EXERCISE OBJECTIVES AND TRAINING AUDIENCE LAW ENFORCEMENT ENTITIES, LEGAL ADVISORS – After the incident is detected, the investigation process begins.   Is there a legal framework in place to respond to a cyber crisis? Are the legal conditions for declaring a state of emergency fulfilled? PRIVATE SECTOR - The SCADA management systems of different private electricity distribution companies were attacked.   What information would be exchanged with affected private companies? Is there an established list of points of contact? INTERNATIONAL/DIPLOMATIC ASPECT – An attack on the electricity grid can damage the electricity grids in neighboring countries if they experience a large-scale overload and/or instability.   Are there means for contacting the neighboring state authorities to mitigate possible impacts of the disruption on their electricity grid? Are there funds available to compensate for any possible cross-border damages? MEDIA – Due to time pressures, media will usually begin reporting without a deeper understanding of the situation. Moreover, getting sufficient information from the affected area is problematic due to the blackout itself.   How can the government effectively communicate its position and recommendations to the citizens if these are out of electricity power? What will be the communicated narrative? Depending on the objectives/specific objectives of the exercise, relevant entities on the horizontal line of Figure 3 must be represented in the exercise. Additionally, the vertical perspective has to be taken into account. During exercise planning, all necessary levels of the “chain of command” must be assessed, so as not to omit any level important to the passing and carrying out of orders. Starting with a clear identification of primary exercise objectives could help better understand what level (operational, tactical, strategic, all?) the exercise should focus on. Let us go back to our possible scenario. TECHNICAL/OPERATIONAL LEVEL – Since critical services and SCADA systems were compromised, the computer emergency response team (CERT) and technical/SCADA experts are included.      MANAGEMENT LEVEL – Management is responsible for assessing the crisis and eventually escalating the incident response.   PUBLIC – Disapproval with government response may move people to the streets. Public trust in government decreases dramatically.  What will be the communicated narrative towards the public? How quickly will they be able to assess the severity of the situation? How and through what channels will they report incidents to the higher echelons? Who will they ask for assistance? What information would they share with partners? Do they have the necessary tools/skills to analyze the malware?  How quickly will they it be able to make decisions regarding the report coming from the technical team/CERT? What countermeasures and recommendations would they take in order to mitigate the escalation of the situation? Are there pre-negotiated policies and SOPs in place? What would they report to the highest level of the chain of command? STRATEGIC/DECISION-MAKER LEVEL – A national crisis should management bodies. involve all crisis 11/29

Select target paragraph3