Why boards should rehearse the bad day

When I was in the RAF, exercises were part of normal life. Some were small: someone would try to follow you through a security gate, or turn up without a pass to see whether anyone would stop them. Others were anything but small. They went as far as battle damage repair on aircraft while wearing a full gas mask and NBC suit.

Every exercise had umpires. Their job was to watch, then tell us plainly what had gone wrong and what to try next time. I didn't always appreciate that at the time. Being told your best effort wasn't good enough stings.

Looking back, the debriefs taught me more than the exercises did. I learned to challenge a visitor even when it felt awkward, and I still do, even with a contractor's badge on. I learned to ask the difficult question in a meeting rather than the comfortable one. Perhaps most usefully, I learned to take criticism as information, even when I thought I had done my best.

Most boards never get that kind of practice for a cyber incident.

The gap

Boards rehearse plenty. Budgets are stress-tested, financial scenarios are modelled and media lines are prepared. Cyber incidents tend to be handled differently: there is a plan, it has been approved, and it sits in a folder until the day it is needed.

For many organisations, the first real test of that plan is a real incident. That is when they discover the out-of-hours contact list is two years old, or that nobody is sure who can authorise taking systems offline, or that the plan itself is stored on the system that has just stopped working.

What a useful drill looks like

It doesn't need NBC suits. A tabletop exercise of a couple of hours, built around a realistic scenario, will surface most of the problems. The scenario should force real decisions:
- Who declares that this is an incident, and on what evidence?
- Who decides to shut systems down, knowing that will stop parts of the business?
- When do we tell regulators, insurers, customers and staff, and who speaks for us?
- If there is a ransom demand, what is our position, and who has the authority to hold it?

Include the board, or at least the chair and a non-executive or two. Their decisions are part of the plan, and they are usually the least practised.

The umpire matters

The part organisations most often skip is the one I value most: an independent observer who watches, then says plainly what didn't work. Without one, exercises drift into performances where everyone agrees it went well.

A good debrief keeps learning separate from blame, records a short list of improvements with named owners, and checks at the next exercise whether they were made.

Questions for the board

- When did we last rehearse a serious cyber incident, and were board members in the room?
- What did we learn, and what has changed since?
- Could we run our response if our own systems, email included, were unavailable?
- Where is the contact list we would need at 2am, and when was it last checked?

Nobody expects a board to be perfect on the day. It needs to have practised enough to decide quickly and calmly when it counts. In my experience, that comes from being watched, criticised and doing it again.

Previous
Previous

Data hoarding: a board-level courage test

Next
Next

Why AI strategy needs more pessimists