The work of rehearsing decisions before they are required.
Preparedness is not a plan, it is a practice. Continuity plans are written for accidents, which arrive singly and without intention. Practice is built for an adversary choosing the moment, which is a different problem and takes a different kind of work.
That work runs in three stages sharing one capability framework and one readiness scale: Expose, Build, Test. Each stage stands on its own and can be commissioned on its own. Each ends the same way, with three specific changes, each carrying a named owner and a date.
The stages are sequential where an organisation wants the full path and independent where it does not. Most begin at Expose, because it is the least demanding way to establish where an organisation stands before committing to anything larger.
A scoping workshop that surfaces what the organisation has been assuming without noticing. Produces an assumption inventory, a seventy-two hour scenario and a readiness ladder. The least demanding way to find out where the organisation stands for real.
A full day of structured training that closes with an embedded tabletop and a certified record meeting management-body obligations under NIS2, CER and DORA. Develops the judgement, rehearsed, so the right call is available when there is no time to reason it out.
Senior people under compounding pressure, deciding on incomplete and contradictory information while a decision log runs, and consequences arrive rather than scores. Preparedness is proven, not asserted.
A single framework runs across the three stages, which is what allows an assessment made at Expose to be tested at Test rather than replaced. Four capabilities are examined, each placed on the same four-point readiness scale, so movement over time is visible rather than asserted.
Continuity plans assume an accident. Stave assumes an adversary choosing the moment.
Designated critical and important entities have a regulated pathway and a statutory clock, and Practice serves it directly. A large part of the exposure, however, sits outside the regulated perimeter altogether: defence-adjacent suppliers, sensitive-technology firms, media organisations, hospitals and municipalities, and the mid-sized operators on whom designated entities quietly depend.
For those organisations the risk is not that a critical function fails by chance but that it is taken out on purpose, at the worst possible moment, while the facts are disputed and the correction is slower than the claim. The work is the same work. Only the reason for commissioning it differs.
Every engagement draws on a library of original scenarios, based on a wargaming repertoire developed from real hybrid-threat patterns across energy, hospital and defence-adjacent operators. Each is designed to expose genuine organisational gaps rather than showcase existing capability, and each treats the informational layer as the primary threat surface.
For designated entities, the same three stages are the regulated pathway. Designation readiness and gap assessment, then risk assessment and the resilience plan, then exercise and validation, with the artefact that satisfies the regulator being the one that makes leaders decide well.
Critical Entities ResilienceThe earliest useful step is almost always a scoping workshop, which establishes where an organisation stands before anything larger is committed to.