Resources · 08

Cyber incident exercise: test decisions before the crisis

Build a realistic scenario that tests coordination, continuity, evidence, communication and service recovery without disrupting production.

· 15 min

Security and continuity specialists validating service recovery evidence

What this guide helps achieve

  • Clarify who decides under pressure
  • Test fallback channels
  • Validate the actual recovery order
  • Turn gaps into verifiable actions

Quick check

  • Does the scenario target a precise capability?
  • Are crisis contacts available offline?
  • Who can isolate a system?
  • Which service must return first?
  • Who informs customers, authorities and partners?

Step-by-step method

  1. 01

    Define the objective

    Select two or three capabilities to test: qualification, decision, containment, continuity, notification or recovery. State what remains out of scope.

    Deliverable: mandate and success criteria.

  2. 02

    Build a plausible scenario

    Start from real assets and dependencies. Gradually add outage, conflicting information, external pressure and business constraints without pursuing spectacle.

    Deliverable: confidential master scenario.

  3. 03

    Prepare roles and injects

    Name exercise control, observers and participants. Each inject should trigger an observable decision, not merely deliver news.

    Deliverable: timeline and inject cards.

  4. 04

    Run without trapping people

    Explain the rules, distinguish simulation from a real incident, protect production and let teams use their normal procedures.

    Deliverable: decision and communication log.

  5. 05

    Debrief twice

    Capture observed facts first, then analyse causes, trade-offs and dependencies. Separate documentation gaps, authority gaps and technical issues.

    Deliverable: evidenced findings and lessons.

  6. 06

    Close the gaps

    Give every action an owner, date and proof. Replay critical steps or test restoration instead of closing by declaration.

    Deliverable: improvement plan and confirmation test.

Management indicators

IndicatorWhat it measuresFirst action
Mobilisation timeTime required to assemble essential rolesFix directories and deputies
Decision timeDelay between a qualified signal and an explicit decisionClarify thresholds and authority
Recovery orderServices restored according to approved business priorityAlign technical dependencies and needs
Actions closedGaps fixed with verified evidenceReplay the highest-risk points

Common pitfalls

  • Writing an over-complex scenario
  • Assessing individuals instead of the system
  • Forgetting customers, suppliers and authorities
  • Producing a report without closure tests

Frequently asked questions

Must an exercise take systems offline?

No. A tabletop exercise tests decisions without real technical action. Restoration or failover tests need a separate safe scope.

Who should participate?

Roles that make a decision or perform a critical action, plus deputies when continuity depends on them.

How long should it take?

Two to four hours often works for a targeted objective, plus preparation, debrief and action follow-up.