Cyber Security Blog

How Cyber Tabletop Exercises Align with the UK CAF Principles

Written by Aditi Uberoi | 26 August 2026

The NCSC Cyber Assessment Framework asks a demanding question that cannot be answered by policy documents alone: Can an organisation demonstrate that its essential functions are genuinely resilient to cyber disruption? A well-designed Cyber Crisis Tabletop Exercise (or cyber drill) helps answer that question by placing real people and established plans inside a credible incident scenario. It then reveals how the organisation makes critical decisions when information is incomplete and time is limited.

That makes the relationship between Cyber Crisis Tabletop Exercises and the NCSC CAF unusually practical. The exercise does not replace a CAF assessment, and participation should never be presented as proof that every relevant outcome has been achieved. It does, however, create a valuable body of operational evidence. It can show whether governance arrangements work under pressure, whether response plans are understood, whether technical alerts reach decision-makers and whether lessons are converted into measurable improvements.

For organisations preparing for a regulator-led review, a GovAssure assessment or an internal CAF maturity programme, that distinction is important. The strongest evidence rarely consists of a document viewed in isolation. Assessors need confidence that policies are embedded, roles are understood and capabilities can be enacted when an incident threatens the continuity of an essential function. A properly scoped Cybersecurity Tabletop Exercise can help make that evidence visible.

The CAF is an Outcomes-Based Framework, Not a Compliance Checklist

The current Cyber Assessment Framework is CAF version 4.0, which the NCSC released in August 2025. It is organised around four high-level objectives, fourteen cyber security and resilience principles and forty-one contributing outcomes. Each contributing outcome is assessed using Indicators of Good Practice, although the NCSC is clear that those indicators inform expert judgement rather than creating an inflexible checklist.

This outcomes-led design explains why realistic exercises matter so much. A written incident response plan may indicate that an organisation has considered its approach, but the document cannot prove that participants understand their responsibilities or that critical information will reach the right person. It cannot demonstrate that decision authority is delegated sensibly, that recovery priorities reflect essential functions or that third-party escalation routes remain workable during a live crisis.

A tabletop exercise adds behavioural and operational evidence to the documentary record. Participants work through a threat-led scenario, receive new information through timed injects and explain what they would do at each stage. Skilled facilitation then tests the assumptions beneath those answers, including who owns the decision, which evidence is available and what happens when the expected process fails.

The value therefore comes from more than rehearsal. A cybersecurity tabletop drill creates a structured opportunity to compare stated arrangements with likely behaviour, which is closely aligned with the CAF’s focus on outcomes that can be demonstrated.

Where Cyber Tabletop Exercises Provide the Strongest CAF Evidence

The clearest alignment appears within Objective D, particularly the D1.c outcome on testing and exercising. The NCSC guidance for Principle D1 explicitly expects organisations to exercise response plans across realistic scenarios. Those scenarios should draw on risk assessments, threat intelligence and previous incidents, while findings should be documented and used to refine response plans and protective security.

The influence of a tabletop exercise extends well beyond D1.c because an incident rarely respects organisational boundaries. A convincing scenario forces governance, risk management, security monitoring, business continuity and communications to operate as one response system. It can also expose uncertainty around suppliers, technical dependencies and recovery priorities that may otherwise remain hidden until a genuine disruption occurs.

The four CAF objectives provide a useful way to understand that wider contribution.

CAF objective

Cyber Drill Focus

Evidence a well-designed exercise can produce

Objective A: Managing Security Risk

Governance, accountability, risk-based decisions and supply-chain dependencies.

Decision records, observed escalation paths, ownership gaps and actions linked to identified risks.

Objective B: Protecting Against Cyber Attacks

Usability of policies, resilience arrangements, recovery dependencies and role-based capability.

Evidence that procedures can be followed, recovery assumptions can be challenged and participants understand their responsibilities.

Objective C: Detecting Cyber Security Events

Alert quality, triage, investigation, escalation and shared situational awareness.

Observations on whether monitoring information supports timely decisions and whether technical findings are communicated effectively.

Objective D: Minimising the Impact of Cyber Security Incidents

Response, containment, continuity, recovery and continual improvement.

Exercise records, a post-exercise report, prioritised remediation and evidence that lessons inform updated plans.

 

Objective A: Managing Security Risk

A1 Governance

Principle A1 expects security governance to be led through clear structures, defined accountability and effective decision-making. Its contributing outcomes cover board direction, roles and responsibilities and the delegation of authority, all of which can be tested directly during an executive or cross-functional tabletop exercise.

The scenario may require leaders to decide whether to isolate a revenue-generating service, notify a regulator or communicate publicly before the technical position is certain. The quality of the answer matters, but the route by which the decision is reached is equally revealing. Facilitators can observe whether the responsible executive is clear, whether the board receives timely information and whether risk appetite offers meaningful guidance when commercial and operational pressures conflict.

