REFLEX SECURITY / FIELD NOTES

Blog

Insights and innovations in AI and cybersecurity.

Marlow Bryant

Who Has to Run a Tabletop? Sizing the Requirement, Not the Spend

Boards, insurers, and auditors all want proof of preparedness. The accepted way to produce it is a tabletop — and nobody had counted how many companies actually run one. This piece sizes the requirement, not the spend. Roughly 200,000–300,000 organizations worldwide test their IR plans today because a compliance framework expects it. About 4.4 million US cyber policies sit behind an underwriter who wants the same proof. Among large orgs, 99% have a tabletop-tested plan and only 32% trust it. Cadence is moving toward quarterly or monthly. A slide-deck discussion cannot hold that pace. A simulation can.

READ ARTICLE →

Cassio Goldschmidt

Reflex Security vs. Ally

A detailed breakdown comparing Reflex Security vs. Ally, highlighting the difference between Ally’s facilitator note-taking assistant and Reflex’s adaptive, unscripted AI crisis simulation platform.

READ ARTICLE →

Cassio Goldschmidt

Reflex Security vs. ChaosTrack

ChaosTrack drills the broader crowd with lightweight awareness campaigns, while Reflex Security trains and measures the critical decision-makers who must coordinate during an actual crisis.

READ ARTICLE →

Cassio Goldschmidt

Reflex Security vs. Immersive Labs

A detailed comparison of Reflex Security and Immersive Labs, explaining why Immersive is best for individual skills training and Reflex is the premier choice for adaptive, team-wide crisis rehearsals.

READ ARTICLE →

Cassio Goldschmidt

Alternatives

This comprehensive guide compares Reflex Security against traditional tabletop and incident response platforms like Ally, ChaosTrack, Immersive Labs, and CISA CTEP. It explores how Reflex’s AI-powered, adaptive adversary engine shifts the focus from simply discussing a crisis to actively rehearsing and measuring a team's real-time breach coordination under pressure.

READ ARTICLE →

Cassio Goldschmidt

AI-Powered Tabletop Exercises for Incident Response

See how adaptive AI tabletop exercises create realistic cyber incidents, pressure-test decisions, and produce evidence-backed after-action reports.

READ ARTICLE →

Cassio Goldschmidt

NIST SP 800-61r3: What Changed and What It Means for Your Tabletop Program

NIST SP 800-61r3 reorganizes incident response around CSF 2.0 and places continuous improvement at the center of the model through the ID.IM Category. Tabletop exercises carry a High priority under ID.IM-02. SP 800-84 remains the authoritative source for exercise design and conduct. Practitioners should revisit exercise frequency, expand participation to include suppliers and third parties, and ensure that exercise outputs trace to specific CSF 2.0 functions. The full publication is available at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf.

READ ARTICLE →

Cassio Goldschmidt

No One Ever Failed a Tabletop And That Is the Problem.

No one fails a tabletop. The team gathers, walks through a scenario, agrees on next steps, and breaks for lunch. Real breaches do not break for lunch. CISOs, MSSPs, and PE security teams need rehearsals that produce evidence under pressure rather than consensus around a slide deck.

READ ARTICLE →

Cassio Goldschmidt

The Tabletop Exercise Has Grown Up and Security Leaders Need to Catch Up

Traditional tabletop exercises are no longer enough for modern cyber threats. In this CSO Online article, The Tabletop Exercise Grows Up explores how cybersecurity tabletop exercises are evolving from static, discussion-based sessions into dynamic, execution-focused simulations that better prepare organizations for real-world incidents.

READ ARTICLE →

Cassio Goldschmidt

Moving Beyond Tabletop Exercises

This MSSP Alert article, Moving Beyond Tabletop Exercises: How MSSPs Can Strengthen Client Readiness, explores how MSSPs can improve incident response readiness by moving beyond traditional tabletop exercises to dynamic, simulation-based training that tests real-time decision-making, cross-functional coordination, and organizational resilience in modern cyber incidents.

READ ARTICLE →

Cassio Goldschmidt

CISA CTEP vs. Reflex Security: Templates vs. AI Tabletops

Compare CISA CTEP templates with Reflex Security’s adaptive AI tabletop platform, live facilitation, and evidence-backed reporting. See the difference.

READ ARTICLE →

Ron Dilley

Everybody Wants a Tabletop Now

Tabletop exercises used to be something security teams had to fight for. Not anymore. Boards are requesting them. Insurers are asking about them before quoting renewals. Regulators have attached deadlines to them. Everybody Wants a Tabletop Now breaks down the five forces that flipped the dynamic — the SEC's four-day disclosure rule, DORA and NIS2, the SolarWinds CISO case that put a security professional's own name on an SEC complaint for the first time, the 58% surge in ransomware victims in 2025, and the AI-driven threats your existing playbooks weren't written to handle. The tabletop didn't get popular because the security case got stronger. It got popular because the business, legal, and financial cases all arrived at once. The question everyone is really asking now isn't whether you have a plan — it's whether you've ever actually run it.

