REFLEX SECURITY / INSIGHTS

Who Has to Run a Tabletop? Sizing the Requirement, Not the Spend

Boards, insurers, and auditors all want proof of preparedness. The accepted way to produce it is a tabletop — and nobody had counted how many companies actually run one. This piece sizes the requirement, not the spend. Roughly 200,000–300,000 organizations worldwide test their IR plans today because a compliance framework expects it. About 4.4 million US cyber policies sit behind an underwriter who wants the same proof. Among large orgs, 99% have a tabletop-tested plan and only 32% trust it. Cadence is moving toward quarterly or monthly. A slide-deck discussion cannot hold that pace. A simulation can.

Marlow Bryant

Who Has to Run a Tabletop? Sizing the Requirement, Not the Spend

Marlow Bryant, Reflex Security 


Every security leader is being asked for proof of preparedness. The board wants to know if you're prepared. Insurers want to know the date of the last exercise ahead of renewal. Auditors want to see evidence-backed assessments. And there is one accepted way to produce that proof: a tabletop. An expensive discussion about being prepared.

Is there a definitive count for this? How many companies run a tabletop as a compliance objective? Surprisingly, we found no such number. So I set out to answer it.

Part of the reason is that the frameworks disagree about what they want.

  • SOC 2, ISO 27001, and NIST CSF treat IR plan testing as evidence and assess it.

  • PCI DSS v4.0.1 Requirement 12.10.2 requires the plan be tested at least every 12 months.

  • DORA, applied to EU financial entities in January 2025, requires scenario-based resilience testing.

  • NIST SP 800-171 Rev. 2 control 3.6.3, which anchors CMMC Level 2, requires the response capability be tested.

  • HIPAA calls contingency-plan testing "addressable," which in practice means the covered entity decides.

PCI DSS and DORA require it. NIST, SOC 2, and ISO assess it. HIPAA calls it addressable. And nobody counts the reports, certificates, and attestations issued each year.

Here is how we counted. Two populations: organizations that run an IR plan test because a compliance framework expects one, and organizations with a cyber insurance policy from an underwriter who wants proof. Where a number is pulled from a registry, it says so. Where a number is derived, the inputs are on the page so you can argue with the assumptions.

Full disclosure: Reflex is replacing the tabletop with crisis simulations. We want to know how many companies feel this pain. I built this count for our own planning. I'm publishing it because I haven't seen anyone else do it.


Population one: organizations that run a tabletop as a compliance objective

TLDR: roughly 200,000 to 300,000 organizations worldwide run an IR plan test today for a compliance reason. We won't sharpen it further, because the inputs are fuzzy.


United States

Census SUSB 2022 counts 675,542 US firms with 20 or more employees. Add about 45,000 public entities and the universe is 720,000 organizations. We estimate 70,000 to 90,000 of them test their IR plans today as a compliance objective. That share is rising, for reasons in the last section.

SOC 2 Type II is where most organizations first meet IR plan testing as a compliance objective, and most meet it around 250 employees. Firms with 500 or more employees almost all run one; they hold PCI scope, federal contracts, or a SOC 2 report, and often all three. Below 250 the share thins fast.


Europe (EU-27)

The European Commission estimates roughly 160,000 entities fall in scope for NIS2. Scope is not adoption. Twenty of 27 member states had transposed NIS2 as of January 2026, so enforcement today is partial. We estimate 72,000 to 120,000 NIS2-scope entities run a test now, plus a smaller share of the roughly 200,000 EU-27 enterprises outside scope. Call it 100,000 to 150,000.


Rest of world

Three jurisdictions publish citable counts; many more impose the requirement. Australia's APRA CPS 234 covers roughly 650 to 680 regulated entities. Singapore's MAS Financial Institutions Directory lists about 2,500. India's RBI counts 508 mid- and upper-layer NBFCs under its IT governance direction. Japan's FSA, Saudi SAMA, and CERT-In all impose testing expectations of some kind but publish no count of the entities they cover.


Population two: organizations with an insurance-linked reason

TLDR: no single number here, but the pressure is real. About 4.4 million US cyber insurance policies sit behind an underwriter who wants proof of readiness. Many companies hold more than one policy, and most of the insured overlap with the compliance population above. The net-new companies are the smaller ones that buy a policy before any compliance framework reaches them, likely a five-figure population.

