Cybersecurity 7 min

How to Pressure-Test Cyber Readiness Before a Real Attack

A cyber exercise should reveal how an organization will actually perform under pressure, not simply confirm that a response plan exists. Learn how to test executive judgment, cross-functional coordination and real-world operational dependencies with insights from members of the Senior Executive Cybersecurity Think Tank.

by Cybersecurity Editorial Team on October 6, 2026

Cyber exercises give an organization a chance to uncover weaknesses before a real attack puts its response to the test. Yet what teams rehearse often differs from what they face. A 2025 survey of 480 senior U.S. cybersecurity leaders found that 57% of significant cyber incidents involved attacks the security team hadn’t prepared for. 

Since no organization can rehearse every scenario, the value of an exercise lies less in the script than in whether it builds the judgment and coordination a response will need when events don’t go according to plan. A scenario that simply walks the security team through familiar technical steps reveals little about how the business would function when a critical vendor goes dark, core systems are unavailable, or executives must make high-stakes calls about operations, disclosure and customer communication with incomplete information. CISA has advised that incident response plans include senior business leadership and board members and that senior management participate in tabletop exercises, reflecting the view that cyber readiness must extend well beyond the security team.

Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategy, risk management, incident response and cybersecurity leadership. Below, they explore what separates a useful cyber exercise from a compliance-driven tabletop and how leaders can design exercises that test executive judgment, operational dependencies and cross-organizational coordination.

“A useful exercise tests whether leaders can make sound business decisions based on how their organization would actually respond.”

David Etue, Chief Strategy Officer at Cyberbit, member of the Cybersecurity Think Tank, sharing expertise on cybersecurity on the Senior Executive Media site.

– David Etue, CEO of Cyberbit

SHARE IT

Test Decisions, Not Just Plans

David Etue, CEO of Cyberbit, has spent more than 20 years working across security program leadership, management consulting, product management and technical implementation. For him, the distinction between checking preparedness on paper and testing it in practice is fundamental.

“A compliance tabletop tests whether a plan exists. A useful exercise tests whether leaders can make sound business decisions based on how their organization would actually respond,” he says.

For Etue, that requires grounding the exercise in the organization’s real-world capabilities and limitations.

“Too many tabletops rely on generic scenarios disconnected from real capabilities and technical realities,” he says. “Instead, ground injects in actual detection and response speed, escalation choices, and technical constraints. Slow detection of lateral movement means greater spread; rapid isolation may contain an attack but disrupt critical operations.”

Those conditions create the foundation for better decisions that reach well beyond the security function.

“Realism lets leaders practice the real decisions: isolating services, notifying customers, engaging counsel and briefing the board,” Etue says. “It connects executive judgment, operational dependencies and cross-functional coordination to facts, not fiction.”

Evaluate How Teams Work Under Pressure

Bhavya Bhandari, Cybersecurity Risk Management Leader, Financial Services at Ernst & Young US LLP, has more than 15 years of experience leading security, regulatory and risk transformation programs for global financial services organizations. He views a cyber exercise as an opportunity to see how leaders respond when the answers aren’t clear-cut.

“A beneficial cyber exercise forces leaders to navigate uncertainty, competing priorities, regulatory obligations, customer impact and business disruption,” Bhandari says.

He argues that preparedness becomes clearer when an exercise moves beyond prescribed procedures.

“A useful cyber exercise reveals how the organization actually makes decisions under pressure,” Bhandari says. “It helps leaders assess preparedness through the lens of whether executives can make timely decisions with incomplete information and whether technology, operations, legal, communications and business teams can work together when the situation is evolving.”

For Bhandari, what the exercise exposes can be as valuable as what participants handle successfully.

“The real benefits come from exposing coordination and decision-making challenges before a crisis does.”

“Inject operational dependencies that don’t show up in the incident response plan: a vendor going dark, a comms channel being compromised, or the legal and PR teams pulling in different directions.”

Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, member of the Cybersecurity Think Tank, sharing expertise on cybersecurity on the Senior Executive Media site.

– Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA

SHARE IT

Make the Exercise Uncomfortable

Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, brings experience spanning national intelligence, cybersecurity consulting and corporate security leadership. He draws a sharp line between exercises that confirm people know the process and those that challenge the organization to operate under realistic crisis conditions.

“A compliance tabletop tests whether people can recite a runbook. A useful exercise tests whether the organization can actually make decisions under pressure, with incomplete information, real-time constraints, and consequences that ripple beyond IT,” Ritesh says.

He breaks that distinction into three areas.

“First, put executives in the room making real calls—‘Do we notify regulators now or wait for more facts? Do we pay? Do we go public?’—not just watching a technical briefing,” Ritesh says. “Second, inject operational dependencies that don’t show up in the incident response plan: a vendor going dark, a comms channel being compromised, or the legal and PR teams pulling in different directions. Third, force cross-functional coordination under time pressure, not sequential handoffs.”

His standard for whether an exercise went far enough is straightforward.

“If nobody’s uncomfortable by the end, the exercise wasn’t hard enough.”

Build for Real-World Coordination

Ken Grohe, President of LeverageGTM, Inc., has more than 35 years of experience across SaaS, IT and security, including leadership roles at global enterprises and startups. He says that mission-critical capabilities need to include several factors.

“First is AI simulation,” Grohe says. “That’s the ability to build custom, real-world cyber crisis scenarios from scratch based on specific threat profiles, industry regulations and compliance needs.”

He also points to the need for teams to repeatedly practice how they’ll work together during an incident.

“Interactive, iterative playbooks allow teams to rehearse ‘war-room’ cross-functional mobile response coordination, escalation paths and operational roles inside a unified platform, with transparency,” Grohe says.

Finally, he cites reliable communication as another essential feature of crisis-ready infrastructure, particularly when normal systems or channels may not be available.

“Teams need mobile linkage: secure, out-of-band manual communication channels for remote or distributed teams to coordinate during repetitive simulated and/or real crisis resolution.”

Pressure-Test Your Cyber Readiness

  • Ground exercises in the organization’s real capabilities and constraints. Build scenarios around actual detection speeds, escalation paths, technical limitations and operational tradeoffs so leaders practice responding to conditions they could realistically face.
  • Use exercises to test business judgment, not just incident procedures. Give executives opportunities to weigh competing priorities such as containment, operational continuity, customer communication, legal exposure and board reporting.
  • Introduce uncertainty and incomplete information. Leaders should have to make timely calls without perfect visibility, just as they would during an evolving cyber incident.
  • Evaluate how well functions work together under pressure. Use exercises to identify coordination gaps among security, technology, operations, legal, communications and business teams before those gaps affect a real response.
  • Test dependencies that may not appear in the incident response plan. Introduce disruptions involving vendors, communications channels, business operations or competing internal priorities to expose hidden points of failure.
  • Build scenarios around the organization’s specific risk environment. Tailor exercises to relevant threats, regulatory requirements and business conditions instead of relying on generic scenarios.
  • Practice how teams will coordinate when normal communications fail. Rehearse escalation paths, operational roles and secure out-of-band communications so distributed teams can continue working together during a crisis.

Prepare for the Crisis You Can’t Predict

A useful cyber exercise does more than confirm that an incident response plan exists or that teams understand their assigned roles. It tests whether leaders can make sound calls under pressure, whether functions can coordinate when circumstances change, and whether the organization’s processes, dependencies and communications hold up when normal operations are disrupted.

Organizations can’t anticipate every attack they may face, which makes adaptability a critical measure of readiness. Exercises that introduce realistic constraints, uncertainty and cross-functional pressure can help leaders find weaknesses while there’s still time to address them—and build the judgment and coordination they’ll need when a real incident doesn’t follow the script.

Category: Cybersecurity

Copied to clipboard.