Cyber Incident Exercising

Cyber incident exercising (CIE) allows organisations to test the effectiveness of their incident response plans in a safe environment and strengthen their incident management processes.
CIE provides a controlled, scenario-based opportunity for organisations to practise, evaluate and improve their cyber incident response plans (CIRPs). CIE doesn’t test your cyber defences but helps you to explore and evaluate your response plans, should a cyber incident occur. This can help your organisation understand what risks it is holding from a cyber perspective and how they can be managed.
If you need more information on incident management, please visit our Incident Management pages.
What is the Cyber Incident Exercising scheme?
The CIE Scheme gives consumers confidence in companies which have been assessed as meeting the NCSC’s rigorous standard for high quality cyber incident exercising.
How does the scheme work?
CIE Assured Service Providers have been assured by the NCSC to develop and deliver controlled, scenario-based, tailored exercising that conforms to the NCSC CIE Technical Standard. These exercises are delivered for organisations that want to practise, evaluate, and improve their cyber incident response plans in a safe environment.
Who is it for?
The CIE Scheme is aimed at organisations with existing cyber incident response plans.
CIE Assured Service Providers are able to support a wide range of UK businesses, charities, public sector, and government organisations to rehearse, evaluate and improve their cyber incident response plans.
The scheme’s remit covers organisationally significant incidents that have the potential for significant operational, financial, or regulatory impacts on the victim. The scheme covers Category 3, 4 and 5 incidents on the UK’s Cyber Attack categorisation system.