Start with a business service

A useful exercise is anchored in a critical service and plausible dependencies, not a generic malware story. Identify the technology, identities, suppliers, data, operational workarounds and regulatory obligations that shape real decisions.

The scenario should create uncertainty progressively while preserving enough information for participants to make choices. The objective is to observe decisions, not to catch people out.

Test decision rights

Exercises should force choices about isolation, business continuity, customer communication, regulatory notification, ransom position, evidence preservation and recovery priority. Facilitators should ask who has authority, what evidence they need and how quickly the decision must be made.

If every answer is ‘the incident team decides’, governance is probably not specific enough.

Challenge recovery assumptions

Backups are not proof of recovery. Test identity dependencies, clean-room requirements, administrative access, restoration sequencing, data integrity and the time needed to validate a recovered service.

Include supplier unavailability and compromised credentials. These conditions reveal hidden dependencies that a conventional backup report will miss.

Turn observations into control change

Record decisions, uncertainties, missing information, conflicting procedures and control failures. Assign each improvement to an owner with an outcome and target date.

Re-test material gaps and report whether critical decisions became faster, evidence improved and recovery assumptions were validated. The exercise creates value only when the operating model changes afterward.