Cyber Incident Exercising

Test Your Plans Before Criminals Do

A cyber incident is never just a technology problem.

Major cyber incidents quickly create business continuity challenges, communications challenges, legal considerations, operational disruption and difficult leadership decisions. The question isn’t whether your organisation has plans. It’s whether those plans work when people are under pressure.

Our Cyber Incident Exercising service helps organisations validate their preparedness, identify gaps and build confidence in their ability to respond to cyber incidents.

Delivered by Police Cyber Protect specialists and aligned to National Cyber Security Centre (NCSC) guidance and exercising methodologies, these discussion-based exercises allow organisations to explore realistic cyber incident scenarios in a safe and controlled environment.

As part of the Home Office-funded Police Cyber Crime Programme, this service is provided completely free of charge.


Who Is It For?

Cyber Incident Exercising is most suitable for organisations that:

  • Already have a Cyber Incident Response Plan (CIRP)
  • Have established business continuity arrangements
  • Understand their critical systems, services and dependencies
  • Want to validate existing plans and processes
  • Are seeking assurance around their incident response capability

We regularly exercise:

  • Medium and large businesses
  • Public sector organisations*
  • Healthcare organisations
  • Charities
  • Critical National Infrastructure operators*
  • Multi-site organisations
  • Education providers
  • Organisations with complex supply chains

Important: Some organisations, particularly Critical National Infrastructure (CNI) operators or those subject to the Network and Information Systems (NIS) Regulations, may have specific exercising requirements. In some circumstances, their regulator may require the use of NCSC-assured Cyber Incident Exercising (CIE) providers. The Police are not an NCSC-accredited CIE provider, and organisations should ensure they understand any regulatory or assurance requirements that apply to them before engaging in an exercise.

Smaller Organisations

Smaller organisations may wish to consider our other services, including Leadership Cyber Security Training and other facilitated awareness activities.

We are also developing additional exercising options aimed at organisations with less mature cyber arrangements or limited availability to commit to a full exercise programme.


Before You Exercise

Organisations gain the greatest value from exercising when they already have documented plans and have addressed known gaps in their preparedness.

If you do not currently have a Cyber Incident Response Plan, we recommend reviewing National Cyber Security Centre guidance and the resources available through the Cyber Resilience Centre for the South East before undertaking a formal exercise.

Think of exercising as testing a plan, not creating one.


What We Offer

NCSC Exercise in a Box

Exercise in a Box is the National Cyber Security Centre’s free exercising platform, containing a range of pre-built cyber incident scenarios designed to help organisations rehearse their response to common cyber security incidents.

You don’t need us to run these exercises. The platform is freely available and organisations can facilitate exercises themselves if they wish.

However, we can facilitate the exercise on your behalf, helping participants explore decision-making, incident management, communications, business continuity and recovery activities in a structured environment.

Think of us as a helpful friend sitting over your shoulder, asking the slightly difficult questions, drawing out important discussions and exploring the consequences of decisions as the scenario develops. We also provide an independent perspective and share observations drawn from our experience supporting organisations affected by real-world cyber incidents.

These exercises typically take around 2 to 2.5 hours to complete depending on the chosen exercise.


Bespoke Cyber Incident Exercises

For organisations with more mature cyber readiness arrangements, we can design and facilitate tailored tabletop exercises aligned to the NCSC Exercise Design Model.

These exercises are built around your organisation’s objectives, structures, risks and operating environment.

A bespoke exercise may include:

  • Ransomware attacks
  • Supply chain compromise
  • Business email compromise
  • Data breach scenarios
  • Network intrusion
  • Distributed Denial of Service (DDoS) attacks
  • Sector-specific cyber threats
  • Threat actor-driven scenarios

These exercises typically last 3 to 5 hours and often include a lunch break.


Our Approach

Every bespoke exercise starts with five core design decisions:

Aim

What are you trying to achieve?

Examples include:

  • Exercising your Cyber Incident Response Plan
  • Validating incident communications
  • Testing command structures
  • Exploring supply chain impacts
  • Assessing organisational resilience during a ransomware attack

Players

Who needs to be involved?

