
Ransomware encrypts a file server at 8:17 a.m. Does the IT manager immediately isolate the source workstation? Who decides to cut VPN access? At what point are management, the insurance provider and customers notified? This is precisely why you need to prepare an incident response exercise before a crisis hits. The goal is not to catch teams off guard. It is to verify that the organization can protect its operations under pressure, with clear decisions and assumed responsibilities.
Why an exercise reveals what procedures do not show
Most organizations have an incident response plan, sometimes required by a client, an insurance provider or a compliance obligation. Yet a document stored in a shared folder does not guarantee it will be usable during an attack. In a real situation, information is incomplete, key contacts do not always respond and business priorities may conflict with containment requirements.
An exercise highlights these gaps without exposing the organization to a real interruption. It measures less the theoretical quality of a procedure than the collective capacity to put it into practice. Technical teams must identify, contain and document. Operational managers must assess the impact on services. Management must quickly arbitrate between availability, security, contractual obligations and communication.
For an SME or mid-sized organization, this test is particularly valuable. Internal resources are often limited and certain critical expertise rests on one or two people. An exercise makes it possible to identify these dependencies before an unavailability, absence or overload turns a contained incident into a prolonged outage.
Preparing a useful incident response exercise
A good exercise does not start with a dramatic scenario. It starts with a concrete business question: what event could disrupt our operations, expose our data or undermine our customers' trust? The scenario must be realistic enough to prompt real decisions, yet constrained enough to remain manageable within the allocated time.
Define the objective before the scenario
Set a primary objective. Are you seeking to validate the escalation of an endpoint alert? To test the reaction to phishing fraud in Microsoft 365? To verify coordination between IT teams, executives and an external provider? An exercise that attempts to cover everything often produces much discussion but few actionable lessons.
Objectives should also be measurable. For example, the organization may want to confirm that an alert reaches the right decision-maker in under 30 minutes, that risky access is suspended according to a validated procedure, or that external communications are subject to formal approval. These criteria prevent concluding vaguely that "the exercise went well".
Choose a scenario close to your actual exposure
The scenario should reflect your technology environment and critical activities. An organization heavily dependent on Microsoft 365 will benefit from simulating an account compromise with fraudulent forwarding rules and spoofing attempts. An industrial or multi-site organization may instead test a VPN intrusion, a compromised workstation or network unavailability affecting production.
Among frequently relevant scenarios are the following:
- a phishing email resulting in the compromise of a privileged account;
- suspicious behavior detected on a workstation, with the risk of ransomware propagation;
- exploitation of a vulnerability on equipment exposed to the Internet;
- exfiltration of customer data from a cloud environment;
- a payment fraud attempt initiated by executive spoofing.
Realism does not mean you need to reproduce an attack from end to end. For a first session, a tabletop exercise is often the best choice. Participants receive information as the discussion unfolds and explain the decisions they would make. A technical simulation is more demanding, but becomes relevant when procedures and roles are already well established.
Bring together the right people
Incident response is never solely the responsibility of the IT department. Invite people capable of deciding, executing or informing: IT manager, management, operations, finance when payments are involved, human resources if employees are affected, as well as legal or communication leads depending on your organization's structure.
The presence of a cybersecurity partner can bring decisive value. They bring an external perspective on technical indicators, containment measures and recovery steps. But they should not replace your organization's decision-makers. A partner's role is to strengthen response capacity, not to guess your risk acceptance thresholds or business priorities on behalf of management.
Give the simulation a credible pace
An effective exercise unfolds in sequences. The facilitator first presents a weak signal: a detection alert on a terminal, a user call, unusual activity spike in logs or a customer report. They then add elements as participants ask the right questions or make decisions.
This progression reveals whether the team knows how to request useful information. Where are the logs located? Who can verify suspicious connections? Do the firewall, endpoint protection and messaging tools provide correlatable elements? Do you have up-to-date contact information for your cloud provider, cyber insurance provider and internal managers?
The facilitator must create realistic pressure, without turning the exercise into a trap. Service unavailability, a difficult-to-reach executive or a social media rumor can be introduced if it serves the objective. Conversely, injecting complications unrelated to your organization's risks diverts attention and weakens the quality of observed decisions.
Test decisions, not just technical reflexes
The central question is not only "can we remove the malware?" It is also "who has the authority to disconnect a critical system?", "when do we classify the event as a major incident?" and "what evidence must we preserve before any irreversible action?".
In some cases, immediately isolating an asset is the right answer. In others, a sudden disconnection may compromise an essential operation or erase information useful to the investigation. There is no universal rule. The exercise must bring out the decision conditions, authorized persons and escalation paths, to avoid improvisation at the worst moment.
Communication deserves the same attention. Premature disclosure can create unnecessary commitments or spread inaccurate information. Conversely, waiting too long can amplify uncertainty among customers and employees. Test approval circuits, internal messages and thresholds that trigger regulatory, contractual or public communication.
Evaluate the exercise with evidence
Designate one or two people to observe and take notes. They should not be absorbed by operational decisions. Their role is to note delays, areas of hesitation, missing information and improvised workarounds.
Evaluation can rely on simple indicators: detection and escalation time, ability to identify affected systems, decision time for containment, availability of critical contacts, quality of traceability and clarity of communications. These measures are not meant to rate individuals. They are meant to prioritize improvements that will truly reduce your organization's exposure.
A slow response is not necessarily a failure if the team chose to verify essential information before acting. Conversely, the absence of a designated owner, escalation procedure or visibility into affected assets is a signal to address quickly. The quality of a response depends as much on organization as on deployed tools.
Transform findings into defensive capacity
The exercise's value is decided after the session. Conduct a debrief in the days following, while facts are still fresh. Classify actions by priority: what must be corrected immediately, what requires a planned project and what simply calls for documentation updates or targeted training.
Fixes may involve technology—enabling logging, hardening remote access, improving alerts—but also people and processes. This may include formalizing decision delegation, updating a contact list, clarifying responsibilities between IT and operations, or testing backup restoration. An untested backup is an assumption, not a continuity guarantee.
Keep an action plan with an owner, deadline and proof of completion. Then schedule another exercise. The frequency depends on your exposure, obligations and evolving environment. An organization adopting new cloud tools, opening a site or handling more sensitive data should test more often than a stable structure. In any case, an annual exercise is a reasonable minimum, supplemented by targeted simulations after major changes.
Preparing an incident response exercise gives your teams the right to learn when consequences are managed. Each decision clarified, each contact verified and each gap corrected strengthens your capacity to protect operations when the attack itself is not a simulation.