This creates evidence that governance is understood in practice, rather than simply described in a chart. It can also expose decisions that are routinely escalated too far, responsibilities that sit between teams or authority that exists on paper but disappears during a crisis.

A2 Risk Management

Principle A2 requires an organisation to identify and understand risks to essential functions, using current threat assumptions and a systematic risk management process. A CAF-aligned incident response tabletop exercise should therefore begin with the organisation’s risk landscape rather than a generic ransomware narrative that could apply to any business.

Exercise design should consider the threat actors that are credible for the sector, the vulnerabilities most relevant to critical systems and the business impacts the organisation has already judged unacceptable. When that preparation is done properly, the scenario becomes a practical test of whether risk assessments describe how harm could arise and whether the resulting mitigations remain effective when challenged.

The exercise can also uncover risks that have been underestimated or described too narrowly. A seemingly technical compromise may reveal a concentration of knowledge, an undocumented dependency or a decision bottleneck that changes the real exposure of an essential function. Those findings should feed back into the risk process, but the exercise itself does not replace technical assurance or a complete risk assessment.

A3 Asset Management

Principle A3 concerns the assets, dependencies and information required to operate essential functions. A discussion-based exercise cannot verify the accuracy of an asset inventory, although it can reveal where asset knowledge is incomplete or difficult to access when the organisation needs it most.

Participants may discover that nobody can confirm which systems support a priority service, which data must be restored first or which individual holds essential recovery knowledge. These observations provide supporting evidence for an asset management review and can help direct deeper technical validation after the exercise.

A4 Supply Chain

Principle A4 expects organisations to understand and manage supplier risks, including the role of third parties in security incident management. A tabletop exercise can test that expectation by making a supplier part of the scenario, rather than treating the organisation as a self-contained environment.

A cloud outage, compromised software provider or unavailable managed service partner can expose whether contact routes are current and whether contracts support the response that leaders assume is available. The exercise can also test who receives supplier intelligence, how assurance is interpreted and whether business continuity plans account for a third party that cannot meet its normal obligations.

The result is not a complete supply-chain assessment, although it offers strong evidence about the organisation’s ability to coordinate a response across external dependencies. It also helps identify where contractual terms and operational practice have drifted apart.

Objective B: Protecting Against Cyber Attacks

B1 Service Protection Policies, Processes and Procedures

CAF Principle B1 expects security policies and procedures to be practical, communicated and implemented, with evidence that they deliver security benefits. A tabletop exercise is an effective way to test whether those documents remain usable when participants must make decisions quickly and work across departmental boundaries.

An exercise may reveal that the incident response plan uses an obsolete severity model, that a communications procedure depends on unavailable systems or that separate teams follow incompatible escalation routes. These findings help demonstrate whether policies are embedded and can inform the regular review expected by the CAF.

The point is not to catch people making mistakes. The more useful question is whether the documented process supports the behaviour the organisation will need during a real incident, especially when the situation does not match the example described in the plan.

B2 Identity and Access Control, B3 Data Security and B4 System Security

These protective principles are normally assessed through technical evidence, operating records and specialist assurance, so a tabletop exercise should not be treated as proof that access controls, data protections or system configurations are effective. Its contribution depends on the scenario and the depth of technical participation.

A privileged-account compromise can test how access is revoked and how emergency credentials are governed. A data-exfiltration scenario can examine whether teams understand the sensitivity and integrity of affected information, while an exploited vulnerability can test the decisions surrounding containment, evidence preservation and urgent mitigation.

These discussions provide useful supporting evidence because they connect technical controls to response behaviour. They may also identify where participants assume a capability exists without having verified it, which gives the organisation a precise question for subsequent technical testing.

B5 Resilient Networks and Systems

Principle B5 has a strong relationship with well-designed operational and technical exercises. The B5.a outcome on resilience preparation expects business continuity and disaster recovery arrangements to be tested for practicality, effectiveness and completeness, with tabletop exercises named as one appropriate testing method.

An exercise can examine whether the organisation understands the systems and dependencies needed to restore an essential function, along with the order in which recovery must occur. It can challenge assumptions about clean backups, alternate communications and the availability of specialist knowledge. It can also expose a gap between the recovery time the business expects and the time technical teams believe they can achieve.

However, a discussion about recovery is not the same as demonstrating failover or restoring data from backup. A mature assurance programme uses the tabletop to test coordination and decision-making, then combines those findings with technical recovery tests that prove the underlying mechanisms work.

B6 Staff Awareness and Training

Principle B6 expects people supporting essential functions to have the knowledge and skills required for their roles, alongside a positive culture in which cyber security is treated as a shared responsibility. A cyber tabletop exercise supports both outcomes because participants learn through realistic decisions rather than passive instruction.

