Helsinki · Finland

Preparedness
is not a plan,
it is a practice.

Speaking & briefingsPreparedness exercisesWargames

Bearings delivers an outside reading of the environment, in a keynote, a board briefing, a teaching module, or a standing engagement across the year. Practice rehearses decisions under pressure, in three stages: Expose, Build, Test. Critical Entities Resilience sets those same stages against the regulated pathway for designated operators. All three end the same way, with what to do next, named and specific.

Founded by Maxime Lebrun, drawing on a decade in countering hybrid threats. Formerly French Seconded National Expert at the European Centre of Excellence for Countering Hybrid Threats in Helsinki, latterly as Deputy Director for Research and Analysis, and before that at the Baltic Defence College, including as Acting Director of the Department of Political and Strategic Studies. He designed and delivered exercises for ministers, intelligence chiefs and critical-infrastructure executives across more than thirty EU and NATO member states.

Governance & accountability
Accountability now sits with the board
CER, NIS2 and DORA place personal accountability for preparedness on management bodies. A tested exercise is both the preparation and the documented evidence.
Infrastructure & continuity
Critical functions are targeted, not just lost
Sabotage, service disruption and supply-chain interference are baseline conditions for energy, transport, communications and water operators, not exceptional events.
Operating environment
Geopolitical pressure reaches private firms
State-influenced pressure campaigns, coercion and strategic interference target defence-adjacent companies, sensitive-technology providers and critical-service operators.
Information & trust
The information layer is where crises are lost
Disinformation, data exposure and orchestrated reputational attacks can be as disruptive as any physical incident. Teams that have not rehearsed this discover it under pressure.
Follow on LinkedIn

Stave Advisory is a Member of the French-Finnish Chamber of Commerce

Three ways in

From a keynote to a wargame.

Stave works on one problem through three doors. Bearings brings an outside reading of the environment to the people who have to act on it. Practice rehearses decisions before they are required, in three stages that expose what an organisation assumes, build what it lacks, and test both under compounding pressure. Critical Entities Resilience takes those same stages and sets them against the sequence the Directive requires, for operators working to a designation and a statutory clock. The first sharpens judgement, the second builds capability, and the third proves it to a regulator. All three end the same way, with what to do next, named and specific.

Bearings
An outside reading of the environment.
Delivered to the people who act on it.

Bearings supplies the reading an organisation cannot easily produce for itself: how hostile actors select their moments, where the authority to respond actually sits when the plan meets the clock, what regulation now requires of the people it names, which dependencies are held on loan, and how an institution can lose standing while its systems remain perfectly intact. Five clusters carry the material, and every engagement is built for the room it is delivered in.

Explore Bearings
Practice
Rehearsing decisions before they are required.
Three stages. One spine.

Continuity plans are written for accidents, which arrive singly and without intention. Practice is built for an adversary choosing the moment, which is a different problem and takes a different kind of work. That work runs in three stages sharing one capability framework and one readiness scale: Expose, Build, Test. Each stage stands on its own, and each ends with three specific changes, each carrying a named owner and a date.

Explore Practice
Critical Entities Resilience
Compliance that actually makes you ready.
The regulated pathway.

CER, NIS2 and DORA now ask operators to prove resilience rather than assert it, and they name the individuals answerable for it. The same three stages become the statutory sequence: designation readiness and gap assessment, then risk assessment and the resilience plan, then exercise and validation. The artefact that satisfies the regulator is the one that makes leaders decide well when it matters.

Explore CER
Bearings

Five clusters. Every engagement built for the room.

Bearings supplies the reading an organisation cannot easily produce for itself. Five clusters carry the material. Every engagement is sized to the audience, the occasion and what the organisation is currently deciding.