NAIC's Report on the Cybersecurity Insurance Market for the 2024 data year, published November 2025, counts 4,368,614 US cyber insurance policies in force. The mix: 55.1% endorsements on other policies, 41.6% standalone primary, 3.3% excess. Most of the 2.4 million endorsements sit on small-business packages far below the size bands above.

What the number measures is pressure. Insurers grade IR maturity when they price the policy and again when they adjudicate a claim. Ron made this point in "Everybody Wants a Tabletop Now," and the underwriting questionnaires we see ask for the date of the last exercise. That is an insurance-linked reason to test. It is not an insurance requirement, and we don't call it one unless a specific carrier program says so.


The forces that drive demand for preparedness

Everyone in both populations is being asked to prove readiness, once a year, with an instrument nobody trusts.

Sygnia's 2026 CISO survey asked 600 security leaders at organizations with 1,000 or more employees. Among them, 99% have an IR plan tested through a tabletop or simulation, 32% rate it highly effective, and 73% say they would not be fully ready for a significant attack tomorrow. Seventy-five percent plan more investment in tabletop or simulation testing in the next 12 months. An instrument that 99% use and 32% believe in is a compliance artifact, and compliance artifacts get replaced when something else produces evidence.

The breach data agrees. IBM and Ponemon's Cost of a Data Breach 2023 found that organizations with high levels of IR planning and testing saved $1.49 million per breach, 34% less than those with low levels or none. The 2025 edition put the US average breach cost at $10.22 million, an all-time high, and its resilience recommendation now names "cyber range crisis simulation exercises."


Close

The tabletop was built to prove you had a plan. Today the question is whether you have ever run it. Most companies still answer once a year, and not convincingly.

Somewhere between 200,000 and 300,000 organizations run a test worldwide. About 4.4 million US policies sit behind an underwriter who wants the same proof. Among the organizations that take it seriously, cadence is moving toward quarterly or monthly, against scenarios built to push back. A slide-deck discussion can't hold that pace for five teams. A simulation can.

The count that matters five years from now is exercises per organization per year. Nobody tracks that either. Yet.

Every number in this piece, with its source, in the order it appears above:

What we counted

Number

Source

Sourced / Estimate

Global organizations running a test today

200,000-300,000

Sum of the US, EU-27, and rest-of-world estimates below

Estimate

US firms with 20+ employees

675,542

Census SUSB 2022

Sourced

US government-owned entities

~45,000

Composite: Census of Governments, IPEDS, APPA, AHA

Estimate

US organizations running an IR plan test as a compliance objective

70,000-90,000

Reflex estimate on SUSB size bands

Estimate

EU-27 entities in NIS2 scope

~160,000

European Commission via ENISA

Sourced

EU-27 organizations running a test today

100,000-150,000

Reflex estimate

Estimate

Rest of world, sourced regulated entities

Australia ~650-680 (APRA); Singapore ~2,500 (MAS); India 508 (RBI)

Regulator directories

Sourced, partial

US cyber insurance policies in force, 2024

4,368,614

NAIC

Sourced

Insured US companies below any compliance threshold

Five figures

Reflex estimate

Estimate, rough

Large orgs with a tabletop-tested IR plan / rating it highly effective

99% / 32%

Sygnia CISO Survey 2026 (n=600, 1,000+ employees)

Sourced

Large orgs not fully ready for a significant attack / planning more testing investment

73% / 75%

Sygnia 2026

Sourced

Breach cost saved by high levels of IR planning and testing

$1.49M (34%)

IBM/Ponemon Cost of a Data Breach 2023

Sourced

US average breach cost, 2025

$10.22M

IBM/Ponemon 2025

Sourced

Incident closed // after-action ready

Incident closed

See what your team does

under real pressure.

True cyber crisis readiness isn't built in a slide deck—it's forged in the trenches. Every team believes it’s ready. The simulation is where you find out. Sixty minutes, your real environment, no slides.

Book A demo

ReflexSecurity

AI-powered incident-response simulation platform.

AI-powered incident-response simulation platform.

© 2026 Reflex Security. All rights reserved.