Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Crisis Management and Business Continuity Exercises | Resilience Guard
Crisis management and business continuity exercises

Exercises that prove your plans survive contact with reality.

Tabletop exercises, crisis simulations, cyber crisis exercises and full scale rehearsals, designed, facilitated and scored by practitioners, so your organisation gains tested capability and the regulatory evidence that ISO 22301, NIS2, DORA, KRITIS and the Swiss ISG now expect.

The service

What is a crisis management exercise?

A crisis management exercise is a structured rehearsal in which an organisation tests its plans, people and decision making against a realistic scenario, in formats ranging from a discussion based tabletop exercise to a full scale live simulation, producing evidence of capability and a prioritised improvement plan.

Plans that have never been exercised are assumptions. A business continuity exercise or preparedness exercise converts those assumptions into observed fact: whether the crisis team convenes fast enough, whether escalation and communication work under pressure, whether recovery decisions hold when information is incomplete. Resilience Guard designs and facilitates the full spectrum, from tabletop exercises for boards to functional and full scale exercises across critical operations.

Every exercise is run to a documented lifecycle: objectives and scope, scenario design, facilitated conduct, scored observation against defined criteria, a no fault debrief, and an owned action plan. That discipline is what turns a rehearsal into a lasting increase in resilience, and into an evidence trail an auditor or supervisor will accept.

Standards
ISO 22301, 22361, 22398
Regulations
NIS2, DORA, KRITIS, ISG
Formats
Tabletop to full scale
Output
Scored report, action plan
THE EXERCISE LIFECYCLEDesignObjectives, scopeScenarioInjects, branchesConductFacilitated liveObserveScored criteriaDebriefNo fault reviewAction planOwned, trackedRe-exercise at planned intervals and after significant change, as ISO 22301 clause 8.5 requiresEvery stage is documented, so one exercise produces a complete evidence trail for auditors and regulators.
The exercise lifecycle: six documented stages, then re-exercise at planned intervals and after significant change, per ISO 22301 clause 8.5.
The formats

From tabletop exercise to full scale rehearsal

FIVE FORMATS, ONE PROGRAMMERealism and decision pressureOrganisational involvementTabletopDiscussion basedFunctionalOne capability, liveGamifiedOperation HELVETIACyber crisisIT, OT and commsFull scaleLive, multi teamA mature programme climbs the ladder over time; most organisations begin with a tabletop exercise.
Exercise formats by realism and organisational involvement. A mature exercise programme climbs the ladder over successive cycles.
Tabletop exercise. A facilitated, discussion based walk through of a scenario with the crisis or continuity team. The fastest way to expose gaps in plans, roles and escalation, and the natural starting point of an exercise programme. Delivered at board level as our Top-Team Exercises.
Functional exercise. One capability tested live in compressed time: crisis communications, incident escalation, an alternate site activation or a recovery procedure, observed and scored against defined criteria.
Gamified decision exercise. Operation HELVETIA, our proprietary branching crisis decision game: 72 decision cards, six business functions, one cascading ransomware crisis, ninety minutes of scored decision pressure.
Cyber crisis exercise. A scenario built on IT and OT disruption, ransomware or data breach, exercising the technical response together with executive decision making and communications. Designed hand in hand with our cyber resilience practice.
Full scale exercise. A live, multi team rehearsal across sites and functions, the closest an organisation can come to the real event without living it. Reserved for mature programmes and critical operations.
Regulation

Exercising is now a supervisory expectation

ISO 22301, the business continuity management standard, requires in clause 8.5 an exercise programme that validates continuity strategies and solutions at planned intervals and after significant change; ISO 22398 provides the international guidance for designing those exercises, and ISO 22361 anchors the crisis management capability they test. Our exercises are designed to all three, so results feed certification audits directly.

NIS2 places cyber risk management, incident handling and business continuity duties on essential and important entities, with management bodies accountable for oversight and training; a documented exercise record is among the clearest evidence of that oversight. DORA goes further for the financial sector, mandating a digital operational resilience testing programme, with crisis communication and response capabilities expected to be exercised, up to threat led penetration testing for designated firms.

