By David Chernitzky, CEO, Armour Cybersecurity · Serving organizations across North America · Last updated August 6, 2026
| Quick Answer SOC 2, ISO 27001, and NIST CSF auditors all expect evidence of tested incident response capability, not just a documented plan. Cyber insurance carriers ask the same question: has the organization actually exercised its response? A formally facilitated tabletop exercise with an independent security assessor report is the most direct way to produce this evidence and satisfy both audiences simultaneously. |
Key Takeaways
- SOC 2 Type II, ISO 27001, and NIST CSF all require evidence that incident response capability has been tested, not just documented. A plan alone does not satisfy this requirement.
- Cyber insurance underwriters have added tabletop exercise evidence to their standard underwriting questionnaires. Organizations that cannot produce this evidence face worse terms or additional conditions.
- An independent security assessor report from a facilitated tabletop exercise is the most credible evidence format for both auditors and carriers because it reflects an external, objective evaluation.
- Tabletop exercise evidence is most effective when it includes the after-action report showing what gaps were found and what remediation actions are being taken, not just evidence that an exercise occurred.
- Annual exercises generate a documented improvement trajectory that demonstrates sustained program maturity rather than a one-time compliance activity.
Cyber simulation exercise audit evidence is what turns a good tabletop into something an auditor or an underwriter will actually accept. SOC 2, ISO 27001, and NIST CSF all now expect proof that incident response capability has been tested, not just a plan sitting in a folder, and cyber insurance carriers ask the same question on every renewal. The organizations that clear both are the ones that can hand over an independent report showing they exercised their plan, found gaps, and closed them. That evidence starts with a breach readiness assessment and is proven by the exercise that follows it.
| By the NumbersUnderwriting is now evidence-based. Carriers ask whether the IR plan was tested, when, in what format, and whether an after-action report exists, not just whether a plan is on file. Source: 2025 to 2026 carrier underwriting guidance.The major frameworks all expect tested IR, not just a plan. SOC 2 Type II, ISO 27001 with ISO 27035, and NIST CSF 2.0 each require evidence of exercised capability and a documented lessons-learned process.Rehearsed response lowers breach cost. The global average breach cost $4.44M ($10.22M in the US), and faster, tested response reduces it. Source: IBM Cost of a Data Breach Report 2025. |
What Do Compliance Frameworks Require for Incident Response Testing?
The gap between writing an incident response plan and exercising it is one that compliance frameworks increasingly recognize and address explicitly. Understanding what each framework expects helps organizations structure their tabletop program to generate evidence that satisfies audit requirements rather than running exercises that are helpful but not documented in a way auditors can use.
SOC 2
SOC 2 Trust Services Criteria require that the organization has implemented controls to respond to security incidents and that those controls are operating effectively over the audit period. For a SOC 2 Type II audit, effective operation means the control was in place and functioning throughout the year, not just at the time of the audit. Auditors ask for evidence of incident response activities during the period: documented exercises, simulation results, or real incidents with documented response. An annual tabletop exercise with a formal after-action report is the standard evidence format that satisfies this expectation.
ISO 27001
ISO 27001 Clause 9.1 requires the organization to monitor, measure, analyze, and evaluate its information security management system. ISO 27035, the companion standard for information security incident management, explicitly recommends regular exercises and simulations to test incident response capability. ISO 27001 certification auditors ask for evidence that incident response procedures have been tested and that the results of testing have been reviewed and acted upon. Tabletop exercise documentation, including the after-action report and evidence of remediation actions taken, provides exactly this evidence.
NIST Cybersecurity Framework
The NIST Cybersecurity Framework, updated to version 2.0 in 2024, organizes incident response across its Detect, Respond, and Recover functions, and adds a dedicated Improvement category that formalizes feeding lessons from incidents, exercises, and audits back into the program. Regulators and auditors applying CSF 2.0 expect to see evidence of exercised response capability and a working lessons-learned process, not just a plan on file. Annual tabletop exercises with documented after-action reports and tracked remediation actions demonstrate both the exercise discipline and the improvement discipline that CSF 2.0 expects.
