<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Breachdeck Blog</title><description>Insights on incident response, tabletop exercises, MITRE ATT&amp;CK, and cybersecurity compliance.</description><link>https://breachdeck.com/</link><item><title>NIST 800-53 IR-3: What Federal Auditors Actually Want</title><link>https://breachdeck.com/blog/nist-800-53-tabletop-exercise/</link><guid isPermaLink="true">https://breachdeck.com/blog/nist-800-53-tabletop-exercise/</guid><description>What FISMA and FedRAMP assessors evaluate for IR-3 compliance. The control requirements, SP 800-84 methodology, and how to pass.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>nist-800-53</category><category>ir-3</category><category>tabletop-exercise</category><category>fisma</category><category>fedramp</category><category>federal-compliance</category><category>sp-800-84</category><author>Breachdeck Team</author></item><item><title>Does Your Cyber Insurance Require a Tabletop Exercise?</title><link>https://breachdeck.com/blog/cyber-insurance-tabletop-exercise/</link><guid isPermaLink="true">https://breachdeck.com/blog/cyber-insurance-tabletop-exercise/</guid><description>What cyber insurance carriers want from IR testing in 2026. Which scenarios to run, what to document, and how to time it for renewal.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>cyber-insurance</category><category>tabletop-exercise</category><category>incident-response</category><category>compliance</category><category>renewal</category><category>underwriting</category><author>Breachdeck Team</author></item><item><title>Why We Built Breachdeck</title><link>https://breachdeck.com/blog/why-we-built-breachdeck/</link><guid isPermaLink="true">https://breachdeck.com/blog/why-we-built-breachdeck/</guid><description>Tabletop exercises cost $30K+ and happen once a year. We built something that makes real incident response practice affordable and on demand.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>product-updates</category><category>tabletop-exercise</category><category>incident-response</category><category>mitre-attack</category><category>product-launch</category><author>Breachdeck Team</author></item><item><title>ISO 27001 IR Testing: A.5.24 &amp; A.5.26 Requirements</title><link>https://breachdeck.com/blog/iso-27001-incident-response-testing/</link><guid isPermaLink="true">https://breachdeck.com/blog/iso-27001-incident-response-testing/</guid><description>What ISO 27001 auditors want from IR plan testing. A.5.24, A.5.26, the 2013→2022 mapping, and how to produce evidence that passes.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>iso-27001</category><category>incident-response</category><category>tabletop-exercise</category><category>compliance</category><category>A.5.24</category><category>A.5.26</category><author>Breachdeck Team</author></item><item><title>Which Compliance Frameworks Require Tabletop Exercises?</title><link>https://breachdeck.com/blog/compliance-tabletop-exercise-requirements/</link><guid isPermaLink="true">https://breachdeck.com/blog/compliance-tabletop-exercise-requirements/</guid><description>Every major framework&apos;s tabletop exercise requirement in one place. SOC 2, PCI DSS, HIPAA, ISO 27001, NIST, CMMC, DORA, GDPR — what each demands.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>compliance</category><category>tabletop-exercise</category><category>incident-response</category><category>soc-2</category><category>pci-dss</category><category>hipaa</category><category>iso-27001</category><category>nist</category><category>cmmc</category><category>dora</category><category>gdpr</category><author>Breachdeck Team</author></item><item><title>HIPAA Incident Response Testing: What Auditors Actually Want</title><link>https://breachdeck.com/blog/hipaa-incident-response-testing/</link><guid isPermaLink="true">https://breachdeck.com/blog/hipaa-incident-response-testing/</guid><description>What the 2026 HIPAA Security Rule requires for IR plan testing, what OCR auditors evaluate, and how to run an exercise that passes.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>hipaa</category><category>incident-response</category><category>tabletop-exercise</category><category>compliance</category><category>healthcare</category><category>2026-security-rule</category><author>Breachdeck Team</author></item><item><title>PCI DSS 12.10.2: What Your QSA Wants from IR Testing</title><link>https://breachdeck.com/blog/pci-dss-incident-response-testing/</link><guid isPermaLink="true">https://breachdeck.com/blog/pci-dss-incident-response-testing/</guid><description>What PCI DSS 12.10.2 requires for IR plan testing, what QSAs actually evaluate, and how to run an exercise that passes assessment.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>pci-dss</category><category>pci-dss-4</category><category>12-10-2</category><category>incident-response</category><category>tabletop-exercise</category><category>compliance</category><author>Breachdeck Team</author></item><item><title>SOC 2 Tabletop Exercises: What Your Auditor Actually Wants</title><link>https://breachdeck.com/blog/soc-2-tabletop-exercise-requirements/</link><guid isPermaLink="true">https://breachdeck.com/blog/soc-2-tabletop-exercise-requirements/</guid><description>What SOC 2 auditors look for in IR testing evidence. CC7.3, CC7.4, CC7.5 — the criteria that matter and how to not fail them.</description><pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate><category>compliance</category><category>soc-2</category><category>audit</category><category>tabletop-exercise</category><category>CC7.3</category><category>CC7.4</category><category>CC7.5</category><category>incident-response</category><author>Breachdeck Team</author></item></channel></rss>