It’s long been accepted that not all cyber-attacks are preventable.
Organisations can adopt the strictest controls, deploy advanced security tools and prioritise regular staff training, but attackers still get through.
This doesn’t mean their security posture is weak or that they are failing, it simply means the odds have tipped in the favour of attackers. There are simply too many entry points, each with their own challenges, to achieve complete security. Attackers will eventually succeed.
Given this position, it’s now widely accepted that incident response planning has become a critical component of an organisation’s defensive architecture.
Incident response planning helps organisations prepare for incidents, allowing them to identify how certain cyber events could impact their operations and then work to limit those damages.
The planning helps organisations pre-agree the roles and responsibilities of team members to mitigate an attack, understand who needs to be contacted in the event of a cyber incident, understand how certain scenarios could impact their data, customers and operations, and take steps to lower their exposure to attacks.
However, pulling together a plan that simply gathers dust on a shelf is not enough.
For organisations to understand how effective their plan is, they must exercise it as well.
This is where Cyber Incident Exercising (CIE) becomes increasingly valuable.
Cyber Incident Exercising
Cyber Incident Exercising allows organisations to test the effectiveness of their incident response plans during a simulated cyber event with a dedicated expert.
The sessions help organisations improve their preparedness to handle real-world threats, enabling teams to practise their roles, identify gaps in processes or technology and enhance coordination across departments and external partners. The ultimate goal is driving cyber resilience and improving recovery timelines.
One of the key benefits of CIE is that the sessions allow organisations to identify gaps across their security posture, which could leave them exposed.
These gaps are difficult to identify in planning stages, as they often only come up unexpectedly during practical rehearsals, or under the surveillance of a dedicated expert.
However, once they are identified, they provide organisations with actionable intelligence to improve their resilience and enhance their security controls.
So, what are the key gaps that often come up during CIE and what can organisations learn from them?
1 – Overconfidence the plan will work
One of the issues that continually surfaces during CIE is an over-confidence that what an organisation’s incident response plan says in theory will work in practice.
Expectations rarely align with reality, and organisations must be prepared for this.
A core purpose of CIE is to uncover overlooked vulnerabilities and take steps to mitigate them.
The goal is not to undermine confidence, but to test and validate it, ensuring the existing controls and processes are truly robust enough to enable recovery from an attack.
This often means existing plans will need to be modified, processes will need to be changed and controls will need to be updated to rectify issues which surface as a result of over confidence.
This shouldn’t cause friction among team members.
Everyone should work towards the shared goal of improving security, and recognise that with every issue identified and addressed, the organisation makes strides towards resilience.
2 – Unprepared for the unexpected
When developing incident response plans, many organisations focus on scenarios they already understand and feel confident managing. Rarely do they introduce unpredictable elements that expose vulnerabilities or reflect badly on IT and security teams in the eyes of leadership.
However, this mindset leaves organisations only securing against past threats and not future-proofing their incident response.
CIE encourages organisations to step outside their comfort zones under the guidance of an expert in cybersecurity, who possesses firsthand insights into the surprises that often come up during incidents.
By simulating a range of attacks, CIE helps test the flexibility and resilience of the response plan.
It also ensures that when surprise events occur, and they always do, the organisation still has the ability to act, and recover, without being thrown into an immobilised frenzy.
3 – No contingency plans when communication is down
Whether it’s Outlook, Gmail, Teams or another messaging app, almost every corporate communication uses a unified approach with their other business software.
But what happens when these communications channels or the infrastructure they rely on are compromised?
This is often a surprise question that comes up during CIE that organisations are completely unprepared for and have no contingency plans around.
Cyber-attacks routinely lock staff out of the corporate network or their accounts, so having access to a communications application or email is never guaranteed. Furthermore, when attackers are still on an organisation’s network during an attack, email may not be the safest option.
As a result, during incident response planning organisations must consider establishing alternative communication lines that can be used during cyber events.
4 – Cyber is seen as an IT / security problem
CIE is about raising awareness of cyber events across different levels within an organisation. One issue commonly unearthed is that cyber is still being treated as a problem for IT and security only.
This is very misguided and leaves organisations in a volatile position.
Cyber-attacks routinely shatter enterprise operations and threaten the solvency of businesses. This makes them a business-wide issue and key focus for leadership teams.
Recommended reading
- Salesforce: Business Leaders Are Losing Trust in Their Data
- UK Gov Using Personal Data to Develop ‘Murder Prediction’ Tech
- Smaller AI Models May Outpace LLMs, Gartner Predicts
During CIE, it is vital a variety of roles are present, so everyone understands their responsibilities during an attack.
This allows all job roles to understand how an attack could impact the business, and practice the role they will play to support with mitigation or communication in the aftermath of the incident.
Typically, an organisation’s schedule of CIE sessions should include exercises overlapping the CEO and CFO, representatives from marketing, HR, security and IT, plus the department head most relevant to the simulated scenario.
5 – Dismissing the debrief
At the end of a CIE session, organisations will be given a debrief report by their Cyber Incident Exercising Provider, which details the findings of the simulation and discusses gaps that were discovered and provides recommendations on how they can be addressed.
Organisations should take these actions as a priority and update the incident response plans accordingly.
Ignoring this feedback risks leaving vulnerabilities unaddressed, whereas acting on it can provide a blueprint for effective recovery from future incidents.
Not all attacks can be prevented today, but they can be prepared for.
This is where CIE plays a key role in simulating cyber incidents on organisations, helping them prepare for them, exercise their response to reduce damage, while identifying gaps which could leave them vulnerable.
By conducting regular CIE sessions, organisations can enhance their ability to withstand cyber threats, close gaps in defences and significantly improve their capacity to respond to and recover from attacks.





