blog hero

Cybersecurity Blog

Stay updated on the latest trends and insights in cybersecurity.

Date: 11/29/2025

Crisis Exercise

Crisis Exercise: We Thought We Knew What to Do During a Cyberattack - Until the Exercise

Discover how a realistic cyber crisis exercise with a unique injection system can prepare your organization for real cyberattacks and save your company millions.

Crisis Exercise: We Thought We Knew What to Do During a Cyberattack - Until the Exercise
"During the exercise, we realized that nobody knew who should take the lead. Our systems were 'under attack', customers were calling in panic, and we had four different people making contradictory decisions. If this had been a real attack, it would have cost us millions. The exercise literally saved our company." - Operations Director at a financial service provider

Forget tabletop exercises, experience a realistic cyber crisis

Imagine this: you and your team are sitting in a specially equipped crisis room. Suddenly, an email arrives: "This is the security monitoring service, we are detecting unusual activity on your servers." A few minutes later, a message appears in your customer service inbox: "I see strange transactions on my account, what's happening?"

And then, while you're still processing these first signals, a tweet appears: "Your customer data is being offered for sale on the dark web"

This is not a real attack. These are components of our cyber crisis exercise - so realistic that your adrenaline rises, but in a safe environment where making mistakes is actually valuable.

What makes our cyber crisis exercise unique: the injection system

The secret to effective preparation lies in what we call "injects" - carefully designed scenario elements that can be introduced through different channels during the exercise:

  • Email injects: Simulated phishing attempts, notifications from "customers" or threatening messages from attackers
  • Telephone injects: Real-time conversations from simulated journalists, customers, or other stakeholders
  • Social media injects: Simulated posts on Twitter or LinkedIn about your "data breach"
  • System alerts: Technical alerts that your security team must interpret
"The various injects made it incredibly realistic. The social media posts about our 'data leak' caused real stress for our communication team, exactly as would happen in real life." - PR manager at a retail company after an exercise

Impressive results from recent cyber crisis exercises

Organizations that have completed our exercises report:

  • 83% faster detection of security incidents
  • 71% more efficient communication during crisis
  • 65% improved coordination between departments
  • 92% of participants feel better prepared for a real crisis
"The exercise showed that our technical teams were well prepared, but our management had no idea what their role was." This finding alone was worth more than the investment." - CISO of a manufacturing company

Why do so many organizations not prepare well? The three most commonly cited reasons:

  1. "We already have a plan on paper" - But has anyone ever tested it? Does everyone know their role?
  2. "We don't have time for exercises" - But do you have time for weeks of recovery operations after an attack?
  3. "This won't happen to us" - The most dangerous assumption of all.

Anatomy of our cyber crisis exercise: How the process unfolds

Our exercises follow a proven structure that ensures maximum learning value:

Structure of the exercise

1. Inject / Scenario: The starting point of the crisis

We begin with a carefully created inject - for example, a simulated notification from a security monitoring system:

"We are seeing unusual login activities from multiple countries on your customer portal. There have been over 50 password reset requests in the last 30 minutes."

Each inject is based on actual incidents and is specifically tailored to your organization and sector.

2. The dual response: Procedural and Technical

Immediately after the first inject, your team splits into two complementary workflows:

The procedural response:

Here we see how your crisis team responds at an organizational level:

  • Who activates the incident response plan?
  • What decision-making authorities are granted?
  • How is the situation assessed?
  • Who is responsible for which actions?
"We thought our crisis response plan was clear, until the exercise. Nobody knew who should take the lead, and everyone looked to each other for answers." - COO of an insurance company

The technical analysis:

Simultaneously, your technical team gets to work:

  • Analysis of the inject signals: What is happening technically?
  • Establishing the attack vector and scope
  • Identifying affected systems
  • Developing an initial containment strategy
"The technical team dove straight into the logs and completely forgot to communicate with management. Meanwhile, management was making decisions without knowing the technical facts." - IT Manager after an exercise

3. The advisory moment: Crucial connection

The procedural and technical workflows come together in the advisory moment:

  • What do we tell senior management?
  • What options are available?
  • What risks are associated with different response choices?
  • What is the recommended approach?

This is where many organizations stumble and where our exercise shows its greatest value.

4. Deliverables: From advice to action

After the advisory moment, we see how your organization produces deliverables:

  • Internal communication strategy
  • External communication for customers and partners
  • Technical mitigation plans
  • Forensic documentation
  • Legal obligations

5. Communication: The crucial link

The communication phase tests how effectively your team can:

  • Translate complex technical situations into understandable language
  • Formulate consistent messages for different audiences
  • Proactively manage reputation risks
  • Be transparent without causing panic
"The communication injects were an eye-opener. Our technical people used jargon that nobody understood, and our PR department made statements without knowing the facts." - Communications Director of a manufacturing company.

