Annual Tabletop Exercises Aren't Enough in 2026: The Shift to Continuous Readiness

Daigo Kobayashi
July 28, 2026
Annual tabletop exercises test a snapshot in time — not whether the plan still works twelve months later. This piece compares annual testing to continuous readiness, backed by 2025-2026 breach-cost and regulatory research, and lays out how to make the shift.

A once-a-year tabletop exercise proves a plan sounded right on exercise day. It doesn't prove the organization can execute that plan twelve months later, after roles, systems, and vendors have changed. Continuous readiness replaces the single annual event with an ongoing cycle of testing and evidence capture, so preparedness holds between exercises, not just during them.

Most resilience programs still run on an annual rhythm: one tabletop exercise, one after-action report, twelve months of silence until the next cycle. That rhythm was set by cost and logistics, not by how fast risk actually moves. Google Cloud's Cybersecurity Forecast 2026 reports that threat actors are moving from experimental to routine use of AI across the full attack lifecycle, scaling and automating campaigns at a pace static, annual testing wasn't built to track. At the same time, the regulators overseeing operational resilience are asking for continuous, documented evidence rather than a single yearly checkbox. The result is a widening gap between how often organizations test and how often they need to.

Key Takeaways

  • IBM and the Ponemon Institute's 2025 Cost of a Data Breach Report found that organizations testing incident response at least twice a year reduced breach costs by $1.49 million on average, compared with less frequent testing.
  • Traditional, fully facilitated tabletop exercises can cost tens of thousands of dollars and take weeks to prepare, which is a major reason most organizations still run just one a year and let skills atrophy in between.
  • DORA's supervisory cycle and NIS2 enforcement are pushing organizations from static policy documents toward continuous, structured evidence of testing and improvement.
  • Continuous readiness isn't "more tabletop exercises" — it's treating every exercise, incident, and after-action report as input into one ongoing, shared record of what's actually been validated.

What's Wrong With Running Tabletop Exercises Once a Year?

An annual tabletop exercise tests a snapshot of the organization as it existed on exercise day, not as it exists today. By month three, a new hire doesn't know the escalation path. By month six, a vendor relationship has changed. By month twelve, the "tested" plan has quietly gone twelve months untested, and nobody has noticed.

The problem is largely structural. A traditionally facilitated exercise, run by an outside firm or a stretched internal team, can cost tens of thousands of dollars and take weeks of preparation, which is why most organizations settle for one cycle a year at best (CSO Online, 2026). Skills fade in the gap between cycles, and new hires never participate in the one exercise their predecessor sat through. The cost of that gap is measurable: IBM and the Ponemon Institute's 2025 Cost of a Data Breach Report, which surveyed more than 600 organizations across 17 industries, found that organizations testing incident response at least twice a year reduced breach costs by $1.49 million on average compared with organizations that tested less often. Frequency isn't a nice-to-have — it's a cost line.

What Does "Continuous Readiness" Actually Mean?

Continuous readiness is an operating model, not a bigger exercise calendar. Instead of one large annual event, plans, exercises, evaluations, and after-action reports feed a shared, living record of what's actually been validated, so coverage gaps surface between cycles instead of showing up as a surprise the next time the plan is tested for real.

In practice, that means treating readiness as a loop rather than a project: identify what's changed and untested, prepare and prioritize fixes, run a smaller and more frequent exercise, evaluate what happened, verify the fix, and feed the result back into the plan for next time. This doesn't blur business continuity, disaster recovery, incident response, and crisis management into one discipline — each still has its own scope. What changes is how each discipline gets tested and evidenced over time, not what each discipline covers.

How Do Annual Tabletop Exercises Compare to Continuous Readiness Programs?

The practical differences show up in frequency, cost per cycle, and what evidence exists afterward. The table below compares a traditional annual tabletop exercise with a continuous readiness program across the dimensions that matter most to CISOs, compliance leaders, and their auditors.

DimensionAnnual Tabletop ExerciseContinuous Readiness Program
FrequencyOnce a year, often lessOngoing, in short cycles throughout the year
Cost per cycleTens of thousands of dollars; weeks of prepLower per-cycle cost once scenario design is reusable
Skill retentionFades between cycles; new hires miss the only exerciseReinforced continuously; new hires participate sooner
Evidence producedOne after-action report, often filed and forgottenA running record of findings, fixes, and verification
Regulatory alignmentPoint-in-time proof, hard to defend under auditContinuous evidence trail matched to testing requirements
ScalabilityLimited to one business unit or scenario per cycleRuns in parallel across units, sites, and scenarios

Why Are Regulators Pushing Organizations Toward Continuous Evidence?

