Home — Services

Incident readiness

Your plan is a document. Find out what your people actually do.

Scenario-based exercises built from the threats that genuinely apply to you, run against your real decision-makers, and scored against defined criteria so you can evidence improvement rather than assert it.

Scenarios drawn from real threat intelligence Scored against defined criteria Executive, technical or combined Evidence for your regulator

The problem

Most tabletops are theatre.

The pattern is familiar. A generic ransomware scenario, a room of people who know it is an exercise, a facilitator who steers away from anything uncomfortable, and a closing slide confirming everyone performed well. Everyone leaves reassured, an attendance record goes in the compliance folder, and nothing about the organisation has changed.

The failure is usually in the scenario. If it isn't built from a threat that would realistically target you, participants can't reason about it properly, and the decisions they make in the room tell you nothing about the decisions they'd make at three in the morning during a real one.

We build scenarios from actual intelligence about who targets organisations like yours, then let the exercise go where it goes. The uncomfortable moments are the ones worth paying for.

Formats

Three levels, depending on what you need to prove.

01

Executive tabletop

Board and executive decision-making under pressure. Disclosure and regulatory notification, customer and market communication, ransom position, third-party dependency, and the authority questions that surface when the people who normally decide are unavailable.

02

Technical tabletop

Detection, triage, containment and recovery walked through by the people who would actually do it. Where the telemetry is, who has access out of hours, what the runbook assumes that is no longer true.

03

Live-play crisis simulation

Injects delivered in real time across both groups, including the handoffs between them. The most demanding format, and the one that most reliably exposes the gap between the technical response and the executive one.

Method

How an exercise runs.

01

Scoping

Objectives, participants, critical functions in scope, and what you need to be able to evidence afterwards.

02

Scenario build

Built from adversaries with real intent and capability against your profile, and the tradecraft they actually use.

03

Delivery

Facilitated in person or remotely, with injects escalating as the exercise develops.

04

Scoring

Performance assessed against criteria agreed at scoping, not impressions formed on the day.

05

Report and actions

Findings, scored results, and a remediation plan with owners — written to be shown to a regulator.

Typical duration
Half day for a single-group tabletop; full day for combined or live-play
Participants
Typically 8–15 per group — small enough that nobody hides
Delivery
In person or remote
Preparation
Scoping session plus scenario build, ahead of delivery
Output
Scored assessment, written findings, prioritised remediation plan with named owners

Questions

Common questions.

Does this satisfy a regulatory requirement?

Exercising is an expectation under DORA and under most supervisory approaches to operational resilience. What supervisors look for is evidence that exercises happen, that they are realistic, and that findings get closed — which is why the scoring and the remediation plan matter more than the exercise itself.

Should executives and technical teams be exercised together?

Eventually, yes — the handoff between them is where most real incidents go wrong. But if the two groups have never exercised separately, running them together first tends to produce a session where neither performs well and nobody learns much.

What if it goes badly?

Then it was worth running. An exercise that everyone passes has usually been set too easy. The report is written to be constructive, but it will say what happened.

How often should we exercise?

Annually as a floor for each group, and after any significant change — a major system migration, an acquisition, a new critical third party, or a change in the people who hold decision authority.

Can you exercise the scenarios from our threat-led test?

Yes, and it is a strong pairing. Running your response against the same scenarios the red team will emulate gives you a genuine read on detection and response before the test rather than after it.

Also relevant

Related work.

Contact

Start with a conversation.

Thirty minutes, no pitch deck. Tell us who needs exercising and what you need to be able to evidence.