Preparedness exercises

Practice

The work of rehearsing decisions before they are required.

Preparedness is not a plan, it is a practice. Continuity plans are written for accidents, which arrive singly and without intention. Practice is built for an adversary choosing the moment, which is a different problem and takes a different kind of work.

That work runs in three stages sharing one capability framework and one readiness scale: Expose, Build, Test. Each stage stands on its own and can be commissioned on its own. Each ends the same way, with three specific changes, each carrying a named owner and a date.

Start a conversation See the three services
The spine

Three stages: Expose, Build, Test.

The stages are sequential where an organisation wants the full path and independent where it does not. Most begin at Expose, because it is the least demanding way to establish where an organisation stands before committing to anything larger.

Expose

A scoping workshop that surfaces what the organisation has been assuming without noticing. Produces an assumption inventory, a seventy-two hour scenario and a readiness ladder. The least demanding way to find out where the organisation stands for real.

Build

A full day of structured training that closes with an embedded tabletop and a certified record meeting management-body obligations under NIS2, CER and DORA. Develops the judgement, rehearsed, so the right call is available when there is no time to reason it out.

Test

Senior people under compounding pressure, deciding on incomplete and contradictory information while a decision log runs, and consequences arrive rather than scores. Preparedness is proven, not asserted.

One framework, one scale

The same four capabilities, measured the same way at every stage.

A single framework runs across the three stages, which is what allows an assessment made at Expose to be tested at Test rather than replaced. Four capabilities are examined, each placed on the same four-point readiness scale, so movement over time is visible rather than asserted.

Decision authority Who decides, on what authority, and whether that authority can be reached and exercised on the clock the situation sets.
Communications What the organisation says, when, to whom, and whether several sites and several spokespeople can hold one position under pressure.
Operational continuity Which functions must keep running, what they depend on, and how far those dependencies sit outside the organisation's control.
Stakeholder management Authorities, boards, customers, staff and media, each arriving with a different demand on the same few hours.
The readiness scale
P0
Unaddressed
No provision exists, and the gap has usually not been named.
P1
Documented
A provision exists on paper and has never been exercised.
P2
Tested, outdated
Exercised at some point, under assumptions that have since changed.
P3
Embedded
Rehearsed recently and reflected in how the organisation actually behaves.
Three services
01Expose · Two to three hours
Scoping Workshop
Structured sessions that expose where decision-making breaks before an adversary finds the gaps first, and where a critical function would stop running under deliberate pressure.
What this involves
  • A facilitated assessment of the real decision architecture: who decides, on what authority, with what information, and where that architecture would fail under contested conditions.
  • No preparation required from the client. The session works with what is in place and is direct about what is not.
  • A written gap assessment, delivered within three working days, structured for board-level reading and regulatory inspection, with priority vulnerabilities and specific next steps.
  • Designed as a first engagement. The least demanding way to find out where the organisation stands for real.
02Build · Full day
Preparedness Training
Executive judgement built through worked adversarial cases, so decisions hold when the situation is contested and the organisation is under adaptive adversarial pressure.
What this involves
  • A briefing on the threat landscape specific to the sector: state-influenced disruption, coordinated pressure campaigns, regulatory risk and supply-chain exposure, illustrated with real cases from comparable operators.
  • A facilitated self-assessment locating where this organisation is exposed, set against what has happened to others in the same sector.
  • A tabletop exercise that puts the framework under pressure through a compressed scenario with structured injects.
  • CER and NIS2 require management bodies to receive preparedness training. This constitutes that training and produces documented evidence of delivery.
03Test · Half to full day
Wargame
A live, adjudicated exercise in which the adversary has genuine agency and the informational layer is the primary threat surface. Preparedness is tested under pressure, not asserted on paper.
What this involves
  • A custom scenario built from the actual threat vectors, regulatory obligations and institutional pressure points specific to the organisation and its sector.
  • An adversary that responds to the team's choices, with structured decision points and timed injects: a notification deadline, a media inquiry with incomplete facts, an operational disruption, a board demand for information.
  • A facilitated debrief that names what held and what broke, with specific, attributed observations rather than a generalised list of lessons.
  • A written after-action report within five working days, constituting documented evidence of leadership-level validation for CER, NIS2 and DORA purposes.

Continuity plans assume an accident. Stave assumes an adversary choosing the moment.

Who this is for

No designation is required to need this.

Designated critical and important entities have a regulated pathway and a statutory clock, and Practice serves it directly. A large part of the exposure, however, sits outside the regulated perimeter altogether: defence-adjacent suppliers, sensitive-technology firms, media organisations, hospitals and municipalities, and the mid-sized operators on whom designated entities quietly depend.

For those organisations the risk is not that a critical function fails by chance but that it is taken out on purpose, at the worst possible moment, while the facts are disputed and the correction is slower than the claim. The work is the same work. Only the reason for commissioning it differs.

The library

The scenario repertoire behind the practice.

Every engagement draws on a library of original scenarios, based on a wargaming repertoire developed from real hybrid-threat patterns across energy, hospital and defence-adjacent operators. Each is designed to expose genuine organisational gaps rather than showcase existing capability, and each treats the informational layer as the primary threat surface.

Exercise Still Water
A coordinated drone incident over an energy site, where the most damaging element is not the drone but a false causal link to an unrelated equipment fault, turning a security event into a public-correction problem.
Exercise Grey Signal
Sustained espionage and influence pressure on a defence-adjacent supplier, where the executive test is how much to disclose, to whom, and when, while a readiness deadline runs against the clock.
The Third Party
A breach at a trusted supplier cascades into a prime's operations, forcing continuity and disclosure decisions the prime does not control and cannot postpone.

For designated entities, the same three stages are the regulated pathway. Designation readiness and gap assessment, then risk assessment and the resilience plan, then exercise and validation, with the artefact that satisfies the regulator being the one that makes leaders decide well.

Critical Entities Resilience
Contact

Every engagement starts with a conversation.

The earliest useful step is almost always a scoping workshop, which establishes where an organisation stands before anything larger is committed to.

LocationHelsinki, Finland