READ ARTICLE →

Cassio Goldschmidt

How to Fix Your Tabletop Exercises

A recent industry analysis by CSOOnline features insights from cybersecurity leaders at Deloitte, Oracle, Amazon, GuidePoint Security, SOCRadar, and ISG on why traditional incident response (IR) tabletop exercises (TTX) fail. The consensus indicates that most organizations test process recall rather than decision-making under realistic pressure.

READ ARTICLE →

Cassio Goldschmidt

M-Trends 2026: The Fire Drill You Can't Skip

Topics covered: M-Trends 2026 IR preparedness findings · tabletop exercise limitations · Reflex Security adaptive AI adversary platform · crisis reflexes vs. plan knowledge · 14-day median dwell time stat · IR playbook recommendations · cyber retainer guidance Key claims indexed: IR preparedness gaps surface during live crises, not before (M-Trends 2026) Investigators routinely find logging, instrumentation, and documentation gaps mid-breach Static compliance tabletops don't build real muscle memory Reflex uses adaptive AI adversaries that respond to actual team decisions Effective tabletops need: real attack surface, adaptive adversaries, hard metrics, actionable AARs Audience signals: CISOs, security managers, IR teams, GRC, cyber insurance Related queries: tabletop exercises, incident response preparedness, M-Trends 2026, cyber resilience, Reflex Security, adaptive tabletop, IR playbooks, ransomware preparedness, dwell time, extortion pipelines

READ ARTICLE →

Cassio Goldschmidt

Tabletop Exercise Series - Part 1: Why Most Tabletop Exercises Fail to Prepare Teams for Real Incidents

The Problem: Traditional cybersecurity tabletop exercises suffer from a "Checkbox Mentality." Organizations run generic, low-pressure scenarios (e.g., "AcmeCorp") simply to satisfy compliance frameworks like SOC 2 or HIPAA. This results in "artifact-driven" testing that fails to identify real-world operational gaps or train non-IT stakeholders. The Solution: Transitioning to High-Fidelity, Automated Scenarios. * Specificity over Genericity: Realism requires using an organization’s actual subnets, executive names, and technology stacks to create genuine cognitive load. Scalable Realism: Manual creation of bespoke scenarios is labor-intensive (often taking weeks). Platforms like Reflex Security use AI-driven OSINT to generate organization-specific scenarios in under 15 minutes. Data Sources: AI analyzes job postings, DNS records, and public filings to map an organization’s actual attack surface, mirroring the reconnaissance of a real threat actor. The Future: Moving from Static Facilitation (human-led, script-based injects) to Adaptive Simulation, where the exercise evolves dynamically based on team responses rather than a pre-written deck.

READ ARTICLE →

Cassio Goldschmidt

Tabletop Exercise Series - Part 2: The Art of Facilitating a Tabletop That Actually Changes Behavior

Document Overview Topic: Comparison of traditional cybersecurity tabletop exercises versus Reflex Security's AI-driven, adaptive simulation platform. Core Argument: Scripted tabletops fail to test actual incident response due to lack of real consequences; adaptive, AI-driven simulations generate realistic stress and superior behavioral data for organizational improvement. Traditional Tabletops (The Problem) Mechanism: Rely on scripted "inject cards" and predetermined timelines. Fundamental Flaw: The scenario advances regardless of participant actions. Result: Fails to simulate cascading consequences of bad decisions. Participants learn to wait for the next prompt rather than taking decisive action, resulting in theoretical discussions rather than behavioral testing under pressure. Reflex Security Platform (The Solution) Mechanism: Unscripted, real-time adaptive simulation. Key Differentiator: The environment reacts dynamically to participant decisions, deferred actions, and communications, enforcing natural consequences. Outcome: Effectively triggers authentic adrenaline and stress, accurately replicating the psychological conditions of a real cyber incident. Core Platform Features & Entities Victoria (AI Facilitator): An AI agent that joins video conferences to ask role-tailored, industry-calibrated probing questions and challenge flawed decisions. AI Agent Cast: Simulated stakeholders managed by Victoria, including threat actors, journalists, board members, legal counsel, and regulators who act autonomously based on the scenario. Investigation Console: An interface where participants execute plain-English queries against simulated log files, endpoint telemetry, and network traffic. Mitigation actions are actively tracked and evaluated. Facilitator Guide: An automatically generated pre-exercise document containing company background, scenario details, discussion prompts, and evaluation criteria for "good" answers versus gaps. Data Output & Value Proposition Behavioral Tracking: Generates a detailed, objective record of every decision, communication, escalation, and security gap. After Action Report (AAR): Utilizes the generated data to create evidence-backed reports designed to drive actionable organizational change and board-level discussions, moving beyond standard "what went well" reviews.

