How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 7 of 26
1.5 Test and exercise
You will have captured a range of scenarios and associated defensive actions and procedures. You will need to test each of these, to check they function as intended, and that their impact on the business is understood.
Test technical controls and conduct exercising. Document your current risk exposure and how effective your technical controls are.
| Test/exercise activity | Supporting information |
|---|---|
| Test and review procedures across your organisation’s different functional areas. | This will ensure they’re aligned, for example emergency response, incident response and business continuity planning. |
| Test and communicate plans with everyone in the organisation. | Plans must be understood by everyone who will be required to act. Ensure plans are handled securely, and not accessible to a threat actor, who could try to delete or alter them. This could include storage in multiple locations and hard copies. |
| Conduct assurance on all planned mitigations, such as adversary simulation. | So you can have confidence the mitigations are doing what is expected before being deployed in a time of crisis. This should include testing, exercising, and a feedback loop for lessons learned. |
| Cyber incident exercising (CIE) provides a controlled, scenario-based opportunity for organisations to practise, evaluate and improve their cyber incident response plans in a safe environment. | NCSC’s CIE scheme provides details of specialist companies which provide CIE services. |