Effective exercises typically include representatives from:

  • Leadership teams
  • IT and cyber teams
  • Communications
  • Legal services
  • Data Protection Officers
  • Operations
  • Human Resources
  • Business continuity teams
  • Front-line practitioners

If a key individual would normally lead an incident response, consider whether a deputy should participate instead. This can help validate succession arrangements and resilience.

Objectives

What does success look like?

Objectives should be observable and measurable so that exercise outcomes can be assessed meaningfully.

Cyber Event

What type of incident are you concerned about?

The selected cyber event drives the scenario and allows us to build realistic impacts and decision points.

Threat Actor

Who is behind the attack?

Organised crime groups, hacktivists, insider threats, nation-state actors and supply-chain compromises can all create very different challenges for an organisation.


Exercising the Whole Organisation

We strongly encourage organisations to exercise broadly rather than focusing solely on technical teams.

Cyber incidents affect the entire organisation, not just IT. The most valuable exercises bring together people from across the business to explore how their teams would respond, communicate and recover.

Where possible, business area leads should bring their Business Continuity and Disaster Recovery plans. After all, business continuity planning shouldn’t particularly care whether a system outage is caused by ransomware, fire, flooding or a power failure. The question remains the same:

  • How does the organisation continue operating?

What Happens During an Exercise?

Whilst every exercise is different, a typical format includes:

  • Exercise briefing and instructions
  • Scenario introduction and “state of the world”
  • Incident injects and developments
    • Table discussions
    • Facilitated group discussions
    • (Repeat x4-6 times)
  • Scenario conclusion
  • Hot debrief and lessons identified

Our role is to challenge assumptions, facilitate discussion and encourage constructive learning.

This is not a technical penetration test, red team exercise or live response simulation.


Exercise Outputs

Following the exercise, participants take part in a facilitated hot debrief.

We also provide an executive-level exercise report highlighting:

  • Strengths observed
  • Areas requiring improvement
  • Gaps in plans, processes or understanding
  • Suggested priorities for future development

Because no external facilitator can fully understand every aspect of your organisation, we ask participating organisations to nominate a scribe for every table. This helps ensure lessons, observations and actions are captured accurately within individual business areas.


Not Ready for a Full Exercise?

If your organisation is still developing its cyber incident management capability, you may benefit from our Leadership Cyber Security Training, including Considerations & Consequences. This facilitated LEGO®-based exercise helps leaders build confidence discussing cyber incidents, risk and resilience before progressing to more formal exercising.

Enquire Now

Tell us a little about your organisation, cyber preparedness and what you’re hoping to achieve through exercising. We typically require at least two month’s notice for Exercise in a Box activities and significantly longer for bespoke exercises, as effective exercise design requires planning with your organisation.

FAQs

Nothing.

This service is delivered free of charge through the Home Office-funded Police Cyber Crime Programme for eligible organisations located within the South East region covered by SEROCU:

  • Berkshire
  • Buckinghamshire
  • East Sussex
  • Hampshire
  • Isle of Wight
  • Oxfordshire
  • Surrey
  • West Sussex

If your organisation is located outside our region, we may be able to direct you to the appropriate Cyber Protect team for your area.

No. Cyber Incident Exercising is a discussion-based tabletop activity. Participants are presented with realistic scenarios and work through how they would respond, communicate, make decisions and recover.

No live systems are tested.

Yes. This is a prerequisite for us to support you with exercising.

Exercises are most effective when organisations already have documented plans, defined roles and responsibilities, and established processes in place. Exercising helps validate those arrangements, identify gaps and build confidence in your ability to respond to a real incident.

If you do not currently have a Cyber Incident Response Plan, we recommend developing one before undertaking a cyber exercise. If you need a template, our partners at the Cyber Resilience Centre for the South East have one freely available (and we’d encourage you to signup while there!). The NCSC also have useful guidance.

