EXERCISE OBJECTIVES AND TRAINING AUDIENCE
LAW ENFORCEMENT ENTITIES, LEGAL
ADVISORS – After the incident is detected, the
investigation process begins.
Is there a legal framework in place to
respond to a cyber crisis?
Are the legal conditions for declaring a
state of emergency fulfilled?
PRIVATE SECTOR - The SCADA management
systems of different private electricity
distribution companies were attacked.
What information would be exchanged
with affected private companies?
Is there an established list of points of
contact?
INTERNATIONAL/DIPLOMATIC ASPECT –
An attack on the electricity grid can damage the
electricity grids in neighboring countries if they
experience a large-scale overload and/or
instability.
Are there means for contacting the
neighboring state authorities to mitigate
possible impacts of the disruption on their
electricity grid?
Are there funds available to compensate
for any possible cross-border damages?
MEDIA – Due to time pressures, media will
usually begin reporting without a deeper
understanding of the situation. Moreover,
getting sufficient information from the
affected area is problematic due to the
blackout itself.
How can the government effectively
communicate
its
position
and
recommendations to the citizens if these
are out of electricity power?
What will be the communicated narrative?
Depending
on
the
objectives/specific
objectives of the exercise, relevant entities on
the horizontal line of Figure 3 must be
represented in the exercise.
Additionally, the vertical perspective has to be
taken into account. During exercise planning,
all necessary levels of the “chain of command”
must be assessed, so as not to omit any level
important to the passing and carrying out of
orders. Starting with a clear identification of
primary exercise objectives could help better
understand what level (operational, tactical,
strategic, all?) the exercise should focus on. Let
us go back to our possible scenario.
TECHNICAL/OPERATIONAL LEVEL – Since
critical services and SCADA systems were
compromised, the computer emergency
response team (CERT) and technical/SCADA
experts are included.
MANAGEMENT LEVEL – Management is
responsible for assessing the crisis and
eventually escalating the incident response.
PUBLIC – Disapproval with government
response may move people to the streets.
Public trust in government decreases
dramatically.
What will be the communicated narrative
towards the public?
How quickly will they be able to assess the
severity of the situation?
How and through what channels will they
report incidents to the higher echelons?
Who will they ask for assistance?
What information would they share with
partners?
Do they have the necessary tools/skills to
analyze the malware?
How quickly will they it be able to make
decisions regarding the report coming
from the technical team/CERT?
What
countermeasures
and
recommendations would they take in
order to mitigate the escalation of the
situation? Are there pre-negotiated
policies and SOPs in place?
What would they report to the highest
level of the chain of command?
STRATEGIC/DECISION-MAKER LEVEL – A
national crisis should
management bodies.
involve
all
crisis
11/29