Learning Objectives:

  • Understand the purpose and value of cyber exercises.

  • Design and conduct tabletop exercises.

  • Design and conduct technical drills and range simulations.

  • Recognise the role of exercises in continuous improvement.

5.1 The Purpose of Cyber Exercises

Cyber exercises are essential for testing and improving cyber resilience. The SEACEN course includes “the design and execution of cyber exercises at institutional and industry levels” . The Skills for Africa course covers “crisis management and disaster recovery plans” .

The Finance Derivative article notes that cyberattacks have become a systemic threat to national stability, and meeting this moment demands a shift from compliance to continuous improvement . Cyber drills build critical muscle memory across the organisation. Rather than reacting like a deer in headlights when a real attack occurs, decision-makers will have an established pattern on how to collaborate under pressure, communicate clearly, and execute with speed .

Key Benefits:

  • Testing Plans: Exercises test the effectiveness of incident response and business continuity plans.

  • Building Capability: Exercises build the skills and confidence of incident response teams.

  • Identifying Gaps: Exercises identify weaknesses in plans, processes, and capabilities.

  • Improving Coordination: Exercises improve coordination between departments and stakeholders.

5.2 Tabletop Exercises

Tabletop exercises are discussion-based exercises where participants walk through a scenario to test their understanding of roles and responsibilities. The ITEdgeNews article notes that tabletop exercises are essential because they are a “dress rehearsal for real ransomware attacks” . A well-executed tabletop exercise helps organisations test and refine incident response plans, improve communication between departments, and develop a more coordinated and efficient response .

Designing Tabletop Exercises:

Scenario Development: The ITEdgeNews article notes that simulations could begin with phishing emails that lead to a network breach or direct attacks on the organisation’s customer data or operational systems . Scenarios should be realistic and tailored to the organisation’s specific risks.

Participant Involvement: The article notes that don’t isolate cybersecurity exercises to the IT team – attacks affect every department . During a ransomware attack, IT must handle the technical aspects of containment and recovery, Legal needs to ensure compliance with notification laws and regulations, Compliance should focus on notifying law enforcement, Operations should focus on maintaining business continuity, Back Office must secure transactional data, Marketing and PR should manage external communication, and the executive team should work with ransomware negotiators .

Facilitation: The article recommends bringing in external experts to guide the process .

5.3 Technical Drills and Range Simulations

Technical drills and range simulations involve hands-on testing of technical capabilities. The ITEdgeNews article notes that “simulations can be highly realistic, creating a detailed dummy copy of the company’s network to bring it as close to home as possible” . Unlike passive training or paper-based exercises, cyber simulations recreate the chaos of a real attack by forcing teams to respond in real time .

Key Elements:

  • Realistic Scenarios: Simulations should reflect the current threat landscape.

  • Live-Fire Format: Technical and executive groups are challenged simultaneously.

  • Measurement: Hard metrics on performance can then guide targeted investment, shape future training, and give CISOs and boards confidence that they are ready .

5.4 Post-Exercise Analysis

The ITEdgeNews article emphasises that tabletop exercises should not stop at the point of containment. “A major part of ransomware resilience is recovery. A simulation should test your backup and data restoration capabilities, and provide a comprehensive systems review to see where the chinks in the armour are” .

Post-Mortem Analysis: The article recommends conducting a post-mortem analysis to assess performance, identify gaps, and make improvements . Regular tabletop exercises help teams stay sharp against rapidly evolving threats.

Regulatory Expectations: The Finance Derivative article notes that the EU’s Digital Operational Resilience Act (DORA) has raised the bar for financial services. The added scrutiny demands that financial firms go beyond policy documents and prove they can maintain operations during cyber incidents . That means showing, rather than just stating, how teams perform under stress. Simulations provide the observable, repeatable evidence of decision-making, coordination, and incident management regulators are looking for .