A rehearsal, not a new emergency

This is evergreen guidance, not a response to a new incident. The NCSC says cyber exercises let organisations test resilience and practise decisions in a safe environment. Its guidance is aimed at IT, cyber-risk and business-continuity teams in small and medium-sized organisations, and its free Exercise in a Box service provides ready-made material for teams that are new to exercising.

The purpose is not to stage a dramatic technical contest. A useful exercise asks whether the organisation can follow its existing response plan when information is incomplete, important services are unavailable and decisions have business consequences. The NCSC is explicit that an exercise should test a plan already in place, not be used to create that plan during the session.

[1]

Choose one decision chain

Start with a scenario connected to a material business risk: ransomware affecting orders, a compromised supplier account, loss of an important cloud service or suspected theft of customer data. Define what the session must learn before writing the storyline. Useful objectives might include establishing who can isolate a service, how an incident is declared, when leadership or legal advisers are involved, and how customers and staff receive accurate updates.

A tabletop is discussion-based; participants explain what they would do as the scenario develops. CISA's exercise packages provide customisable objectives, scenarios, discussion questions and after-action templates. They cover subjects including ransomware, phishing, insider threats and industrial-control compromise. The packages are US government resources, so UK organisations should adapt regulatory, reporting and organisational details rather than adopting them unchanged.

[1][2]

What businesses should do

Keep the first exercise small enough to finish. Appoint a facilitator, select a named scenario and invite the people who would genuinely carry the response: service owners, leadership, communications, business continuity and relevant suppliers. Give participants access to the current response plan and important contact details. Label all exercise messages clearly so that simulated events cannot be mistaken for a real incident.

Introduce a few credible updates, sometimes called injects, that force decisions rather than reward technical trivia. Ask who has authority, which evidence must be preserved, what can safely be disconnected, how essential work continues and who approves external communication. Suppliers should participate where the real plan depends on them. Do not contact live emergency services, customers or regulators as part of a simulation unless that activity has been specifically agreed and safely controlled.

Measure a few observable outcomes. The NCSC suggests considering adherence to the plan, time taken for key tasks, decision quality and the effectiveness of actions. Record gaps without turning the session into a performance review. A confused handover, an inaccessible contact list or a recovery estimate based on an untested backup is a useful finding when discovered during rehearsal.

Finish with a short review while details are fresh, then produce a concise after-action record. Assign each recommendation to a business owner with a target date. Update plans, contacts and technical arrangements before repeating the exercise. CISA's templates include participant feedback and an after-action report; the NCSC likewise recommends implementing lessons before the next exercise.

  • Test an existing plan against one material business risk.
  • Include decision-makers, service owners and dependent suppliers.
  • Label every simulated message unmistakably as an exercise.
  • Measure decisions, handovers and recovery assumptions.
  • Give each lesson a named owner and completion date.
[1][2]

The Beekeeper view

Incident plans often look complete because the difficult parts are hidden inside verbs such as notify, isolate and recover. An exercise turns those verbs into names, permissions, telephone numbers and elapsed time. That is where paper confidence either becomes an operational capability or reveals honest work to do.

The best result is not a team that wins the scenario. It is a short list of weaknesses the business can now fix, followed by another rehearsal that proves the fixes work. Calm response is rarely improvised; it is practised.

[1][2]
Run a bounded exercise against an existing incident plan, involve the people who would make business decisions, and give every lesson an owner and deadline.

Primary sources

  1. Effective steps to cyber exercise creation — National Cyber Security Centre, 3 February 2020
  2. CISA Tabletop Exercise Packages — US Cybersecurity and Infrastructure Security Agency, 14 July 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.