Keynote30 to 45 minutes, public conference or company event, followed by questions.
In ConversationPanel chair, moderation, or a recorded conversation for internal channels.
Executive Briefing60 to 90 minutes, closed room, board or executive committee, no slides required.
Standing BriefRecurring situational reading, quarterly or on trigger, 45 minutes, remote or in person.
Teaching ModuleHalf day, internal skills development, structured material, exercise optional.
Full Bearings page
01
How the Moments Are Chosen
The reading an adversary makes of an organisation from the outside
Read more
Public and private entities are not impacted or targeted randomly. The current geostrategic environment shows that adversaries select the target and the hour with care. A hostile actor reads an organisation from material it publishes willingly: procurement notices, maintenance windows, financial calendars, leadership announcements. What that reading reveals is not a vulnerability in any technical sense but a window, a period in which the institution will be slower to convene, slower to authorise and slower to speak. The instruments then arrive in combination rather than in sequence, mixing physical interference, network intrusion, regulatory and legal pressure, economic leverage and information manipulation, which is why a single operation is experienced by an energy company, a municipality, a hospital and a newsroom as four unrelated local problems. This cluster covers how that selection works, why the pattern is so difficult to see from inside any one organisation, and what can be decided responsibly in the months before attribution arrives.
02
Authority Under Pressure
Where the right to act sits when the situation evolves and the clock is running
Read more
Organisations facing crises rarely fail for lack of information. They routinely fail because the people who held the information were not authorised to act on it. The authority exists somewhere in the plan, but in the first hour it turns out to be held by a person who cannot be reached, or split between two functions that each expect the other to move, or conditional on a committee whose quorum assumes ordinary working days. This cluster examines that gap, in the executive committee and in the organisational arrangement alike. For private operators it ends where it matters commercially, on what a company inherits when a state decides to act, and on how little of that inheritance is ever negotiated beforehand.
03
Where Risk Management Stops
Risk frameworks built for probability, but facing an actor choosing the moment
Read more
Risk registers assume probability and adversaries assume intent, and the two do not combine, which is why an organisation can hold a mature risk register and remain unprepared for the one situation in which the environment is choosing rather than rolling dice. Regulation has begun to close that gap by naming individuals rather than functions, and the management body is now personally answerable for a readiness it has usually certified without ever having seen it demonstrated. This cluster works through the substance of the CER Directive, NIS2 and DORA rather than their summaries, including the parts most often misstated. It sets out the distinction the regulations imply but seldom define, between a capability that is unaddressed, one that is documented, one that was tested some years ago under assumptions that have since changed, and one that is genuinely embedded in how the organisation behaves. It closes on preparedness as a financial object: an unpriced line in valuation, an emerging item in due diligence, and a growing source of exposure for boards.
04
Borrowed Continuity
What the organisation depends on and does not control
Read more
Nothing an institution depends on is entirely its own, since power arrives across an interconnector owned by another organisation, payments clear through an intermediary chosen for cost, and a critical process runs on a platform maintained by a supplier with a small number of employees. Continuity plans are written on the assumption that failures are accidental and arrive in isolation to each other, which is a reasonable assumption about accidents but a poor one about a failure that has been selected. This cluster works through the mechanics of cascade, showing how one interruption propagates across operators who each hold accurate information about their own position and almost none about the position of the others, and why second and third order effects arrive faster than the coordination meant to manage them. It treats interconnection as an arrangement that distributes resilience in normal conditions and distributes shock in abnormal ones. It then widens to comprehensive security itself, which is a division of labour in which the state relies on operators it does not own and operators rely on authorities they do not command, and is candid about the conditions that arrangement assumes and relies on.
05
Narrative Contests
Systems intact, but standing lost
Read more
An institution can lose while every system it operates remains perfectly intact, because the disruption is real, the cause is misstated, and the misstatement is faster, simpler and more satisfying than the truth. That interval belongs to whoever moves first, and it is widened by a speed gap the organisation cannot easily close: an operator needs hours to confirm a technical fact, a regulator needs days to authorise a position, and a newsroom is working to a deadline measured in minutes. This cluster addresses the particular difficulty of correcting a false causal claim without amplifying it, why the first statement is the one quoted for the following fortnight regardless of what follows it, and why organisations with several sites and several spokespeople reliably contradict themselves on a tight clock. It treats institutional credibility as an asset that appears on no balance sheet and has no owner in the organisational chart, which is why it is defended late and by whoever happens to be available. For media and public bodies it extends to editorial and source pressure applied deliberately, where the target is not the system but the standing of the institution that operates it.

Continuity plans assume an accident. Stave assumes an adversary choosing the moment.

Practice

Three stages: Expose, Build, Test.

Three stages sharing one capability framework and one readiness scale, carrying three services: a scoping workshop, a full day of preparedness training, and an adjudicated wargame. Each stage stands on its own, and each ends the same way, with three specific changes, each carrying a named owner and a date.

Expose

A scoping workshop that surfaces what the organisation has been assuming without noticing. Produces an assumption inventory, a seventy-two hour scenario and a readiness ladder. The least demanding way to find out where the organisation stands for real.

Build

A full day of structured training that closes with an embedded tabletop and a certified record meeting management-body obligations under NIS2, CER and DORA. Develops the judgement, rehearsed, so the right call is available when there is no time to reason it out.

Test

Senior people under compounding pressure, deciding on incomplete and contradictory information while a decision log runs, and consequences arrive rather than scores. Preparedness is proven, not asserted.

The three services and the scenario library
Critical Entities Resilience

The same spine, in statutory clothing.

For designated critical and important entities, the three stages become the four phases the Directive requires. Nothing new is added: the practice that makes an organisation ready is the practice that makes it compliant. CER remains the reference throughout, with NIS2 and DORA served by the same stages where they apply.

