‘In theory, theory and practice are the same thing…
Most organisations have an incident response plan. The problems tend to start when a real incident crosses departments, affects suppliers, takes systems offline, and forces people to make decisions before they fully understand what has happened.
At that point, response is no longer confined to the security team. Operations may need to decide whether a service can stay online. Communications teams must work out what customers should be told and when. Legal and compliance teams may have reporting deadlines to meet. Executives could be asked to approve decisions while the investigation is still underway. All of this can happen while attackers remain active in the environment. Cyber Europe 2026 offered a useful example of how complicated that can become. In June, around 5,000 participants responded to a simulated attack affecting European rail and maritime infrastructure.
The scenario involved disruption to port and rail operations, ransomware, exposed passenger data, safety concerns, and disinformation. The exercise required coordination across technical, operational, and political teams, and tested the EU Cyber Blueprint and broader EU‑level crisis coordination mechanisms.
…in practice, they’re not.’ — Benjamin Brewster
Exercises can expose problems that aren’t obvious from incident response documents. Who has the authority to shut down a critical service? What happens when a supplier is unavailable? Who speaks to customers? Can the company continue operating if its usual communications systems are down? And who takes over if somebody with a key role in the response plan can’t be reached?
Organisations can also use exercises to find out where time is being lost. A security team may detect and contain an attack quickly, while an important business decision sits waiting for approval. Information may reach one team but not another. An escalation process that works during normal operations could well prove too cumbersome in the middle of an incident. Dependencies outside the business need the same scrutiny. The World Economic Forum found 44% of highly resilient organisations simulate cyber incidents with ecosystem partners, compared with 16% of those it classifies as not resilient enough.
Few companies will handle a serious incident alone. Cloud providers, software vendors, managed service providers, insurers, regulators, law enforcement, and other partners may all be involved. An exercise can show whether those relationships work before they are tested by an actual crisis.
Top trends
• Incident exercises are extending beyond security teams: Businesses are involving operations, communications, legal, executive leadership, and external partners in business resilience exercises. This can reveal problems with authority, escalation, communications, and third-party dependencies that technical exercises are unlikely to uncover.
• Organisations are looking more closely at where response time is lost: Detection and containment are only part of an incident. Approval processes, missing information, unclear responsibilities, and
slow escalation can hold up important decisions. Exercises give companies an opportunity to map these delays before a real incident occurs.
• Incidents increasingly require several response plans at once: A single attack can involve ransomware, stolen data, operational disruption, supplier problems, safety concerns, and disinformation. Security teams may find themselves working alongside business continuity, crisis communications, legal, compliance, and operational teams from the early stages of an incident.
Regulatory watch
The first year of DORA incident reporting has provided an early look at what is causing major ICT disruption. System failures and external events were the main causes of reported incidents, with regulators also pointing to third-party risk and coordination with service providers during incident response.
CISO voice
“It is crucial that simulation exercises genuinely challenge everyone involved and closely reflect how a real crisis might unfold. You can’t make it easy. Executives need to be confronted with difficult decisions – are they willing to pay a ransom or spend two weeks offline while systems are brought back online?”
— Martin Laberge, CISO at North American natural gas company Énergir
Innovation/startup spotlight
Respond.Repeat develops cyber incident simulations that examine how businesses respond under pressure. Its platform records issues such as delays in decision-making, escalation bottlenecks, missing information, and coordination problems, giving organisations evidence of where their response processes need work and supporting exercises linked to requirements such as NIS2 and DORA.
Barcelona Cybersecurity Congress update
This year’s Barcelona Cybersecurity Congress will look at how organisations prepare for cyber incidents and manage the disruption that follows. Resilience, critical infrastructure protection, incident response, and security across connected environments will form part of the wider discussion around Europe’s changing cybersecurity requirements.
Barcelona Cybersecurity Congress 2026
Dates: 3–5 November Location: Barcelona Co-located with: Smart City Expo World Congress
CONNECTING EUROPE’S CYBERSECURITY ECOSYSTEM Register for Barcelona Cybersecurity Congress 2026