Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should be accountable for running tabletop exercises…
Governance, Ownership & Risk

Who should be accountable for running tabletop exercises in an organization?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the incident response owner, but the exercise itself needs shared participation across security, IT, legal, communications, HR, finance, and executive leadership. A facilitator should guide the session, while leadership ensures the findings become policy and process changes. Without clear ownership, lessons learned often disappear after the exercise ends.

Who should own tabletop exercise accountability?

Tabletop exercises work best when one role owns the program end to end and everyone else plays a defined part. The accountable owner should be the incident response lead, or the function that owns incident readiness, because that role is responsible for scope, follow-up, and making sure lessons turn into changes. The exercise still needs cross-functional participation and visible leadership support.

Why the incident response owner is the right accountable role

Accountability belongs with the team that owns the response process because tabletop exercises are not just meetings, they are readiness checks. The accountable role needs enough authority to set the scenario, decide who must attend, and ensure actions are assigned after the session. If accountability sits too low, findings often stop at discussion and never become updated playbooks, training, or control changes.

The incident response owner is also the best position to balance realism with operational discipline. They can decide whether the exercise is validating escalation paths, decision authority, communications handoffs, vendor dependencies, or recovery assumptions. That makes the exercise more than a compliance event, it becomes a controlled test of how the organisation would actually behave during a live incident.

How shared participation and facilitation should work

Accountability does not mean the owner runs every conversation alone. A strong tabletop needs a facilitator to guide timing, prompt decisions, and keep the group focused on the scenario rather than on side debates. Security, IT, legal, communications, HR, finance, and executive leadership should each contribute where their decisions affect the response. The value comes from exposing dependency gaps across functions that may not be obvious in a single-team review.

The practical structure is simple: one accountable owner, one facilitator, and the right subject-matter participants. The facilitator should not be confused with the accountable party. A good facilitator surfaces decision points and capture actions, but the accountable owner owns the output, including remediation tracking, policy updates, and any escalation needed to leadership.

What good ownership looks like after the exercise

Good ownership is visible in what happens after the tabletop, not only during it. The accountable role should ensure there is a written record of decisions, owners for every follow-up item, deadlines, and a review step that confirms the exercise changed something real. If the same gaps reappear in the next tabletop, the organisation is probably treating exercises as a recurring event instead of a governance control.

Leadership involvement matters because many findings require authority outside the incident response team. Some issues are procedural, but others require budget, policy approval, staffing, or risk acceptance. Without executive sponsorship, the accountable owner may be able to document issues but not close them.

Risk and Threat Considerations

The main risk is governance failure: a tabletop can produce useful discussion but no durable improvement if ownership, facilitation, and follow-through are unclear. In larger organisations, this also creates fragmentation, where different teams believe someone else will own corrective action.

Failure mechanism: The exercise is treated as a one-time event, so actions are not assigned, tracked, or validated, and the same response gaps persist until a real incident exposes them.

Impact: The organisation loses time, confidence, and response quality, and may discover too late that escalation, communications, or recovery decisions were never tested under realistic conditions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyTabletop ownership supports a clear incident readiness governance model.
RS.RP-01 — Response Plan ExecutionTabletop exercises validate whether response roles and execution paths are clear.
Recommendation — Assign a single owner for exercise follow-up and ensure findings feed the risk management process. Use exercises to test response roles, handoffs, and execution of the incident plan.
NIST SP 800-53 Rev 5IR-3 — Incident Response TestingTabletop exercises are a direct form of incident response testing and readiness validation.
IR-4 — Incident HandlingOwnership of tabletop exercises should mirror the function that manages incident handling.
Recommendation — Run regular incident response tests and document corrective actions to closure. Ensure incident handling roles are defined and exercised with cross-functional participation.
ISO/IEC 27001:2022A.5.24 — Information security incident management planning and preparationTabletops are part of planning and preparing for security incidents.
A.5.26 — Response to information security incidentsThe exercise owner should govern the response process tested by the tabletop.
Recommendation — Use incident exercises to validate preparedness and assign remediation actions. Define response ownership and ensure exercise outcomes update incident procedures.
CIS Controls v8CIS-17 — Incident Response ManagementTabletop accountability is part of maintaining and testing incident response capability.
Recommendation — Designate IR ownership and test the program through recurring exercises.

Practitioner Guidance

What to verify: Confirm that the accountable owner can assign actions, chase closure, and report unresolved findings to leadership. If that person cannot change policy, process, or readiness plans, they are not the right accountability point.

Decision rule: If the tabletop is meant to test incident response, the incident response owner should own accountability; if it is testing a business continuity or crisis-management scenario, responsibility may sit with the function that owns that program, but the same cross-functional participation rule still applies.

Practitioner takeaway: The key judgement is to separate facilitation from accountability, because tabletop quality comes from shared participation, but lasting improvement comes only when one owner is responsible for turning findings into action.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org