How it works
A facilitator presents a scenario in stages, adding new information as it unfolds: an alert, then encrypted servers, then a ransom note, then a journalist calling. Participants explain what they would do, who they would call and what they would decide. The exercise usually lasts two to four hours.
Who should take part
Not only IT. The most valuable exercises include management, legal, communications, operations and finance, because many critical decisions in an incident are business decisions: whether to shut down systems, what to tell customers, whether to notify authorities and when.
Common scenarios
Ransomware affecting core systems, a data breach with a 72 hour notification deadline, BEC fraud, a critical supplier going down, or the loss of a key cloud service.
What comes out of it
A short report with the gaps found, such as missing contacts, unclear authority, untested backups or unknown notification deadlines, and actions with owners and dates to update the incident response and business continuity plans. DORA requires financial entities to test their continuity and response plans, and exercises like this are a common way to show ISO 27001, ENS or NIS2 auditors that plans are tested.




