The short answer
A useful readiness exercise asks people to work through a hypothetical disruption together. The goal is to expose unclear responsibilities and turn them into assigned follow-up actions, before the organization faces a real incident.
Start with a business scenario
Choose one fictional situation relevant to your operations: a team cannot access a critical service, or a supplier reports a security problem. State clearly that this is an exercise. Keep it separate from production systems and avoid using actual customer records. You are testing how people make decisions, not recreating an attack.
Invite the people who make decisions
Bring together an operational leader, IT or security, communications, and other advisers appropriate to your organization. Give someone responsibility for recording questions and decisions. Set a time limit and agree that the exercise is about learning rather than assigning blame.
Ask what happens first
Who receives the report? Who decides whether to activate the response plan? Where are the necessary contact details kept? What if the usual communication channel is unavailable? Ask participants to explain the process they would actually follow. If answers depend on a single person being available, record that dependency.
Separate technical facts from business decisions
Participants may not know immediately what caused a disruption. Ask them to identify what is known, what needs verification, and which decisions cannot wait. A business leader may need to consider service continuity while qualified responders investigate. Avoid turning uncertain information into a confident statement for customers or staff.
Discuss recovery before declaring success
What would your team need to know before restoring a service or resuming normal work? Who confirms that business operations function as expected? What evidence would demonstrate that an agreed recovery objective was met? Capture the unanswered questions for the people who can validate them.
Leave with a short improvement list
For every gap, assign an owner, a due date, and a clear completion test. Examples include confirming an out-of-hours contact, clarifying decision authority, or arranging a separate recovery test. Schedule a follow-up discussion to check the actions. An exercise becomes useful when it changes the plan people will rely on.
Know the boundary
This is a planning guide, not instructions for handling an active compromise. For a real incident, use your organization's response plan and qualified incident response contacts. NIST's incident resources provide further preparation guidance. Ask Peter about the right Argent Reach expertise for an incident-readiness discussion.
General educational content. Apply it with the people responsible for your organization's security and operations.
What does this mean for your organization?
Ask to connect with Peter Reynolds for a practical conversation about your next step.
Talk with the team →Keep exploring
Seven cybersecurity questions to ask before buying another tool →