Resources · 08
Cyber incident exercise: test decisions before the crisis
Build a realistic scenario that tests coordination, continuity, evidence, communication and service recovery without disrupting production.
· 15 min
What this guide helps achieve
- Clarify who decides under pressure
- Test fallback channels
- Validate the actual recovery order
- Turn gaps into verifiable actions
Quick check
- Does the scenario target a precise capability?
- Are crisis contacts available offline?
- Who can isolate a system?
- Which service must return first?
- Who informs customers, authorities and partners?
Step-by-step method
- 01
Define the objective
Select two or three capabilities to test: qualification, decision, containment, continuity, notification or recovery. State what remains out of scope.
Deliverable: mandate and success criteria.
- 02
Build a plausible scenario
Start from real assets and dependencies. Gradually add outage, conflicting information, external pressure and business constraints without pursuing spectacle.
Deliverable: confidential master scenario.
- 03
Prepare roles and injects
Name exercise control, observers and participants. Each inject should trigger an observable decision, not merely deliver news.
Deliverable: timeline and inject cards.
- 04
Run without trapping people
Explain the rules, distinguish simulation from a real incident, protect production and let teams use their normal procedures.
Deliverable: decision and communication log.
- 05
Debrief twice
Capture observed facts first, then analyse causes, trade-offs and dependencies. Separate documentation gaps, authority gaps and technical issues.
Deliverable: evidenced findings and lessons.
- 06
Close the gaps
Give every action an owner, date and proof. Replay critical steps or test restoration instead of closing by declaration.
Deliverable: improvement plan and confirmation test.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Mobilisation time | Time required to assemble essential roles | Fix directories and deputies |
| Decision time | Delay between a qualified signal and an explicit decision | Clarify thresholds and authority |
| Recovery order | Services restored according to approved business priority | Align technical dependencies and needs |
| Actions closed | Gaps fixed with verified evidence | Replay the highest-risk points |
Common pitfalls
- Writing an over-complex scenario
- Assessing individuals instead of the system
- Forgetting customers, suppliers and authorities
- Producing a report without closure tests
Frequently asked questions
Must an exercise take systems offline?
No. A tabletop exercise tests decisions without real technical action. Restoration or failover tests need a separate safe scope.
Who should participate?
Roles that make a decision or perform a critical action, plus deputies when continuity depends on them.
How long should it take?
Two to four hours often works for a targeted objective, plus preparation, debrief and action follow-up.






