Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 7 of 26

1.5 Test and exercise

You will have captured a range of scenarios and associated defensive actions and procedures. You will need to test each of these, to check they function as intended, and that their impact on the business is understood. 

Test technical controls and conduct exercising. Document your current risk exposure and how effective your technical controls are.

Test/exercise activitySupporting information
Test and review procedures across your organisation’s different functional areas.This will ensure they’re aligned, for example emergency response, incident response and business continuity planning.
Test and communicate plans with everyone in the organisation.

Plans must be understood by everyone who will be required to act.

Ensure plans are handled securely, and not accessible to a threat actor, who could try to delete or alter them. This could include storage in multiple locations and hard copies. 

Conduct assurance on all planned mitigations, such as adversary simulation.

So you can have confidence the mitigations are doing what is expected before being deployed in a time of crisis. This should include testing, exercising, and a feedback loop for lessons learned. 

Cyber Adversary Simulation (CyAS) 

Cyber incident exercising (CIE) provides a controlled, scenario-based opportunity for organisations to practise, evaluate and improve their cyber incident response plans in a safe environment. NCSC’s CIE scheme  provides details of specialist companies which provide CIE services.

Published

Reviewed

Version

1.0