The exercise gives executives, technical specialists and business teams a common view of the incident lifecycle. It also helps participants understand how their actions affect other functions, which can improve communication and reduce the tendency to treat a cyber crisis as an issue owned only by IT.

Training value should still be measured with care. Attendance alone says little about capability, while observed performance and the closure of identified gaps provide stronger evidence that the exercise has changed preparedness in a meaningful way.

Objective C: Detecting Cyber Security Events

C1 Security Monitoring

Principle C1 covers the data sources, tools, alerts and triage processes required to detect events that could affect essential functions. A technical tabletop exercise can test the human workflow around those controls, particularly when the exercise begins with an alert that must be interpreted and escalated.

Facilitators can examine whether the alert contains enough context for triage, whether severity is assigned consistently and whether responders can distinguish an isolated event from a wider compromise. Later injects can reveal whether monitoring information reaches operational and executive teams in a form that supports timely decisions, rather than remaining trapped in technical language.

This is valuable evidence for outcomes such as alert generation and triage, although it does not validate log coverage or detection engineering on its own. Live simulations, control testing and technical assurance are still required to prove that the underlying monitoring capability can identify genuine activity.

C2 Threat Hunting

CAF v4.0 now describes C2 as Threat Hunting, which requires a proactive and structured capability that draws on threat intelligence, system behaviour and suitable data. A cyber drill can support this principle when the scenario asks specialists to form hypotheses, identify the evidence they would need and explain how findings would become improved detections.

The alignment is nevertheless limited unless the organisation also demonstrates real hunting activity and retains appropriate records. A discussion can reveal whether the capability is understood and deployable, but it cannot prove that threat hunts occur at a frequency matched to the risk.

Objective D: Minimising the Impact of Cyber Security Incidents

D1 Response and Recovery Planning

Principle D1 represents the most direct connection between incident response tabletop exercises and the Cyber Assessment Framework. It requires well-defined and tested incident management processes that support continuity, containment and restoration, with three contributing outcomes covering the response plan, response and recovery capability and testing and exercising.

For D1.a, the exercise tests whether the response plan is current, accessible and understood by the people expected to use it. It can show whether the plan covers the complete incident lifecycle and whether it integrates with business continuity, communications and supplier arrangements.

For D1.b, the scenario explores whether the organisation can actually enact the plan. Participants must identify the people, information and external support required to limit harm. They must also make decisions using the authority and situational awareness available at that moment, which often exposes capability gaps that a document review would miss.

For D1.c, the alignment with a cyber drill is entirely explicit. The NCSC expects exercises to be routine and threat-informed, with scenarios that cover the response cycle and findings that improve both incident response plans and protective security. A bespoke cyber security tabletop exercise can provide exactly that evidence when its scope, participant group and post-exercise process are designed around the relevant essential functions.

D2 Lessons Learned

The exercise is only the beginning of the D2 relationship because the CAF expects lessons to drive improvement. The NCSC guidance for Principle D2 specifically refers to post-exercise reviews, good-quality reporting and the use of lessons to reduce the risk of similar incidents.

A credible post-exercise process should therefore capture more than a list of observations. It should explain what happened and why, distinguish symptoms from underlying causes and assign prioritised actions to accountable owners. Senior management should receive the findings, while relevant lessons should feed into risk management, security monitoring, recovery arrangements and future exercise design.

The strongest evidence is an improvement trail that can be followed over time. An assessor should be able to see the original observation, the agreed remediation, the decision that funded or accepted it and the subsequent test that confirmed the change was effective.

What evidence should a CAF-aligned Cyber Drill produce?

A productive exercise leaves behind a coherent evidence pack rather than a presentation deck and a set of memories. The exact contents should reflect the organisation’s CAF profile and assessment scope, although the following artefacts usually provide a useful foundation.

  • The exercise objectives should identify the essential functions and CAF outcomes being tested, while explaining why the selected scenario is credible for the organisation.

  • The scenario design should show how risk assessments, threat intelligence and relevant incidents informed the timeline, injects and expected decisions.

  • The participant record should show that the appropriate executive, operational, technical and specialist roles took part, including relevant third parties where their response is material.

  • The exercise record should capture key decisions, information gaps, escalations and assumptions without turning the session into a search for individual blame.

  • The post-exercise report should distinguish strengths from weaknesses and provide evidence-based findings against the agreed objectives.

  • The improvement plan should assign actions, owners, priorities and target dates, with a governance process that tracks remediation to completion.

  • The retest record should show whether significant changes were exercised or otherwise validated, creating evidence that lessons have improved capability.

These records are most useful when they connect with existing governance and assurance processes. Exercise actions should appear in the same risk and improvement mechanisms that senior leaders already review, rather than living in a separate document that loses attention once the event has finished.

What a Cyber Tabletop Exercise Cannot Prove on its Own?