Two of the most consequential resilience regulations now in force, DORA and NIS2, have moved past requiring a written plan and into requiring proof that the plan works — tested and documented on an ongoing basis, not demonstrated once and filed away.

DORA (Regulation (EU) 2022/2554) has applied since January 17, 2025, and 2026 marks its first full supervisory and audit cycle: financial entities are now expected to produce structured evidence of testing, corrective action, and ongoing oversight of ICT third parties, not just a policy binder (ComplianceHub.Wiki, 2026). NIS2 (Directive (EU) 2022/2555) is moving through the same shift across EU member states, with enforcement intensifying through 2026 as national authorities scrutinize risk-management measures more closely (ComplianceHub.Wiki, 2026). Neither regulation is satisfied by running one exercise a year and hoping the report holds up; both are built around the assumption that resilience is tested continuously.

What Role Does AI Play in Making Continuous Testing Practical?

AI lowers the cost and time barrier that made an annual cadence feel like the only option, by helping generate scenarios, draft playbooks, and summarize after-action findings, while leaving containment, notification, and disclosure decisions with a human reviewer.

Google Cloud's Cybersecurity Forecast 2026 describes this shift on the defender's side as well as the attacker's: AI-assisted "Agentic SOC" workflows can generate case summaries, decode commands, and map activity to frameworks like MITRE ATT&CK, freeing people to focus on validation and containment rather than manual assembly work. Opsbook, for example, uses AI to build a dynamic model of an organization from its existing documentation, then uses that model to recommend which playbooks, roles, and scenarios are due for validation, and to draft after-action findings once an exercise ends. Every recommendation routes through human review before it's published, and every finding traces back to its source, whether that's a document, an exercise, or a real incident.

How Do You Move From an Annual Tabletop to a Continuous Readiness Program?

  1. Audit what's actually validated, not assumed. List every playbook, role, and system dependency, and mark which ones have been tested in the last twelve months versus which are assumed current.
  2. Break the annual event into smaller, frequent drills. Replace one large tabletop with shorter, targeted sessions that test one team, role, or scenario at a time.
  3. Capture findings in one shared, structured record. Route every exercise's and incident's findings into the same system instead of a folder of separate slide decks and PDFs.
  4. Map evidence to the frameworks your auditors examine, as you go. Tag findings against DORA, NIS2, or whichever frameworks apply, so audit prep stops being an annual scramble.
  5. Close the loop. Feed verified findings back into the plans and playbooks the organization will use next time, so the next cycle starts further ahead than the last one did.

Conclusion

  • An annual tabletop exercise is a snapshot, not proof of ongoing readiness — twelve months is long enough for the tested plan to go stale.
  • Testing more often measurably reduces incident cost, per IBM and Ponemon's 2025 research, and gives regulators the continuous evidence DORA and NIS2 now expect.
  • Continuous readiness doesn't replace the tabletop exercise; it turns it from an annual event into one input among many in an ongoing record.
  • AI can lower the cost of testing more often, but the decisions still belong to a human reviewer, not the model.

Opsbook connects your organization's documents, playbooks, exercises, and after-action reports into one continuously improving intelligence layer, so readiness compounds between cycles instead of resetting every year. See how a continuous readiness program would look for your organization — book a walkthrough.

FAQs

How often should organizations test their incident response and continuity plans?
There's no single right cadence, but IBM and the Ponemon Institute's 2025 research found organizations testing at least twice a year cut breach costs by $1.49 million on average compared with less frequent testing. Higher-risk or heavily regulated organizations typically need shorter, more frequent cycles than lower-risk ones.
What's the difference between continuous readiness and simply running more tabletop exercises?
Running more exercises without connecting their findings just produces more individual after-action reports. Continuous readiness routes every exercise, incident, and evaluation into one shared, living record, so gaps surface between cycles and verified fixes carry forward into the next plan automatically.
Does continuous readiness satisfy DORA and NIS2 testing requirements?
Continuous readiness produces the kind of ongoing, documented evidence both DORA and NIS2 increasingly expect, but neither regulation is satisfied by a testing cadence alone. Organizations still need to map findings to the specific requirements of the framework that applies to them.
Opsbook

Let's Talk Resilience.

Dot grid pattern with varying sizes forming an abstract design in black and white.