Program Building Tabletop

A zero-day tabletop for vulnerability teams

October 1, 2026·9 min read·Chris Boker, Founder, CVEasy AI
A long paper tabletop runs across the frame, four green capability pillars stand along its back edge each stamped with a distinct glyph for inventory, authority, hunt, and comms, a scatter of surface advisory cards and gold inject cards is dealt across the top of the table, a dark exercise cell lamp casts a cone of light over the cards and the pillars, and a vertical mint ribbon marks the twenty four hour mark on the left side of the table.

At 2am a pager fires on a CVSS 10.0 advisory for a vendor you use. The engineering lead signs on, the on-call manager signs on, the SOC lead signs on, and the first ninety seconds of the call are spent trying to answer a question nobody wrote down in peacetime: do we run the affected product, which versions, and which instances are reachable from the open internet. Hour one of a mass-exploitation event almost always begins there, and almost no exercise most teams have ever run started there. Our first 48 hours playbook is the live-fire sequence; this piece is the rehearsal of it, and it borrows none of that playbook's hour bands by design.

The gap is methodological, not cultural. Incident-response tabletops are a mature discipline. Nobody publishes an exercise where the premise is that something happened to a vendor and the first job is to find out whether it happened to you at all. That question is absent from the IR tabletop because IR exercises start after it has been answered. Three regulatory clocks and one pre-disclosure case now make the gap expensive, which is why vulnerability teams should rehearse the question before the next advisory lands.

Credit where the ground is already covered

Tabletop exercise theory is not thin, and this framework builds on top of it, not around it. CISA publishes free Tabletop Exercise Packages (CTEP) with facilitator guides, situation manuals, and participant materials covering ransomware, insider threat, cyber supply chain, and more. The methodological foundation is NIST SP 800-84, the guide for test, training, and exercise programs for IT plans and capabilities, which codifies the discussion-based and operations-based categories most practitioners use today. The SANS incident handler curriculum has carried similar material for two decades. If a team wants an IR tabletop, the material already exists, and this framework points at it rather than replacing it.

The common thread across every published package is the same: they rehearse an incident, where the premise is that something already happened to the organization running the exercise. The decision chain starts at containment and ends at recovery. The vulnerability team's first forty-five minutes in a mass-exploitation event sit upstream of that chain, in a region the published packages do not cover.

Three clocks that make the rehearsal gap expensive

Under BOD 26-04, three days became the default remediation window for anything exposed and actively exploited. Of 39 CVEs CISA added to the Known Exploited Vulnerabilities catalog between June 10 and July 29, 2026, thirty four carried a three-day-or-less deadline. The three-day band is not an exception any more; it is the shape of the default. Private-sector teams inherit the shape by procurement pressure and by the behaviour of the ecosystem their partners live inside.

From September 11, 2026 the EU Cyber Resilience Act reporting duty attaches a 24-hour early warning clock to manufacturers of products with digital elements the moment they become aware of active exploitation, with a 72-hour notification duty behind it. Any team that ships software into the EU now runs a parallel regulatory clock on top of the technical one. Hour six of the exercise is the wrong time to discover who signs the ENISA filing.

The pre-disclosure case is documented rather than theoretical. Interlock ransomware affiliates exploited Cisco firewall management CVE-2026-20131 (CVSS 10.0) from January 26, 2026, more than a month before the advisory was published, as recounted in our live-fire playbook. The exercise therefore has to include at least one inject where the advisory arrives after the intrusion did, because that is the data the industry now has.

VulnCheck's 1H 2026 report adds the macro texture: 495 CVEs were added to KEV in the half, median time from CVE publication to KEV evidence fell from 120 days in 2025 to 80 days, and content management systems were about one third of all KEV additions, the highest share VulnCheck has ever recorded. Verizon's 2026 DBIR put vulnerability exploitation at 31% of initial access, the first time in nineteen years it passed stolen credentials, and lifted edge appliances and VPNs from 3% to 22% of exploitation-driven breaches. The exercise's scenario choice should reflect those shapes. A CMS exposure is a useful scenario because most teams do not have a CMS on their crown-jewel list.

The four capability tests, each with a pass or fail condition

A good vulnerability tabletop is scored, not discussed. Four capabilities decide whether hour one leaks into hour six, each with a condition the facilitator can mark pass or fail on the spot.