Sector-specific frameworks
Financial services regulators, healthcare privacy frameworks, and government sector requirements often include more specific incident response testing obligations than the general frameworks. OSFI guidance for Canadian financial institutions, for example, identifies testing of recovery and response procedures as an expectation for technology and cyber risk management. Organizations in regulated sectors should align their tabletop exercise program with both the general frameworks and the sector-specific expectations of their primary regulator.
What Do Cyber Insurance Carriers Expect?
Cyber insurance underwriting has evolved significantly in its expectations around incident response capability. Carriers that previously accepted a self-attested IR plan as sufficient evidence of preparedness now ask specifically whether the plan has been tested, when it was last exercised, what format the exercise took, and whether an after-action report was produced. A cyber insurance advisory relationship helps translate the exercise evidence into the language underwriters score.
The questions appear in both initial underwriting and renewal applications. Organizations that answer yes to IR plan existence but no to testing evidence face additional underwriting scrutiny, potential sublimits on coverage for incidents where response failures contributed to severity, or conditions requiring testing within a defined period as a coverage condition.
The evidence format that carriers find most credible is an independent security assessor report from a facilitated exercise, for the same reason that an independent auditor is more credible than self-assessment: the independence provides assurance that the findings reflect actual capability rather than a favorable self-assessment. A formal report from a third-party facilitator that documents what was tested, what was found, and what improvements are being made is the gold standard for carrier evidence.
What Does the Tabletop Exercise Documentation Package Include?
A well-structured tabletop exercise engagement produces a documentation package specifically designed to satisfy audit and underwriting requirements while also serving the organization’s internal improvement program.
The independent security assessor report documents the exercise design, the scenario and inject structure, the participant roles, the conduct of the exercise, and the assessor’s observations and findings. This is the document that auditors and carriers ask for. It reflects an external, independent evaluation of the exercise rather than a self-report by the participating organization.
The after-action report complements the assessor report with the detailed findings: key responses (what worked effectively), key observations (gaps and friction points surfaced during the exercise), and key improvement opportunities (prioritized recommendations with suggested owners and timelines). The after-action report is the document that drives the internal improvement program, connecting the exercise experience to specific actions. This is the incident response exercise documentation that closes the loop between finding a gap and fixing it.
The executive summary is a board-ready translation of the findings into governance language: what the exercise revealed about the organization’s response capability, what the highest-priority improvements are, and what actions executives are being asked to sponsor. Many organizations distribute the executive summary to the board as part of their regular cyber risk reporting.
Together, these documents demonstrate to auditors and carriers that the organization has exercised its response capability, received an independent assessment of that capability, identified the gaps that need to be addressed, and has a documented plan for addressing them. This evidence package is significantly more persuasive than a self-attested IR plan because it reflects actual exercise experience rather than documentation aspiration.
How Does Annual Exercise Documentation Build a Track Record?
A single tabletop exercise produces a point-in-time evidence package. An annual exercise program produces something more valuable: a documented track record of sustained engagement with incident response capability development.
Year-over-year exercise documentation demonstrates that gaps identified in one year were closed before the next exercise, that the program is genuinely improving the organization’s capability rather than generating compliance documents, and that leadership engagement is sustained rather than episodic. Auditors who review multiple years of exercise documentation can assess improvement trajectories. Carriers who see a consistent annual exercise program develop higher confidence in the organization’s overall security posture.
Armour Cybersecurity structures its cyber simulation exercises to support this annual cadence. Each year’s exercise is designed to test the improvements made since the previous exercise, introduce new scenarios reflecting the current threat landscape, and produce documentation that builds on the prior year’s record. The improvement roadmap from each exercise feeds directly into the design of the next.
Where Exercise Evidence Fits in Armour’s Managed Services
Exercise evidence rarely works alone. It is one pillar of Armour’s managed cybersecurity services, operating alongside a managed Security Operations Center whose monitoring records are themselves audit evidence, cyber threat intelligence that keeps scenarios current, vCISO leadership to own the remediation the reports recommend, cyber awareness training whose completion records auditors also request, and the all-in-one Armour 360 managed program. The exercise proves the capability. The program produces the rest of the evidence.
