MAKE YOUR EXERCISE CATCHY CHAPTER 5 MAKE YOUR EXERCISE CATCHY Exercise execution costs a lot of time, financial, and human resources. To maximize exercise design efforts, some fundamental rules must be followed. If your exercise team’s ambitions are higher still, strive to reflect a few more recommended tips. However, keep in mind that each exercise is unique. How polished and well-rounded the exercise ultimately is always depends on the approach of all the people involved.  WHAT IS NECESSARY      Well balanced skills testing – Both technical skills and the strategic, communication and procedural aspects of cyber security must be continually trained. Reflecting a whole-of-nation response – Cooperation and interaction among public, government and private sector entities is fundamental for managing malicious cyber activities. All communication channels, cooperation agreements and prearranged conditions must be in place before the attacks hit. Involvement of decision-makers and executives – Strive to incorporate all levels of the “food chain” from the tactical to the operational, and strategic level. Doing so will result in more effective decision making during a complex crisis. Implementing latest trends – Since cyber exercises are used as an education tool, it is insufficient to exercise only past incidents that your institution has experienced. The latest trends and threats (the unrecognizable or unfamiliar concepts out of the traditional comfortzone) must be integrated as well. Emphasis on the evaluation process – Holding a follow-up session where major stakeholders and players can meet and discuss their results, decisions and feedback is essential. Without participant     observations, it is impossible to improve the exercise. Moreover, post-exercise analysis is key for identifying gaps, shortcomings and weak spots, and comparing if any progress has been made. Make the most out of the exercise and its benefits – Strive to push through the “not interesting” or uncomfortable exercise topics which might tend to otherwise be overlooked. Show, via hypothetical scenarios, what consequences may occur as a result of inadequately addressing an abbreviated or omitted item. Allow friction among different frameworks to discover how they can cooperate during a crisis – Different stakeholders operate in differing environments (private stakeholders tend to be profit-oriented, versus state sector focus on ensuring the continuity of services), with different tools and mandates/competences. Use the exercise to test if these frameworks are interoperable. Use scenarios which are as realistic as possible – Responders must feel as though the given incidents are really happening. Ideally, real incidents are selected and then set into a fictitious context familiar to the responders to some extent. Sharing best practices – Be candid and share outcomes and best practices from the exercises across the security community. The more institutions implement best practices into their reallife operation, the better cyber security is ensured, with a greater degree of commonality. Create a candid and non-threating atmosphere – Explain to all participants (and top management) that the exercise does not aim to show failures, to seek culprits or to be punitive. On the contrary, it is far more valuable to create a friendly and open atmosphere. Emphasize the opportunity that exercises offer – to 19/29

Select target paragraph3