01 Expose
Designation Readiness & Gap Assessment
Establish where designation obligations are met and where they are not, and where judgement would break under pressure. The gap is located before the regulator, or an adversary, finds it first.
02 Build
Risk Assessment
The risk analysis the Directive requires, developed as decisions that have to hold rather than a document to be filed. The relevant threats, the dependencies, and the remaining exposure, named plainly.
03 Build
Resilience Plan
The plan itself, including the implementation schedule that generic templates routinely omit. It typically falls due within a fixed window after the risk assessment is completed, often around twelve months.
04 Test
Exercise & Validation
The wargame. Recommended in some jurisdictions and statutory in others, where designated entities must exercise at least every two years. Preparedness proven under live adversarial conditions, and documented as evidence.
The full CER pathway, with timing and sequencing
Why Stave

The case for a different approach.

01
Scenarios built from real threat intelligence, not adapted templates
Stave builds each scenario from actual threat vectors, specific regulatory obligations, and the institutional pressures that apply to the client's operating environment. This is the difference between a plausible exercise and one that reveals gaps.
scenario specificity over template efficiency
02
Cross-domain experience, not single-lane expertise
Cyber advisory, crisis communications, geopolitical analysis, and continuity planning each provide depth within their lane. Real crises do not respect those boundaries. A decade working at the intersection of EU and NATO policy, national security institutions, private-sector exposure, and exercise design produces an advisor who can see the whole board.
cross-domain by design, not by assembly
03
Institutional knowledge of the authorities an organisation answers to in a crisis
Knowing what regulatory authorities expect when an incident is reported, how ministries react in crisis, what a senior official looks for in the first three hours. This knowledge comes from having been on both sides of those interactions, at the most senior levels, over years. It is built into every scenario and debrief.
institutional knowledge as methodology
04
Accessible at the scale where the gap is most acute
Significant operational and reputational exposure is not confined to large organisations. Smaller regulated entities, defence supply-chain manufacturers, and companies in sensitive-technology sectors often carry substantial risk while meeting different thresholds and timelines. The question of readiness does not scale with headcount.
senior-level methodology at mid-market access
About
Maxime Lebrun — Stave Advisory

The gap is closeable.
But only before.

Helsinki
Finland

Most people who speak about this subject describe what an adversary might do. Comparatively few can describe what institutions actually do in response, because that requires having watched them do it. Maxime Lebrun spent six years at the European Centre of Excellence for Countering Hybrid Threats in Helsinki, latterly as Deputy Director for Research and Analysis, where he led EU-HYBNET across some 130 public and private entities and worked daily with the ministries, operators and armed forces that carry the response. Before that he taught and directed political and strategic studies at the Baltic Defence College, in a region that has never treated any of this as theoretical. Since founding Stave Advisory he has put senior teams under compounding pressure in a room with the clock running, and taken the notes.

What that produces is not access to information. It is judgement about how institutions behave when the situation is unclear, the authority is contested and the first statement has already been written by somebody else.

Maxime Lebrun served from 2020 to 2026 as a seconded national expert at the European Centre of Excellence for Countering Hybrid Threats in Helsinki, deployed by the French Ministry of the Armed Forces. He filled successive roles as Senior Analyst for Research & Analysis and for Training & Exercise, as well as Deputy Director for Research and Analysis. He designed and delivered scenarios and briefings for heads of state and government, ministers, senior intelligence officials, and critical infrastructure executives across more than thirty EU and NATO member states.

He led major EU and NATO-funded projects that produced exercise frameworks, policy tools, and operational recommendations for European institutions and member states. He delivered exercises at the EU Council level, for the NATO Parliamentary Assembly, and in bilateral settings with national authorities across European capitals.

He has spoken at international security conferences including the Paris Defence and Strategy Forum, the Heinrich Böll Berlin Foreign Policy Conference in 2025, and the European Dialogues in Helsinki in 2024. A regular contributor to European media on security and strategic affairs, with interviews and commentary in Le Monde, RFI, La Libre Belgique, and Yle. He speaks in English and French, and has nothing to sell in the room beyond the argument he came to make.

Before the Hybrid CoE, he served at the Baltic Defence College as Lecturer in War and Conflict Studies and Acting Director of the Department of Political and Strategic Studies, teaching and mentoring officers on Joint Command, Higher Command, and Senior Leaders courses across EU and NATO member states.

A decade engaging with senior leaders, knowing how they think and what drives them.
Get in touch

Contact

Every engagement starts with a conversation.

If your organisation faces questions about crisis readiness, leadership preparedness, or the compliance obligations that now apply to your management body, please get in touch.

LocationHelsinki, Finland