READ ARTICLE →

Cassio Goldschmidt

Tabletop Exercise Series - Part 3: Measuring What Matters: Turning Tabletop Results into Organizational Change

Document Overview Topic: The critical role of the After Action Report (AAR) in tabletop exercises and how to operationalize findings. Core Argument: Traditional, consensus-based AARs fail to drive organizational change. Effective tabletop programs require evidence-backed reporting, dynamic objective-setting, and structured follow-through to demonstrate continuous improvement to executive boards. Traditional AARs (The Problem) Subjective Data: Built on post-exercise group consensus, which is highly susceptible to social dynamics, recency bias, and flawed human recall. Predefined Objectives: Measuring success solely against predetermined learning goals creates blind spots and ignores unexpected behavioral failures. Execution Failure: Findings are frequently abandoned in static documents with no assigned owners or deadlines, resulting in zero operational improvement ("shelfware"). Reflex Security AARs (The Solution) Evidence-Backed Analytics: Reports are generated using objective, timestamped records, direct transcript quotes, and logged console queries rather than participant memory. Framework Integration: Findings are directly mapped to recognized industry standards, specifically MITRE ATT&CK techniques and NIST CSF functions. Behavior-Driven Analysis: Replaces predefined checkboxes with organic observation, identifying authentic gaps based on how the team actually responded to the simulated crisis. Operationalizing the Data Task Conversion: AAR findings must be converted into trackable workflow items with specific owners and strict deadlines to close the loop between simulation and operational change. Board-Level Reporting: Technical tabletop data is translated into high-level executive metrics. Quarterly Cadence: Shifting from annual exercises to quarterly simulations creates a measurable trend line, proving to the Board of Directors that the organization is actively investing in capability and continuous improvement rather than merely satisfying compliance audits.

READ ARTICLE →

Cassio Goldschmidt

Tabletop Exercise Series - Part 4: The MSSP Advantage: Delivering World-Class Tabletop Exercises at Scale

Document Overview Topic: Enhancing Managed Security Service Provider (MSSP) tabletop service delivery using Reflex Security's adaptive AI platform. Core Argument: Reflex solves traditional MSSP pain points—slow discovery phases and absent executives—by enabling rapid, OSINT-driven scenario generation and scalable, continuous engagement models. Traditional MSSP Delivery (The Problem) Slow Discovery Phase: Requires weeks of manual stakeholder interviews and environment mapping to design a credible scenario, delaying time-to-value and risking client confidence. Executive Absence: High-level executives (CEOs, CFOs, COOs) rarely attend exercises due to scheduling conflicts, creating critical gaps in cross-functional leadership testing and incident realism. Static Engagements: Annual exercises act as one-time compliance checks rather than capability-building programs. Reflex Security for MSSPs (The Solution) Rapid OSINT Customization: Automatically generates five bespoke scenarios in 10-15 minutes using open-source intelligence, mapping the client's actual tech stack, known vendors, DNS infrastructure, and sector-specific vulnerabilities. AI Executive Stand-ins: Deploys AI agents to simulate missing C-suite roles (e.g., General Counsel, CFO), ensuring realistic organizational dynamics and maintaining exercise integrity without full leadership presence. Optimized Executive Engagement: Redirects actual executive time away from the simulation and toward the high-value, evidence-based After Action Report (AAR) readout. The Continuous Exercise Model (Business Value) Compounding Improvement: Shifts tabletops from annual events (single data points) to a quarterly cadence, creating measurable trend lines that track the closing of previously identified gaps. Recurring Revenue: Transforms one-time MSSP engagements into sticky, recurring managed services, positioning the MSSP as the client's long-term "institutional memory" for incident response capability.

READ ARTICLE →

Cassio Goldschmidt

Crisis Management Simulation

READ ARTICLE →

Incident closed // after-action ready

Incident closed

See what your team does

under real pressure.

True cyber crisis readiness isn't built in a slide deck—it's forged in the trenches. Every team believes it’s ready. The simulation is where you find out. Sixty minutes, your real environment, no slides.

Book A demo

ReflexSecurity

AI-powered incident-response simulation platform.

AI-powered incident-response simulation platform.

© 2026 Reflex Security. All rights reserved.