The CAF requires expert judgement across all forty-one contributing outcomes, which means no single exercise can demonstrate complete alignment. A cybersecurity drill is particularly strong at testing people, plans, coordination and decision-making, while its ability to validate technical controls remains limited unless it is combined with live technical activity.

An exercise discussion cannot prove that every critical asset is inventoried, that backups can be restored or that security monitoring covers the required systems. It also cannot demonstrate that a supplier meets contractual security obligations simply because someone knows whom to call.

This limitation does not reduce the value of exercising, but it should shape the claims made afterwards. The defensible position is that the cyber drill provides evidence relevant to specified principles and outcomes, while identified technical questions are verified through appropriate testing, records and specialist assessment.

Organisations seeking a formal view of their position should combine exercise evidence with an NCSC Assured CAF Assessment, which can examine the wider evidence base and apply the judgement required by the framework.

How to design a Cyber Drill around CAF outcomes?

The most effective starting point is not the attack scenario but the assurance question. Leaders should decide which essential function is in scope, which CAF outcomes require stronger evidence and what observable behaviour would increase confidence that those outcomes are being achieved.

The exercise team can then design a threat-led scenario that creates the right decisions and dependencies. If A1 governance is a priority, injects should force delegation and board-level choices. If C1 monitoring is in scope, the opening evidence should test alert quality and triage. If B5 resilience matters, the scenario should create a genuine conflict between containment and continuity before requiring an ordered recovery.

Participants should reflect the system being tested because cyber response extends beyond the security team. Legal, communications, business continuity, operations and senior leadership may all hold decisions that determine whether an essential function is protected. Key suppliers should also participate when the organisation depends on their information or actions during response and recovery.

Finally, the post-exercise process should be agreed before the session begins. Findings need clear owners and governance routes, while material improvements need deadlines and a method of validation. Without that discipline, the organisation may have held an engaging workshop but will struggle to demonstrate the continual improvement that CAF expects.

Tabletop Drills Turn CAF Expectations Into Observable Practice

The Cyber Assessment Framework is deliberately concerned with outcomes rather than paperwork, which is why a Cybersecurity Drill can be so valuable. It creates a controlled setting in which governance, response and resilience arrangements must operate together, allowing an organisation to see whether its plans can support an essential function during a credible cyber incident.

The closest alignment sits within D1 Testing and Exercising, although the evidence can support principles across all four CAF objectives when the scenario and observation method are designed carefully. The result should be a clearer view of current capability, a defensible record of what was tested and a prioritised route towards stronger cyber resilience.

For organisations that want to connect exercising with formal CAF assurance, CM-Alliance can design a bespoke cyber drill around relevant essential functions, threat assumptions and target outcomes. The exercise can then feed into a broader CAF evidence programme, ensuring that lessons are not only recorded but translated into decisions and improvements that stand up to scrutiny.

Frequently Asked Questions about CAF Principles and Cyber Tabletop Exercises  

1. Does the NCSC CAF require Cyber Crisis Tabletop Exercises?

CAF Principle D1 includes a specific contributing outcome for testing and exercising, while the associated guidance expects response plans to be exercised across threat-informed scenarios. A tabletop exercise is one effective method, although the appropriate testing programme should reflect the organisation’s essential functions, risk profile and regulator expectations.

2. Which CAF outcome aligns most directly with a Cyber Drill?

D1.c Testing and Exercising provides the most direct alignment because it expects routine, documented exercises whose findings improve incident response plans and protective security. Strong exercises also generate relevant evidence for D1.a Response Plan, D1.b Response and Recovery Capability and D2.b Using Incidents to Drive Improvements.

3. Can a tabletop exercise prove that an organisation has achieved CAF compliance?

A tabletop exercise cannot prove complete CAF alignment because the framework assesses forty-one contributing outcomes using expert judgement and a broad evidence base. It can provide strong evidence for selected outcomes, particularly those involving governance, people, plans, coordination and improvement.

4. How often should a CAF-aligned tabletop drill be conducted?

The CAF expects exercises to be routine, although it does not prescribe one universal frequency for every organisation. The schedule should reflect risk, material changes, previous findings and relevant regulatory expectations, with additional exercises conducted when new threats or changes to essential functions make existing assurance less reliable.

5. Should executives participate in a CAF tabletop exercise?

Executive participation is important when the exercise tests board direction, risk appetite, crisis governance or decisions that exceed operational authority. Technical and operational sessions remain valuable, but they cannot demonstrate how senior leaders will govern a crisis unless those leaders take part in the decisions assigned to them.

6. What should happen after the exercise?

The organisation should conduct a structured review, document causes and contributing factors and agree prioritised improvements with accountable owners. Significant changes should then be validated through a later exercise or suitable technical test, producing an evidence trail that supports CAF Principle D2 and wider continual improvement.