6. The Action List: Concrete next steps

The end product of each exercise is a concrete action list:

  • Directly implementable improvements
  • Responsible persons for each action item
  • Timelines for implementation
  • Priorities based on risk impact
"The action list was the most valuable part. We didn't have this before and thus had no overview. These are not vague recommendations, but concrete tasks that we could tackle immediately. We implemented 80% within a month." - Security Officer at a media company.

Example scenarios that could affect your organization

Our exercises are based on actual incidents. Here are three examples of scenarios we have recently used:

Scenario 1: The unseen attacker

First inject: "Security monitoring reports unusual outgoing network activity outside office hours over a period of 3 weeks."

This scenario tests how organizations deal with gradual, difficult-to-detect attacks where data is slowly extracted. What we often see:

  • Teams focus on the technical details but miss the bigger picture
  • Uncertainty about when management should be informed
  • Slow escalation with 'vague' signals

Scenario 2: The public ransomware crisis

First inject: "Employees report they cannot log into their systems, followed by an email with a ransom demand of €500,000 in cryptocurrency."

This scenario tests decision-making under public pressure:

  • How quickly can your team make an initial assessment?
  • Who decides whether or not to pay the ransom?
  • How do you communicate with customers when your systems are offline?

Scenario 3: The Supply Chain attack

First inject: "A critical supplier reports a data breach where your customers' data may also have been involved."

This scenario tests your ability to respond to situations outside your direct control:

  • How do you obtain reliable information from a third party?
  • Who is responsible for communication to your customers?
  • What legal position does your organization take?

Why participants experience our exercises as transformative

What distinguishes our cyber crisis exercises:

1. Fully personalized scenarios

We develop scenarios specifically for your organization, industry, and risk profile. No generic tabletop exercises, but realistic situations that could happen tomorrow.

"The exercise felt so realistic that I forgot for a moment it was a simulation. The injects were perfectly aligned with our business processes." - IT Manager at a financial institution

2. Professional role players

Our exercises include trained actors who play journalists, hackers, angry customers, and other external stakeholders - this creates an irreplaceable realistic dimension.

3. Real-time adjustments

Our facilitators adapt injects based on how your team responds, just as real attackers adjust their tactics. This ensures a dynamic and challenging experience.

4. Multi-level observation

While your team works, our experts observe not only what happens, but also why certain decisions are made. This in-depth analysis provides the most valuable insights.

Plan your cyber crisis exercise: Practical details

What can you expect on the day of the exercise?

Preparation (2 weeks before the exercise)

  • Intake conversation to determine your specific risk profile
  • Adaptation of scenarios to your organization
  • Brief briefing for key players about the process (not about the content!)

The exercise day itself

  • Morning: Reception and brief introduction (30 minutes)
  • Phase 1: First scenario injects and response (2 hours)
  • Lunch: Break during which the scenario continues to "live" evolve (1 hour)
  • Phase 2: Escalation of the scenario, decision-making under pressure (2 hours)
  • Phase 3: Communication and stakeholder management (1.5 hours)
  • Closing: First reflection and debriefing (1 hour)

After the exercise

  • Detailed analysis by our expert team (within 1 week)
  • Presentation of findings and recommendations (within 2 weeks)
  • Prioritized action list with concrete improvement points
  • Follow-up session after 3 months to discuss progress

Flexible options that suit your organization

On-site or virtual

Our exercises can be conducted:

  • At your location, in your own crisis room
  • In our specially equipped crisis facility
  • Completely virtual via a secure online environment
  • Hybrid (combination of the above)
"We chose a virtual exercise because our team works remotely. The realistic injects via our own communication channels made it surprisingly effective." - IT Director of an international consultancy

Who is the exercise intended for?

The most effective teams consist of 8-12 participants, including:

  • Crisis Team Leader
  • IT
  • IT Security specialists & Chief Information Security Officer
  • Board members
  • Communication professionals
  • Legal experts
  • HR professionals
  • Secretary

Certification and reporting

All participants receive:

  • A personal certificate of participation
  • Access to the improvement report
  • Insight into their strengths and development opportunities within their role area

Plan your exercise: An investment in business continuity

A medium-sized company that falls victim to a ransomware attack loses an average of €300,000 in direct costs and another €500,000 in indirect costs such as reputational damage and lost productivity.

For less than 5% of these costs, you can conduct a comprehensive cyber crisis exercise that:

  • Improves your response speed by an average of 60%
  • Reduces the duration of an incident by 45%
  • Reduces the financial impact by 30-50%

Plan your cyber crisis exercise today

A well-prepared organization can not only survive a cyber incident but emerge stronger from it. Our exercises offer the most realistic preparation without the risks of a real attack.

Plan your cyber crisis exercise

Would you like to know how prepared your organization is for a cyberattack? Contact us for a no-obligation conversation about our realistic cyber crisis exercises.

Schedule a conversation