Cyber Incident Exercising

Information for Cyber Incident Exercising buyers
About the scheme
The CIE Scheme assures Service Providers which deliver controlled, scenario-based, tailored exercises simulating organisationally significant cyber incidents, allowing you to rehearse, evaluate and improve your cyber incident response plans.
All CIE Assured Service Providers have been assured by the NCSC and are considered capable of providing high quality cyber incident exercising services to a defined standard.
CIE Assured Service Providers which are assured under the CIE Scheme provide:
- Table-top exercises – discussion-based sessions where representatives from relevant teams meet to discuss their roles and responsibilities, expected activities and key decision points (in accordance with an incident response plan), facilitated by the CIE Assured Service Provider and driven by a cyber incident scenario.
- Live-play exercises – where team members execute their roles and responsibilities from their normal work environment, in response to controlled injects which represent a given cyber incident scenario. Different participants typically receive different sets of injects. Activities and decisions happen in close to real-time, although the incident pace and timeline is managed by an exercise control function.
How to select a CIE Assured Service Provider
You should contact a CIE Assured Service Provider directly. Before doing so, you may want to research the types of exercises they have conducted, the sectors they have worked in and the types of clients they have worked for, to ensure they are appropriate for your needs.
Any contract you may engage in will be between yourself and the CIE Assured Service Provider – the NCSC is not a party to these contracts. To ensure that the work is carried out under the Terms and Conditions of the NCSC Assured CIE Scheme, it may be prudent to stipulate this in your contract with the CIE Assured Service Provider.
If you do not have a cyber incident response plan (CIRP) or are not yet ready to engage a CIE Assured Service Provider, the NCSC has created guidance for organisations creating their own CIRPs – see the Incident Management pages.
Alternatively, if you want to create your own cyber incident exercise or understand the basic principles of doing so, see Effective steps to cyber exercise creation. These steps have been written for IT staff, cyber risk management, and business continuity teams in small to medium sized organisations.
If you're new to cyber exercising, or looking for off-the-shelf, generic exercises, please refer to the NCSC’s free Exercise in a Box online tool, which contains different scenarios and materials for setting up, planning, delivery, and post-exercise activity.
Considerations for Government buyers
Government and public sector buyers can use the Crown Commercial Service’s Dynamic Purchasing System to invite suppliers to bid for work. Full guidance is available on the Crown Commercial Services website.