They are working only if they reveal whether leaders can make tradeoffs under pressure, not just repeat steps from a runbook. Good exercises expose gaps in coordination, priority setting, and authority, especially when information is incomplete or changing. If the exercise validates the plan without challenging decision quality, it has tested the wrong thing.
What “working” actually means in a cyber crisis exercise
An exercise is useful when it tests decision-making under uncertainty, not just whether people can recite the incident plan. The real question is whether leaders can set priorities, accept tradeoffs, and coordinate across functions when facts are incomplete, contradictory, or changing. If the team only proves it can follow a script, the exercise has validated process familiarity, not crisis readiness.
That distinction matters because cyber crises rarely unfold in a clean sequence. The organisation needs to see whether the right people know who can decide, which decisions can wait, and which actions create the largest blast radius if they are delayed or rushed. Strong exercises surface ambiguity in authority before a real incident does.
How to judge whether the exercise exposed the right failure points
Look for evidence that the exercise revealed friction, not just speed. A good exercise usually exposes coordination gaps between security, operations, legal, communications, and business leadership, especially when those groups must act on partial information. It should also show whether escalation paths are realistic, whether assumptions are shared, and whether leaders can resist making the wrong call too early.
The most useful output is not a polished score, it is a set of observed failure modes: delayed ownership, conflicting priorities, unclear approval thresholds, or overreliance on one individual. Those findings tell you the organisation has tested something material. If everyone stays comfortable throughout the scenario, the exercise may have been too scripted to be diagnostic.
For incidents driven by active exploitation or exposed credentials, exercises should also test whether the organisation can move from discussion to containment without waiting for perfect proof. That is where exercises often miss the real world, because the Known Exploited Vulnerabilities catalog reflects the kind of confirmed exploitation pressure that can turn a planning problem into an urgent operational one.
What good follow-up looks like after the exercise
Good follow-up turns observations into decision fixes, not just action items. If the scenario exposed weak prioritisation, unclear authority, or slow escalation, the organisation should record exactly which decision broke down, who needed to act, and what evidence they lacked at the time. That is more valuable than generic “improve communication” notes.
Use the debrief to separate three things: what the plan said should happen, what actually happened, and what the organisation would choose to do differently next time. That comparison shows whether the exercise improved judgement. It also prevents teams from confusing procedural compliance with operational resilience.
Where the exercise surfaced third-party, supply chain, or credential-related exposure, the follow-up should be concrete enough to test whether the organisation can remove or contain trust dependencies quickly. Internal learning is strongest when it is anchored in a real failure path, such as the Sisense breach 2024, which shows how a single credential path can open access to a much wider set of sensitive materials.
Risk and Threat Considerations
A cyber crisis exercise is risky when it only rehearses communication flow and not authority under pressure. In a real incident, the organisation can lose time because nobody is sure who can approve containment, service shutdown, customer notification, or public statements while evidence is still incomplete.
Failure mechanism: The exercise becomes a confirmation exercise, so leaders get comfortable because the scenario is easy to narrate and nobody is forced to make a hard tradeoff. That hides the exact failure mode that matters in a crisis: delayed containment, unclear ownership, and decisions that are technically correct but operationally too slow.
Impact: The organisation leaves with false confidence, then discovers during a real event that escalation is slower, coordination is weaker, and the plan is less usable than it appeared. That can increase downtime, extend exposure, and create avoidable recovery costs.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RR-01 — Roles, Responsibilities, and Authorities | Exercises must test whether crisis roles and decision authority are clear under stress. |
| RC.RP-01 — Recovery Plan Execution | Crisis exercises should prove teams can execute recovery actions when information is incomplete. | |
| Recommendation — Define crisis decision authorities and validate them in exercise scenarios. Rehearse recovery decisions under changing conditions and refine the plan from results. | ||
| NIST SP 800-53 Rev 5 | IR-4 — Incident Handling | Cyber crisis exercises directly evaluate incident handling coordination and response decisions. |
| IR-3 — Incident Response Testing | The subject is specifically about whether exercises are effective and revealing the right gaps. | |
| Recommendation — Exercise incident handling roles, escalation, containment, and communication paths. Test incident response procedures with scenarios that stress decision quality. | ||
| CIS Controls v8 | CIS-17 — Incident Response Management | Exercises are a core way to validate incident response governance and coordination. |
| Recommendation — Validate incident response plans with scenarios that force tradeoff decisions. | ||
Practitioner Guidance
What to verify: Test whether the exercise produces observable decision evidence, not just participation. A useful after-action review should show who made each key decision, what information they had, what alternatives they rejected, and where authority was unclear.
Decision rule: If an exercise ends with “we followed the plan” but no one had to choose between competing priorities, treat it as incomplete. If the scenario never forced a business-off, containment, or communications decision, increase ambiguity next time.
Practitioner takeaway: A cyber crisis exercise has value only when it proves the organisation can choose under pressure, because crisis readiness is ultimately a judgement test, not a memorisation test.
Related resources from NHI Mgmt Group
- How can organisations tell whether NHI governance for agents is working?
- How can organisations tell whether SOX access governance is actually working?
- How can organisations tell whether identity posture sync is actually working?
- How can organisations tell whether their AI security model is actually working?