Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 15 of 15
Using cyber security scenarios

Introduction
In step 3 of our risk management framework guidance, we encouraged you to define your cyber security risk challenge. Exploring cyber security scenarios can help you understand the cyber security risk challenges you might be facing and develop your responses to a cyber security incident. Using scenarios can also help identify risks and issues that risk assessments and control sets might have missed.
Cyber security scenarios can be used to support two types of cyber security risk management activity.
- scenario-based exercises can help an organisation improve its response to specific scenarios to identify previously unforeseen risks and consequences
- future scenario planning can help by making organisations reappraise potential scenarios, challenging their current assumptions about what could happen in the future
If you're new to using cyber security scenarios, you may find the NCSC's Exercise in a Box useful, a free online tool which helps organisations find out how resilient they are to cyber attacks.
Scenario-based exercises
Scenario-based exercises help organisations test incident response plans to highlight any potential problems with them. This is well-established practice (a fire drill being a typical example, when participants learn the routes out of a building during an emergency). The benefits of such a drill are clear; in the event of a real fire, people will be less prone to panic as they know what they need to do. Lessons learnt (such as spotting bottlenecks in the evacuation of a building) can be used to develop 'playbooks', or documents which describe how an organisation will respond to a specific scenario. They can help to develop a consistent, focused and repeatable response.
Developing exercises and playbooks for cyber security incidents is perhaps less well established. Cyber security incidents will often have unexpected consequences; scenarios allow organisations to unearth them in a safe environment. You should develop playbooks to document how to respond to the most common attacks (such as a ransomware incident, or problems within your supply chain), or to those risks that concern you most. These exercises should not necessarily be performed to find fault with the organisation. Rather, their focus should be to help to train and equip the organisation to deal with a cyber attack.
The technology systems we use are increasingly complex and connected, making it difficult to understand how one part of a system might interact with and affect other parts. Using system models to inform cyber security exercises and scenario planning can be a useful way to not only visualise the system you are exercising, but to test your model and the assumptions you have made when building it. It is useful to remember that no model is perfect, and all models will have their limitations.
Types of scenario-based exercises
There are three main types of scenario-based exercises.
These are inexpensive, require the least amount of planning and can be run easily, including on a semi-impromptu basis. They are often used to develop awareness of a plan that has already been formulated, or for scenarios that are difficult to test in practice (such as a ransomware attack impacting every end point within an organisation).
These are table-based and involve a structured activity (including role play and games) as a focus for the scenario. These are usually held in an informal setting, with no hands-on practice or field work. They aim to generate discussion about the scenario to enhance awareness, develop, validate or stress-test plans. Games can be effective at highlighting decision making during an incident, and problems with the sequencing of post incident recovery actions (participants often highlight interdependencies between actions).
These are the most immersive, and involve the technology, people and processes being exercised. They can disrupt normal work, are expensive and demand detailed planning. They provide greater insight about how your organisation will react and reveal unforeseen results more effectively than tabletop exercises. They can vary in scale from a single department to a group of organisations.
Whichever type you use, remember that the aim is to manage risks, not to blame individuals or teams for perceived ineffective or negligent behaviour. Scenarios should be planned with this in mind, and framed in positive, collegial and learning-based terms.
Further information on creating cyber incident response exercises can be seen in our guidance.
Getting participants to engage with a scenario-based exercise
- You need to ensure you have 'buy in' from participants, this will ensure their response to the scenario closely matches their normal behaviour. After all, the aim of the exercise is to assess how people would respond to a real event. These scenarios should be updated and evolve to reflect changes to your organisation. This will keep them interesting and engaging. Consider the following:
- What will the exercise involve? Ensure your scenario is clear from the outset, and includes a realistic (if accelerated) timeline and environment. Many different scenarios could be exercised.
- Who should be involved? You must have the right people, and consider their roles, skills and experience.
- What level of detail should be included? Incorporate sufficient detail to enable the effects of decisions made to be revealed and to increase the realism of a scenario.
Observers and facilitators
Facilitators play an important role in creating a realistic scenario, but think carefully about the level of input you expect from them. Pointing out obvious errors early can avoid wasted time. Conversely, too much input can restrict the scenario and reduce learning opportunities. Observers or scribes (who play no part in the actual exercise but document the proceedings) are crucial, ensuring all outcomes are captured.
Short-term planning: further reading
Future scenario planning
The aim of future scenario planning is not to forecast, but to encourage learning so that decision makers can consider alternative future possibilities. It provides the means to map out different potential futures, and look at how they may affect an organisation's plans. Developing such scenarios expands your thinking. Whilst the future cannot be precisely predicted, you can develop a deeper insight to the drivers of change. Future scenario planning should be open to 'what if' type questions that allow people to challenge existing perceptions in a forgiving environment, allowing high-impact, once-in-a-generation events (also known as 'black swans') to be considered.
The most important outcome of future scenario planning is to challenge people's existing perceptions and encourage them to think differently about the future, so they can plan for cyber security risks and outcomes that might currently seem implausible or far-fetched.
These approaches may be useful to consider common business/technology challenges such as those encountered when migrating services to the cloud, when merging or demerging IT systems and business processes with partner organisations, or when having to continue to use potentially vulnerable legacy technology due to operational needs or lack of finance. They can also be useful to consider your response to unpalatable 'low frequency - high impact' events (such as having to compel staff to work at home in response to a pandemic), or significant problems within your supply chain (which may mean that critical parts or services vital to your operations may no longer be available).
Consider the following when developing these future scenarios:
- Scope: this should be clearly defined from the outset, as should key stakeholders and timescales.
- Differentiate between trends and uncertainties; participants should agree the criteria for a 'trend'. Otherwise, it will be an uncertainty.
- Plausible futures: consider multiple alternative futures within the confines agreed in steps 1 & 2 above, giving freedom to pursue any 'what if' questions. Scenarios should be consistent and plausible.
- Focus on the 'so what?' Each scenario may uncover a variety of outcomes; ensure your focus is on how your organisation could react. Look at both commonalities (as this can define a course of action) and divergencies. This will enable a focus on identifying key decision-making points.
- Communicate lessons learnt.
- Understand limitations of the approach you have used and the level of accuracy they provide (ensuring you do not overestimate the potential realism of the futures investigated).


