Tabletop exercise

NIST CSF 2.0 tabletop exercise

Govern, Identify, Protect, Detect, Respond, Recover outcomes.

We can run the NIST CSF 2.0 exercise for your team, or set you up as a facilitator to run it yourself.

What the room works through

NIST Cybersecurity Framework 2.0 subcategories

Whole-of-organisation cyber programme. Use subcategory refs such as GV.OC-01, ID.AM-01, PR.AA-01, DE.CM-01, RS.MA-01, RC.RP-01 with domains Govern, Identify, Protect, Detect, Respond, Recover.

Clauses
42
Rounds
10 across two stages
Room size
Up to 20 participants

Stage 1 — assess

Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a NIST CSF 2.0 clause.

Stage 2 — survive

Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.

What you take away

  • Clause-by-clause coverage across NIST CSF 2.0
  • A gap list ranked by what the room could not defend
  • Per-table divergence, so you can see where opinion split
  • Word and CSV exports plus a drafted findings narrative

New to facilitating? Start with the facilitator manual or read the session walkthrough.

Other standards