MAKE YOUR EXERCISE CATCHY
CHAPTER 5
MAKE YOUR EXERCISE CATCHY
Exercise execution costs a lot of time, financial,
and human resources. To maximize exercise
design efforts, some fundamental rules must
be followed. If your exercise team’s ambitions
are higher still, strive to reflect a few more
recommended tips. However, keep in mind
that each exercise is unique. How polished and
well-rounded the exercise ultimately is always
depends on the approach of all the people
involved.
WHAT IS NECESSARY
Well balanced skills testing – Both
technical skills and the strategic,
communication and procedural aspects of
cyber security must be continually trained.
Reflecting a whole-of-nation response –
Cooperation and interaction among
public, government and private sector
entities is fundamental for managing
malicious
cyber
activities.
All
communication channels, cooperation
agreements and prearranged conditions
must be in place before the attacks hit.
Involvement of decision-makers and
executives – Strive to incorporate all levels
of the “food chain” from the tactical to the
operational, and strategic level. Doing so
will result in more effective decision
making during a complex crisis.
Implementing latest trends – Since cyber
exercises are used as an education tool, it
is insufficient to exercise only past
incidents that your institution has
experienced. The latest trends and threats
(the unrecognizable or unfamiliar concepts out of the traditional comfortzone) must be integrated as well.
Emphasis on the evaluation process –
Holding a follow-up session where major
stakeholders and players can meet and
discuss their results, decisions and
feedback is essential. Without participant
observations, it is impossible to improve
the exercise. Moreover, post-exercise
analysis is key for identifying gaps,
shortcomings and weak spots, and
comparing if any progress has been made.
Make the most out of the exercise and its
benefits – Strive to push through the “not
interesting” or uncomfortable exercise
topics which might tend to otherwise be
overlooked. Show, via hypothetical
scenarios, what consequences may occur
as a result of inadequately addressing an
abbreviated or omitted item.
Allow friction among different frameworks
to discover how they can cooperate during
a crisis – Different stakeholders operate in
differing
environments
(private
stakeholders tend to be profit-oriented,
versus state sector focus on ensuring the
continuity of services), with different tools
and mandates/competences. Use the
exercise to test if these frameworks are
interoperable.
Use scenarios which are as realistic as
possible – Responders must feel as though
the given incidents are really happening.
Ideally, real incidents are selected and
then set into a fictitious context familiar to
the responders to some extent.
Sharing best practices – Be candid and
share outcomes and best practices from
the exercises across the security
community. The more institutions
implement best practices into their reallife operation, the better cyber security is
ensured, with a greater degree of
commonality.
Create a candid and non-threating
atmosphere – Explain to all participants
(and top management) that the exercise
does not aim to show failures, to seek
culprits or to be punitive. On the contrary,
it is far more valuable to create a friendly
and open atmosphere. Emphasize the
opportunity that exercises offer – to
19/29