REFLEX SECURITY / INSIGHTS
Who Has to Run a Tabletop? Sizing the Requirement, Not the Spend
Boards, insurers, and auditors all want proof of preparedness. The accepted way to produce it is a tabletop — and nobody had counted how many companies actually run one. This piece sizes the requirement, not the spend. Roughly 200,000–300,000 organizations worldwide test their IR plans today because a compliance framework expects it. About 4.4 million US cyber policies sit behind an underwriter who wants the same proof. Among large orgs, 99% have a tabletop-tested plan and only 32% trust it. Cadence is moving toward quarterly or monthly. A slide-deck discussion cannot hold that pace. A simulation can.
Marlow Bryant

Who Has to Run a Tabletop? Sizing the Requirement, Not the Spend
Marlow Bryant, Reflex Security
Every security leader is being asked for proof of preparedness. The board wants to know if you're prepared. Insurers want to know the date of the last exercise ahead of renewal. Auditors want to see evidence-backed assessments. And there is one accepted way to produce that proof: a tabletop. An expensive discussion about being prepared.
Is there a definitive count for this? How many companies run a tabletop as a compliance objective? Surprisingly, we found no such number. So I set out to answer it.
Part of the reason is that the frameworks disagree about what they want.
SOC 2, ISO 27001, and NIST CSF treat IR plan testing as evidence and assess it.
PCI DSS v4.0.1 Requirement 12.10.2 requires the plan be tested at least every 12 months.
DORA, applied to EU financial entities in January 2025, requires scenario-based resilience testing.
NIST SP 800-171 Rev. 2 control 3.6.3, which anchors CMMC Level 2, requires the response capability be tested.
HIPAA calls contingency-plan testing "addressable," which in practice means the covered entity decides.
PCI DSS and DORA require it. NIST, SOC 2, and ISO assess it. HIPAA calls it addressable. And nobody counts the reports, certificates, and attestations issued each year.
Here is how we counted. Two populations: organizations that run an IR plan test because a compliance framework expects one, and organizations with a cyber insurance policy from an underwriter who wants proof. Where a number is pulled from a registry, it says so. Where a number is derived, the inputs are on the page so you can argue with the assumptions.
Full disclosure: Reflex is replacing the tabletop with crisis simulations. We want to know how many companies feel this pain. I built this count for our own planning. I'm publishing it because I haven't seen anyone else do it.
Population one: organizations that run a tabletop as a compliance objective
TLDR: roughly 200,000 to 300,000 organizations worldwide run an IR plan test today for a compliance reason. We won't sharpen it further, because the inputs are fuzzy.
United States
Census SUSB 2022 counts 675,542 US firms with 20 or more employees. Add about 45,000 public entities and the universe is 720,000 organizations. We estimate 70,000 to 90,000 of them test their IR plans today as a compliance objective. That share is rising, for reasons in the last section.
SOC 2 Type II is where most organizations first meet IR plan testing as a compliance objective, and most meet it around 250 employees. Firms with 500 or more employees almost all run one; they hold PCI scope, federal contracts, or a SOC 2 report, and often all three. Below 250 the share thins fast.
Europe (EU-27)
The European Commission estimates roughly 160,000 entities fall in scope for NIS2. Scope is not adoption. Twenty of 27 member states had transposed NIS2 as of January 2026, so enforcement today is partial. We estimate 72,000 to 120,000 NIS2-scope entities run a test now, plus a smaller share of the roughly 200,000 EU-27 enterprises outside scope. Call it 100,000 to 150,000.
Rest of world
Three jurisdictions publish citable counts; many more impose the requirement. Australia's APRA CPS 234 covers roughly 650 to 680 regulated entities. Singapore's MAS Financial Institutions Directory lists about 2,500. India's RBI counts 508 mid- and upper-layer NBFCs under its IT governance direction. Japan's FSA, Saudi SAMA, and CERT-In all impose testing expectations of some kind but publish no count of the entities they cover.