In Germany, operators under KRITIS and the BSI Act must demonstrate the effectiveness of their resilience measures, and in Switzerland the Information Security Act gives critical infrastructure operators a 24 hour incident reporting duty to BACS, a deadline no organisation meets for the first time during a real crisis. Exercising is how that readiness is built and evidenced; see our German language ISG briefing and our operational resilience overview.

Questions

Frequently asked questions

What is the difference between a tabletop exercise and a simulation?+

A tabletop exercise is discussion based: the team talks through its response to a scenario around a table, at low cost and low risk. A simulation adds live pressure, injects arriving in real time, compressed decision windows and observed performance. Most programmes start with a tabletop and climb towards simulation and full scale formats.

How often should we run a crisis management or business continuity exercise?+

ISO 22301 requires exercising at planned intervals and after significant organisational change. In practice, mature organisations exercise at least annually at leadership level, with critical functions and regulated entities exercising more frequently and varying the format each cycle.

Do your exercises count as evidence for NIS2, DORA or ISO 22301 audits?+

Yes. Every exercise produces a documented record: objectives, scenario, participants, scored observations, debrief findings and a prioritised action plan. That record maps directly to ISO 22301 clause 8.5 and to the oversight and testing expectations in NIS2 and DORA.

Who should take part in an exercise?+

It depends on the format. Tabletop and gamified exercises are built for boards, executive committees and crisis teams; functional exercises involve the teams that own the capability under test; full scale exercises span multiple teams and sites. We design the participant set around the objective.

Can you exercise a cyber crisis specifically?+

Yes. Cyber crisis exercises built on ransomware, data breach or IT and OT disruption scenarios are our most requested format, exercising technical response together with executive decisions and communications. Operation HELVETIA is built on exactly such a scenario; see also our cyber resilience practice.

Explore further

Related programmes

Simulations and Exercises

Top-Team Exercises

Board level crisis simulations that place your leadership team inside a realistic, escalating disruption, scored and debriefed.

Explore the programme ›
Simulations and Exercises

Operation HELVETIA

Our proprietary gamified crisis decision exercise: 72 cards, six functions, one cascading ransomware crisis, ninety minutes.

Explore the programme ›
Executive and Masterclass

Crisis Management Masterclass

One intensive, practitioner led day that prepares boards and executives to lead through a serious crisis, anchored on ISO 22361.

Explore the programme ›
Professional Certification

BCLE 2000 Business Continuity Training

DRI's seminal 4.5 day course on all ten Professional Practices, the foundation of a defensible continuity programme.

Explore the programme ›
Professional Certification

CRLE 2000 Cyber Resilience Training

DRI's CRLE 2000, Cyber Resilience for the Business Continuity Professional, integrating cyber security and continuity across five elements.

Explore the programme ›
Professional Certification

CIRP Professional Certification

The European training architecture for critical infrastructure resilience under NIS2, KRITIS and the Swiss ISG, in three tiers plus a workforce programme.

Explore the programme ›
Executive and Masterclass

Executive Training for Advisory Firms

Training and accreditation for global consulting teams, trusted by three of the world's four largest professional services networks.

Explore the programme ›
Professional Certification

DRI Accredited Training

The global gold standard in business continuity education, delivered by an exclusive accredited DRI International provider.

Explore the programme ›
Professional Certification

BCP IT/DR Workshop

DRI's two day IT Disaster Recovery Planning workshop: project plan, risk and BIA for IT, strategy, plans and new DR technologies.

Explore the programme ›
Professional Certification

7A Risk Management Framework Training and Certification

A three level pathway on the proprietary 7A framework, from Foundation through Professional to the governed Lead and Assessor scheme.

Explore the programme ›
Next step

Find out what your plans are worth, before an incident does.

Talk to us about a single exercise or a multi year exercise programme, on site or virtual, tailored to your sector and regulators.

Book a consultation
All consultations are treated with strict confidentiality.