Security Insights

What to Budget For Next Year: Penetration Testing, Tabletop Exercises, and Compliance

6 min read
John, Founder of EliteSec By John Svazic
Illustration in muted purple tones of a piggy bank on a desk beside a wall calendar, a stack of papers, a notebook, a pen, a printed sheet, and a calculator

As you approach annual budget planning, here’s what your security program needs you to know: two of the most common line items, penetration testing and tabletop exercises, get budgeted, scoped, and scheduled very differently, and conflating them is one of the more common planning mistakes mid-market companies make heading into the new year.

Here is how both work: what the frameworks actually expect around penetration testing, and where a gamified tabletop exercise fits as a separate, complementary line. Read it, confirm what applies to your organization, and put dates on the calendar.

What Your Annual Security Budget Needs to Cover

Most companies default to thinking about “security testing” as one thing. It isn’t. A penetration test validates whether your technical controls hold up against a realistic attacker. A tabletop exercise validates whether your people, decisions, and processes hold up once something has already gone wrong. Planning for one without the other leaves a real gap: a hardened environment with a team that hesitates during an actual incident, or a well-drilled team defending an environment nobody has actually tested.

Both belong in the same planning conversation. They don’t compete for the same budget line so much as cover two different failure modes.

Penetration Testing: Where Compliance Sets the Clock

Pentest cadence depends heavily on which compliance framework is driving it, and the three most common ones, PCI DSS, SOC 2, and ISO 27001, handle this very differently.

PCI DSS is the most prescriptive: annual testing is expected, plus retesting after any significant infrastructure or application change, with explicit scope requirements covering the Cardholder Data Environment (CDE) and segmentation validation.

SOC 2 doesn’t mandate a specific cadence in its Trust Services Criteria. Auditors set the expectation based on risk profile, and annual testing is the common baseline in practice, though “common” isn’t the same as “written down.” Confirming evidence expectations with your auditor directly, before scoping anything, avoids budgeting for the wrong thing.

ISO 27001 takes a risk-based approach: testing cadence should trace back to a documented risk assessment rather than a fixed calendar rule. The flexibility is useful, but it only holds up under audit if the rationale is actually written down.

Framework language and clause numbers shift between versions (PCI DSS v4.0.1 is current, and its future-dated requirements have been mandatory since March 31, 2025), so treat this as directional and confirm current wording with your auditor or the published standard before locking in scope or dates.

One thing all three frameworks share: a finding that is fixed but never retested leaves the compliance question open. Every EliteSec engagement includes five free retests over 12 months, against an industry norm of one, so the verification step is already inside the line item. We covered why that gap matters in Finding Closed Is Not Finding Fixed.

Beyond Controls: What Gamified Tabletop Exercises Test

A traditional tabletop exercise is a structured, discussion-based simulation: the team talks through a scenario (ransomware, a data breach, an insider threat) and walks through decisions, escalation paths, and who’s responsible for what. It’s useful, but it tends to follow what’s sometimes called the “happy path”: face a decision, assume it works, move to the next one. Real incidents don’t cooperate that way.

Gamified tabletop exercises are built specifically to break that pattern. By introducing randomness, dice rolls that determine whether a given decision actually succeeds, the exercise forces teams to adapt in real time instead of assuming every choice lands cleanly. The result tests how a team actually coordinates and decides under pressure, not just whether a response plan exists on paper.

Common scenarios include ransomware outbreaks, business email compromise, cloud data exposure, insider threats, and third-party supply chain compromise, with many exercises incorporating adversary behaviors aligned to the MITRE ATT&CK framework for realism. Participants typically include security and IT leadership, legal counsel, communications, HR where insider scenarios are involved, and, for more mature programs, the board.

This isn’t a substitute for a penetration test, and it isn’t positioned as one. Some organizations use tabletop exercises as supporting evidence of incident response readiness alongside other compliance activities, though, as with pentest cadence, the specific evidence an auditor expects should be confirmed directly with them rather than assumed.

Two Different Failures, Two Different Tests

Worth stating plainly: a penetration test and a tabletop exercise aren’t sequential, and neither is the “advanced” version of the other. A company can pass a pentest cleanly and still have a team that miscommunicates or stalls during a real incident. A team can run a flawless tabletop and still be sitting on an unpatched, exploitable environment. Budgeting for one doesn’t substitute for the other. They’re answering different questions about the same organization, and the same logic applies to audits: passing one doesn’t mean you’re safe.

Self-Check: What Belongs in Next Year’s Plan

Run through this while building out the calendar:

  • Payment card data in scope? PCI DSS testing is likely an annual fixed date, plus a contingency trigger for significant infrastructure changes.
  • Pursuing or maintaining SOC 2? Confirm evidence expectations with your auditor in writing before setting the budget line.
  • Certified or pursuing ISO 27001:2022? Testing cadence should trace back to a documented risk assessment. If that rationale isn’t written down yet, that’s the gap to close first.
  • Multiple frameworks at once? Scope penetration testing to satisfy the strictest requirement across all of them rather than running separate engagements.
  • When was the incident response plan last actually tested, not reviewed on paper, but run through a live scenario with the people who’d be in the room? If it’s been more than a year, or never, a gamified tabletop exercise is worth scoping alongside the pentest conversation.

For a faster, structured version of the pentest side of this self-check, the free Pentest Readiness Assessment walks through seven questions and returns a scorecard with a tier rating and prioritized next steps.

What to Do Next

Three paths, depending on where the organization stands heading into planning season:

  1. Confirm pentest scope and tier. Run the Pentest Readiness Assessment for a personalized scorecard before locking in a budget number.
  2. Scope a gamified tabletop exercise. A short call confirms scope, walks through sample scenarios, and outlines timelines. Details on format and included scenarios are on the Gamified Tabletop Exercises page, and if the line item needs internal sign-off first, how to get budget approved for a gamified tabletop exercise covers that conversation.
  3. Review the deliverables directly. Redacted sample reports for Web Application, Internal Network, and Gamified TTX engagements are available on request, and they’re useful for finalizing what to ask any vendor to deliver next year.

Schedule a consultation to talk through both lines of the budget at once. Replies within one business day.

Explore Our Penetration Testing Services

Certified testing with five free re‑tests

View Penetration Testing

Curious how EliteSec stacks up against the competition? See our comparison with large consulting firms.

Related Posts