Incident readiness
Scenario-based exercises built from the threats that genuinely apply to you, run against your real decision-makers, and scored against defined criteria so you can evidence improvement rather than assert it.
The problem
The pattern is familiar. A generic ransomware scenario, a room of people who know it is an exercise, a facilitator who steers away from anything uncomfortable, and a closing slide confirming everyone performed well. Everyone leaves reassured, an attendance record goes in the compliance folder, and nothing about the organisation has changed.
The failure is usually in the scenario. If it isn't built from a threat that would realistically target you, participants can't reason about it properly, and the decisions they make in the room tell you nothing about the decisions they'd make at three in the morning during a real one.
We build scenarios from actual intelligence about who targets organisations like yours, then let the exercise go where it goes. The uncomfortable moments are the ones worth paying for.
Formats
Board and executive decision-making under pressure. Disclosure and regulatory notification, customer and market communication, ransom position, third-party dependency, and the authority questions that surface when the people who normally decide are unavailable.
Detection, triage, containment and recovery walked through by the people who would actually do it. Where the telemetry is, who has access out of hours, what the runbook assumes that is no longer true.
Injects delivered in real time across both groups, including the handoffs between them. The most demanding format, and the one that most reliably exposes the gap between the technical response and the executive one.
Method
Objectives, participants, critical functions in scope, and what you need to be able to evidence afterwards.
Built from adversaries with real intent and capability against your profile, and the tradecraft they actually use.
Facilitated in person or remotely, with injects escalating as the exercise develops.
Performance assessed against criteria agreed at scoping, not impressions formed on the day.
Findings, scored results, and a remediation plan with owners — written to be shown to a regulator.
Questions
Exercising is an expectation under DORA and under most supervisory approaches to operational resilience. What supervisors look for is evidence that exercises happen, that they are realistic, and that findings get closed — which is why the scoring and the remediation plan matter more than the exercise itself.
Eventually, yes — the handoff between them is where most real incidents go wrong. But if the two groups have never exercised separately, running them together first tends to produce a session where neither performs well and nobody learns much.
Then it was worth running. An exercise that everyone passes has usually been set too easy. The report is written to be constructive, but it will say what happened.
Annually as a floor for each group, and after any significant change — a major system migration, an acquisition, a new critical third party, or a change in the people who hold decision authority.
Yes, and it is a strong pairing. Running your response against the same scenarios the red team will emulate gives you a genuine read on detection and response before the test rather than after it.
Contact
Thirty minutes, no pitch deck. Tell us who needs exercising and what you need to be able to evidence.