Cyber Exercising: What Boards Need to Know

When the British Library was struck by a ransomware attack in October 2023, its crisis management plan was invoked within two hours. A Gold/Silver command structure was stood up, regulators were notified, and communications were coordinated through social media channels after the intranet went dark. In its candid post-incident review, published in March 2024, the Library acknowledged that while its security measures had been extensive and externally accredited, there was much it wished it had understood better or prioritised differently. Among sixteen lessons drawn out for the benefit of other organisations, one stands out for its breadth of relevance: the importance of regularly rehearsing comprehensive business continuity plans and ensuring that senior leaders understand what a cyber incident actually demands of them.

Most UK organisations have not absorbed that lesson. The government’s Cyber Security Breaches Survey 2025 found that only 22% of businesses have a formal incident response plan, even as 74% of large businesses reported experiencing a breach or attack in the preceding twelve months. The implication is stark: the majority of organisations that will face a serious cyber incident have no documented plan for how to respond to one, let alone a plan that has been tested.

A governance expectation, not just a technical one

The UK government’s Cyber Governance Code of Practice, published in April 2025, sets out five principles for board-level oversight of cyber risk. Under the principle covering incident planning, response and recovery, the Code is explicit: boards should gain assurance that the organisation’s cyber incident response plan is exercised at least annually, involving relevant internal and external stakeholders, and that lessons from each exercise are reflected in future plans and risk assessments. The Code is currently voluntary, but it has been designed to complement existing regulatory obligations under UK GDPR and the NIS Regulations, and legal commentators have noted that it may follow the trajectory of other governance codes towards a “comply or explain” reporting standard.

The regulatory direction reinforces this. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025, proposes expanded incident reporting requirements, including a 24-hour initial notification window, alongside significantly increased enforcement powers and penalties of up to £17 million or 4% of global turnover. In October 2025, the government wrote directly to the UK’s largest 250 businesses urging them to make cyber risk a board-level priority. Incident exercising is becoming a core governance expectation, and boards need to understand what distinguishes a meaningful exercise from a performative one.

What makes a good exercise

The exercises that produce genuine organisational value tend to share a few characteristics, though they manifest differently depending on the organisation’s size, sector and maturity. The scenario must be realistic and grounded in current threat intelligence. An exercise simulating a ransomware attack on a retail organisation in 2025 should bear some resemblance to the social engineering and identity compromise techniques that were reportedly used in the attacks on Marks & Spencer, Co-op and Harrods earlier that year. Scenarios informed by recognised frameworks such as MITRE ATT&CK carry more weight than generic templates, because they force participants to engage with the kinds of decisions they would actually face.

Equally important is who is in the room. Cyber incidents are not contained within IT departments. They generate legal obligations around regulatory notification, they require decisions about communications with customers, partners and the media, and they demand senior leadership input on matters such as business continuity, insurance claims and reputational management. An exercise that only tests the technical response team is testing a fraction of the organisation’s actual capability. The most valuable exercises bring together participants from across the business: board members or their representatives, legal counsel, communications leads and operational managers.

What comes after the exercise matters as much as the exercise itself. The purpose is not to pass or fail but to surface gaps, assumptions and dependencies that would otherwise remain hidden until a real incident exposes them. Who authorises external communications when the CEO is unavailable? How would the organisation operate if core communication systems were compromised? Does the incident response plan account for regulatory notification timelines that have recently changed? A well-facilitated exercise will generate findings like these. Those findings need to be documented, prioritised and fed back into the plan in a structured way, or the exercise has achieved very little.

What makes a bad exercise

Poor exercises tend to be designed to confirm existing assumptions rather than challenge them. An exercise built around an implausible scenario, conducted with only a handful of IT staff in a room, following a script that leads participants towards a predetermined outcome, will generate little of value. Worse, it may leave the board believing the organisation is prepared when it is not.

The other common failure is treating exercising as a one-off compliance activity. An organisation that exercises once, files the report, and does not revisit its incident response plan until the following year’s exercise has missed the point of continuous improvement. Exercises that exclude senior leadership, use off-the-shelf scenarios with no relevance to the organisation’s threat profile, or produce findings that are never reviewed at board level fall into the same category. They satisfy a perceived requirement without delivering any of the preparedness that requirement is designed to achieve.

The value of NCSC assured exercising

The NCSC’s Cyber Incident Exercising scheme was established to give organisations confidence that the providers they engage meet a defined technical standard. Assured Service Providers under the scheme are assessed against the NCSC CIE Technical Standard and must demonstrate competence in threat intelligence-led scenario development, an understanding of incident management best practice and wider business continuity considerations, and the ability to deliver both tabletop and live-play exercises tailored to the client organisation. The scheme is administered by CREST and IASME as delivery partners, and assured providers are reassessed annually.

For boards, this provides a practical means of due diligence. Engaging an NCSC Assured Service Provider means that the exercise will be designed and delivered to a standard independently validated against national benchmarks. For organisations subject to regulatory scrutiny, or those seeking to demonstrate alignment with the Cyber Governance Code of Practice, the use of an assured provider offers evidential confidence that exercising has been conducted to an appropriate standard.

How Evolve North can help

Evolve North is an NCSC Assured Service Provider for Cyber Incident Exercising. We work with organisations across sectors to design and deliver exercises that genuinely test incident response capability, from structured tabletop exercises through to our “Fire Drill Model”, which combines a pre-agreed scenario with an unannounced trigger to test how effectively the organisation can mobilise its response team and activate its plans under realistic conditions. If your organisation needs to build, test or strengthen its approach to cyber incident preparedness, we would welcome a conversation. Contact us at info@evolvenorth.com or call 01748 905 002.

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.