) / Federal Emergency Management Agency (FEMA) methodology for designing, conducting, and evaluating exercises across sectors.
Cyber Tabletop Exercise Package (CTEP)
The Cybersecurity and Infrastructure Security Agency (CISA)'s set of ready-made tabletop scenarios and facilitation guides for sector-specific cyber incidents.

Acronyms in full

AI
Artificial intelligence — used here for planning support, inject drafting, response evaluation, and after-action drafting.
TTX
Tabletop exercise — a discussion-based rehearsal of an incident, with no live systems touched.
AAR
After-action review — the written record of what happened in the exercise and what the organization will change.
MFA
Multi-factor authentication — requiring more than a password, such as an app prompt or hardware key, to sign in.
SaaS
Software-as-a-service — business applications delivered over the internet by a vendor rather than run in your own data center.
OT
Operational technology — the computers and controllers that run physical processes such as manufacturing, energy, or water treatment.
ICS
Industrial control system — the specific control equipment inside an operational technology environment.
DDoS
Distributed denial of service — flooding a service with traffic from many sources so legitimate users cannot reach it.
BEC
Business email compromise — fraud in which an attacker impersonates an executive, supplier, or colleague to redirect a payment.
API
Application programming interface — the machine-to-machine connection that lets one system call another.
RMM
Remote monitoring and management — the tools a service provider uses to administer customer computers remotely.
EDR
Endpoint detection and response — security software on laptops and servers that detects and blocks malicious activity.
IR
Incident response — the plan, team, and process for handling a security incident.
SOC
Security operations center — the team that monitors alerts and triages suspected incidents.
UAC
User Account Control — the Windows prompt that asks for approval before software gains administrator rights.
CVE
Common Vulnerabilities and Exposures — the public catalog that assigns each known vulnerability an identifier.
PII
Personally identifiable information — data that identifies a specific person, such as a name paired with a government number.
RTO / RPO
Recovery time objective and recovery point objective — how quickly a service must be restored, and how much recent data may be lost.
SITREP
Situation report — a short, timed status update issued during an incident or exercise.
CSF
Cybersecurity Framework — the National Institute of Standards and Technology model that organizes security outcomes into six functions.

Threat language

Threat Actor
The individual, group, or organization responsible for a malicious activity, often characterized by motive, capability, and typical targets.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access, such as phishing, an exposed remote service, or a compromised third party.
Kill Chain
A model describing the sequential stages of an attack, from reconnaissance through actions on objectives, used to frame where defenses and decisions apply.
Dwell Time
The length of time a threat actor remains undetected inside an environment between initial compromise and discovery.
Breakout Time
The time it takes an attacker to move from an initial compromised host to other systems on the network, a key metric for how fast defenders must respond.
Double / Triple Extortion
Ransomware tactics that add data theft (double) and pressure on victims' customers or partners (triple) on top of encrypting systems, increasing leverage over the victim.
Recovery Denial
An attacker action, such as deleting or encrypting backups, intended to remove an organization's ability to restore systems without paying or negotiating.
Materiality (Securities and Exchange Commission, SEC)
The Securities and Exchange Commission (SEC) standard for whether a cybersecurity incident is significant enough to a reasonable investor that it must be publicly disclosed, a judgment exercises can help rehearse.
Notification Clock
The regulatory or contractual countdown — often 72 hours or less — that starts once an incident is identified, within which breach notifications must be made.