Population two: organizations with an insurance-linked reason
TLDR: no single number here, but the pressure is real. About 4.4 million US cyber insurance policies sit behind an underwriter who wants proof of readiness. Many companies hold more than one policy, and most of the insured overlap with the compliance population above. The net-new companies are the smaller ones that buy a policy before any compliance framework reaches them, likely a five-figure population.
NAIC's Report on the Cybersecurity Insurance Market for the 2024 data year, published November 2025, counts 4,368,614 US cyber insurance policies in force. The mix: 55.1% endorsements on other policies, 41.6% standalone primary, 3.3% excess. Most of the 2.4 million endorsements sit on small-business packages far below the size bands above.
What the number measures is pressure. Insurers grade IR maturity when they price the policy and again when they adjudicate a claim. Ron made this point in "Everybody Wants a Tabletop Now," and the underwriting questionnaires we see ask for the date of the last exercise. That is an insurance-linked reason to test. It is not an insurance requirement, and we don't call it one unless a specific carrier program says so.
The forces that drive demand for preparedness
Everyone in both populations is being asked to prove readiness, once a year, with an instrument nobody trusts.
Sygnia's 2026 CISO survey asked 600 security leaders at organizations with 1,000 or more employees. Among them, 99% have an IR plan tested through a tabletop or simulation, 32% rate it highly effective, and 73% say they would not be fully ready for a significant attack tomorrow. Seventy-five percent plan more investment in tabletop or simulation testing in the next 12 months. An instrument that 99% use and 32% believe in is a compliance artifact, and compliance artifacts get replaced when something else produces evidence.
The breach data agrees. IBM and Ponemon's Cost of a Data Breach 2023 found that organizations with high levels of IR planning and testing saved $1.49 million per breach, 34% less than those with low levels or none. The 2025 edition put the US average breach cost at $10.22 million, an all-time high, and its resilience recommendation now names "cyber range crisis simulation exercises."
Close
The tabletop was built to prove you had a plan. Today the question is whether you have ever run it. Most companies still answer once a year, and not convincingly.
Somewhere between 200,000 and 300,000 organizations run a test worldwide. About 4.4 million US policies sit behind an underwriter who wants the same proof. Among the organizations that take it seriously, cadence is moving toward quarterly or monthly, against scenarios built to push back. A slide-deck discussion can't hold that pace for five teams. A simulation can.
The count that matters five years from now is exercises per organization per year. Nobody tracks that either. Yet.
Every number in this piece, with its source, in the order it appears above:
What we counted | Number | Source | Sourced / Estimate |
|---|---|---|---|
Global organizations running a test today | 200,000-300,000 | Sum of the US, EU-27, and rest-of-world estimates below | Estimate |
US firms with 20+ employees | 675,542 | Census SUSB 2022 | Sourced |
US government-owned entities | ~45,000 | Composite: Census of Governments, IPEDS, APPA, AHA | Estimate |
US organizations running an IR plan test as a compliance objective | 70,000-90,000 | Reflex estimate on SUSB size bands | Estimate |
EU-27 entities in NIS2 scope | ~160,000 | European Commission via ENISA | Sourced |
EU-27 organizations running a test today | 100,000-150,000 | Reflex estimate | Estimate |
Rest of world, sourced regulated entities | Australia ~650-680 (APRA); Singapore ~2,500 (MAS); India 508 (RBI) | Regulator directories | Sourced, partial |
US cyber insurance policies in force, 2024 | 4,368,614 | NAIC | Sourced |
Insured US companies below any compliance threshold | Five figures | Reflex estimate | Estimate, rough |
Large orgs with a tabletop-tested IR plan / rating it highly effective | 99% / 32% | Sygnia CISO Survey 2026 (n=600, 1,000+ employees) | Sourced |
Large orgs not fully ready for a significant attack / planning more testing investment | 73% / 75% | Sygnia 2026 | Sourced |
Breach cost saved by high levels of IR planning and testing | $1.49M (34%) | IBM/Ponemon Cost of a Data Breach 2023 | Sourced |
US average breach cost, 2025 | $10.22M | IBM/Ponemon 2025 | Sourced |