Cyber incidents affect the entire organisation. We recommend involving representatives from leadership, communications, legal, IT, cyber security, data protection, business continuity, operational teams and any other area likely to be involved in an incident response.

We find it especially valuable to involve frontline practitioners. Quite often, the systems and data that leadership teams believe are most important do not perfectly align with the tools, services and information that operational teams actually rely on day to day.

Previous exercises have uncovered unexpected dependencies, workarounds and single points of failure that would otherwise have remained hidden until a real incident occurred.

NCSC Exercise in a Box exercises typically take around 2 to 2.5 hours.

Bespoke exercises are usually between 3 and 5 hours depending on complexity and objectives.

Yes, within reason. Where appropriate, we can tailor scenarios, impacts and objectives to reflect your organisation’s structure, risks, operating environment and concerns. We work in line with the NCSC Exercise Design Model and aim to deliver the most realistic and useful exercise possible.

However, this is a free policing service and we must balance exercise development time across the many organisations we support. As a result, bespoke exercise design and revision cycles are necessarily limited to ensure fair access to the service.

Participants take part in a facilitated hot debrief and receive an executive exercise report summarising observations, strengths, areas for improvement and recommended next steps.

No. The purpose of exercising is learning and improvement, not scoring. There is no pass or fail outcome.

In fact, some of the most valuable exercises are those that identify previously unknown gaps, assumptions, weaknesses or opportunities for improvement before they are discovered during a real cyber incident.

Success should be measured by what your organisation learns and improves as a result of the exercise.

A major cyber incident is often also a business continuity incident.

Whether critical systems become unavailable because of ransomware, a supplier failure or a technical outage, organisations still need to maintain essential services and continue operating. Exercising helps organisations understand those dependencies before a real incident occurs.

In many cases, yes.

However, some organisations, particularly Critical National Infrastructure (CNI) operators and those subject to the Network and Information Systems (NIS) Regulations, may have specific assurance or exercising requirements imposed on them by their regulator. In some circumstances, these requirements may need to be met through NCSC-assured Cyber Incident Exercising providers.

If you’re unsure whether this applies to your organisation, please get in touch and we’ll be happy to discuss your circumstances.

Not at all.

Many organisations come to us looking to run their first cyber exercise. If you already have a Cyber Incident Response Plan and a reasonable understanding of your roles, responsibilities and key systems, an NCSC Exercise in a Box exercise is often an excellent starting point.

Where we feel a different approach would be more beneficial, we’ll discuss the options and help you identify the most appropriate next step.

Tell us a little about your organisation, cyber preparedness and what you’re hoping to achieve through exercising. We typically require at least two month’s notice for Exercise in a Box activities and significantly longer for bespoke exercises, as effective exercise design requires planning with your organisation.


Service Availability and Disclaimer

All services are delivered through the Home Office-funded Police Cyber Crime Programme and are subject to available resources, operational commitments and ongoing programme funding.

Services are primarily available to eligible organisations, communities and individuals located within the South East region served by SEROCU, including Berkshire, Buckinghamshire, Oxfordshire (Thames Valley Police); Hampshire & the Isle of Wight; Surrey; and East Sussex and West Sussex (Sussex Police).

In exceptional circumstances, we may be able to support organisations outside the region where there is a clear connection to our policing area, such as organisations headquartered within the region but seeking to use an alternative venue elsewhere. Any such arrangements are entirely at our discretion.

Whilst we aim to accommodate requests wherever possible, submission of an enquiry does not guarantee that a service will be delivered. We reserve the right to decline, defer or prioritise requests based on operational priorities, capacity, funding, audience suitability and anticipated impact.

All advice, guidance, training and exercising activities are based on recognised good practice and align with guidance published by the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. However, responsibility for assessing, implementing and acting upon any advice remains with the individual or organisation receiving the service.

The South East Regional Organised Crime Unit, participating police forces and partners accept no liability for any loss, damage, cost or consequence arising from reliance upon information, advice, training materials, exercise outcomes or recommendations provided through these services.