The Bottom Line
Auditors and underwriters have stopped accepting a plan on a shelf as proof of readiness. Both now want evidence that the plan was tested, that gaps were found, and that they were closed, and both find an independent assessor report far more credible than a self-assessment. A cyber simulation exercise produces exactly that evidence, satisfying the SOC 2, ISO 27001, and NIST CSF auditor and the cyber insurance underwriter in a single engagement. If your next audit or renewal will ask whether you have tested your response, the time to generate the evidence is before the question is asked.
| Across the 260+ organizations Armour runs exercises for in 52+ industries, the ones that sail through underwriting and audit are not the ones with the thickest IR plan. They are the ones that can hand over an independent after-action report showing a gap was found and closed. |
Frequently Asked Questions
What is cyber simulation exercise audit evidence?
Cyber simulation exercise audit evidence is the documentation a facilitated tabletop exercise produces to prove, to an auditor or a cyber insurance underwriter, that an organization has actually tested its incident response capability. The core artifact is an independent security assessor report, supported by an after-action report and an executive summary, that records what was tested, what gaps were found, and what remediation is underway. Because the assessor is independent of the organization, this evidence carries more weight with auditors and carriers than a self-produced report, and it satisfies the SOC 2, ISO 27001, and NIST CSF expectation that IR capability be exercised, not just documented.
What is an independent security assessor report and why does it matter?
An independent security assessor report is a formal document produced by the exercise facilitator, in their role as an independent third party, that attests to what was tested, how the exercise was conducted, and what the findings were. Its value is the independence: an assessor who was not part of the organization’s response team and has no stake in presenting a favorable picture provides a more credible evaluation than an internally produced exercise report. Auditors and insurance carriers give significantly more weight to independent assessor reports than to self-assessment documents because the independence is the assurance of objectivity.
Can we run our own tabletop exercise and produce compliant documentation?
An internally facilitated exercise can be valuable for building team familiarity and testing specific procedures. However, internally facilitated exercises typically cannot produce independent security assessor reports because the assessor must be independent of the organization being assessed. For audit and underwriting purposes, the independence of the facilitation is part of what makes the documentation credible. Organizations that run internal exercises as supplemental practice between formal facilitated engagements get the benefit of both: regular practice and credible external evidence.
How does tabletop exercise evidence help during a claim?
When a cyber incident results in a claim, the carrier reviews the organization’s response against documented procedures and coverage conditions. Evidence that the organization exercised its IR plan, identified gaps, and addressed them demonstrates a good-faith commitment to response preparedness that supports the claim relationship. Organizations that can produce tabletop exercise documentation showing they identified a specific risk area and took documented steps to address it are in a stronger position than those who cannot demonstrate any pre-incident improvement activity.
How soon after a real incident should we run a tabletop exercise?
A post-incident tabletop exercise, designed around the lessons learned from the real event, is one of the highest-value exercise formats available. The team has direct experience with the incident, the gaps that surfaced are specific and recent, and the motivation to improve is high. Running a tabletop exercise within three to six months of a real incident, specifically designed to test the updated procedures and validate the improvements made in response to the incident, demonstrates the lessons-learned discipline that auditors, carriers, and boards all expect to see following a material event.
What is the minimum documentation needed to satisfy a SOC 2 auditor for IR testing?
SOC 2 auditors typically expect to see evidence that an IR plan exists and has been communicated to relevant personnel, that the plan has been tested during the audit period, and that the results of testing have been reviewed and used to improve the plan. The minimum documentation set that addresses these requirements includes the IR plan with a recent review date, evidence of an exercise (a formal after-action report or independent assessor report is the most credible format), and evidence that improvement actions from the exercise have been tracked. An annual tabletop exercise with a formal after-action report and a tracked remediation list satisfies this documentation expectation comprehensively.
About the Author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