  • Asset answerability. Within thirty minutes of the inject, produce a written list of affected assets by version, sorted by internet exposure and tagged with named owner, inside the ticketing system and not in chat. A shared screen with a query result is a fail.
  • Mitigation authority. Name the single human who can approve an emergency configuration change at 2am without a change advisory board. If the room cannot name that person, or if the person named cannot be reached inside twenty minutes in the drill, the capability fails.
  • Detection pivot. Convert the advisory's technical surface into at least two behaviour hunt hypotheses within sixty minutes and run them as backfill against the last thirty days of telemetry. A query that only looks forward from now is a fail, because Interlock, SolarWinds, and the long tail of pre-disclosure cases teach that the clock often began weeks ago.
  • Comms discipline. Produce three draft notices by hour four: an internal engineering notice, a business-owner notice, and (for CRA-scope products) the 24-hour ENISA early-warning skeleton. Approval is from legal and corporate communications in advance of the exercise, not during it. If any of the three has to be composed from a blank page during the drill, the capability fails.

An inject set that bites

Most published injects are kind to the exercise. The ones that teach are the uncomfortable ones. Deal them at realistic timestamps against a composite scenario, never against a named real vendor or victim.

  • At minute zero, a CVSS 10.0 advisory lands against a product your composite organization uses. The affected version range is a superset of what the vendor originally posted.
  • At minute forty, the first vendor mitigation (a configuration change) is published, and testing in your composite staging environment shows it breaks a load balancer health check.
  • At hour two, a researcher posts a proof-of-concept to a public gist. The exploit path differs slightly from the advisory text.
  • At hour three, your SIEM team surfaces a thirty-day backfill hit against one asset that does not appear in the asset management system. Nobody in the drill owns it.
  • At hour five, your legal counsel asks whether this is a CRA-scope product and whether the 24-hour ENISA clock has started.
  • At hour eight, the vendor revises the advisory. One previously unaffected version is now listed, and one previously affected version has been removed.
  • At hour twelve, a sales engineer forwards a customer email asking what you are doing about it. Nobody has told sales the exercise is running, which is the point.

Scoring the exercise, converting gaps into a dated backlog

The facilitator keeps a scoring sheet with the four capability lines and a timestamped log. At the end of the drill, each failed capability becomes a backlog item with an owner, a target date, and a measurable completion condition. "Improve asset management" is not a backlog item. "The internet-facing asset list for the top ten vendor products is a one-click report in the asset identity graph by November 15" is. The asset identity graph and the evidence architecture are the usual load-bearing dependencies that surface here, and surfacing them in peacetime is the whole point of the drill.

A good after-action report lists the four capabilities, the pass or fail decision, the timestamped evidence behind the decision, and the dated backlog item that follows. It is one page. If it is longer than one page it will not be read, and the point of the drill was never the report.

A composite scenario you can run tomorrow

Call it the Riverstone CMS advisory. Riverstone is a fictional open-source content management system in widespread marketing-site use. On exercise day, the first inject is a CISA advisory listing Riverstone 4.8.x through 5.2.3 as actively exploited, CVSS 9.9, with a KEV entry under BOD 26-04 three-day treatment. The facilitator holds the subsequent injects on a timer so the room cannot skip ahead. Participants are the vulnerability lead, the detection lead, the on-call platform engineer, a business-side communications lead, a legal counsel, and a facilitator-observer who keeps the scoring sheet.

The scenario works because most teams do not pre-build a crown-jewel list that includes marketing CMS instances, which is the state VulnCheck's one-third-of-KEV statistic predicts the industry walks in with. The capabilities get tested where they are weakest, which is the only interesting place to test them. Run the drill once a quarter, rotate the scenario between a CMS exposure, an edge-appliance exposure, and an identity-plane exposure, so the muscle covers the three categories doing most of the damage in 2026.

Where this fits in the program

Our local-first Continuous Threat Exposure Management platform exists to shorten the gap between advisory and asset answer so the first capability test does not fail in production, and TRIS holds the exposure band on every affected asset so the ordered list for hour one is already there. The tabletop is the receipt that the program can meet those tests when the night actually comes.