Tabletop exercises, crisis simulations, cyber crisis exercises and full scale rehearsals, designed, facilitated and scored by practitioners, so your organisation gains tested capability and the regulatory evidence that ISO 22301, NIS2, DORA, KRITIS and the Swiss ISG now expect.
A crisis management exercise is a structured rehearsal in which an organisation tests its plans, people and decision making against a realistic scenario, in formats ranging from a discussion based tabletop exercise to a full scale live simulation, producing evidence of capability and a prioritised improvement plan.
Plans that have never been exercised are assumptions. A business continuity exercise or preparedness exercise converts those assumptions into observed fact: whether the crisis team convenes fast enough, whether escalation and communication work under pressure, whether recovery decisions hold when information is incomplete. Resilience Guard designs and facilitates the full spectrum, from tabletop exercises for boards to functional and full scale exercises across critical operations.
Every exercise is run to a documented lifecycle: objectives and scope, scenario design, facilitated conduct, scored observation against defined criteria, a no fault debrief, and an owned action plan. That discipline is what turns a rehearsal into a lasting increase in resilience, and into an evidence trail an auditor or supervisor will accept.
ISO 22301, the business continuity management standard, requires in clause 8.5 an exercise programme that validates continuity strategies and solutions at planned intervals and after significant change; ISO 22398 provides the international guidance for designing those exercises, and ISO 22361 anchors the crisis management capability they test. Our exercises are designed to all three, so results feed certification audits directly.
NIS2 places cyber risk management, incident handling and business continuity duties on essential and important entities, with management bodies accountable for oversight and training; a documented exercise record is among the clearest evidence of that oversight. DORA goes further for the financial sector, mandating a digital operational resilience testing programme, with crisis communication and response capabilities expected to be exercised, up to threat led penetration testing for designated firms.
In Germany, operators under KRITIS and the BSI Act must demonstrate the effectiveness of their resilience measures, and in Switzerland the Information Security Act gives critical infrastructure operators a 24 hour incident reporting duty to BACS, a deadline no organisation meets for the first time during a real crisis. Exercising is how that readiness is built and evidenced; see our German language ISG briefing and our operational resilience overview.
A tabletop exercise is discussion based: the team talks through its response to a scenario around a table, at low cost and low risk. A simulation adds live pressure, injects arriving in real time, compressed decision windows and observed performance. Most programmes start with a tabletop and climb towards simulation and full scale formats.
ISO 22301 requires exercising at planned intervals and after significant organisational change. In practice, mature organisations exercise at least annually at leadership level, with critical functions and regulated entities exercising more frequently and varying the format each cycle.
Yes. Every exercise produces a documented record: objectives, scenario, participants, scored observations, debrief findings and a prioritised action plan. That record maps directly to ISO 22301 clause 8.5 and to the oversight and testing expectations in NIS2 and DORA.
It depends on the format. Tabletop and gamified exercises are built for boards, executive committees and crisis teams; functional exercises involve the teams that own the capability under test; full scale exercises span multiple teams and sites. We design the participant set around the objective.
Yes. Cyber crisis exercises built on ransomware, data breach or IT and OT disruption scenarios are our most requested format, exercising technical response together with executive decisions and communications. Operation HELVETIA is built on exactly such a scenario; see also our cyber resilience practice.
Board level crisis simulations that place your leadership team inside a realistic, escalating disruption, scored and debriefed.
Our proprietary gamified crisis decision exercise: 72 cards, six functions, one cascading ransomware crisis, ninety minutes.
One intensive, practitioner led day that prepares boards and executives to lead through a serious crisis, anchored on ISO 22361.
DRI's seminal 4.5 day course on all ten Professional Practices, the foundation of a defensible continuity programme.
DRI's CRLE 2000, Cyber Resilience for the Business Continuity Professional, integrating cyber security and continuity across five elements.
The European training architecture for critical infrastructure resilience under NIS2, KRITIS and the Swiss ISG, in three tiers plus a workforce programme.
Training and accreditation for global consulting teams, trusted by three of the world's four largest professional services networks.
The global gold standard in business continuity education, delivered by an exclusive accredited DRI International provider.
DRI's two day IT Disaster Recovery Planning workshop: project plan, risk and BIA for IT, strategy, plans and new DR technologies.
A three level pathway on the proprietary 7A framework, from Foundation through Professional to the governed Lead and Assessor scheme.
Talk to us about a single exercise or a multi year exercise programme, on site or virtual, tailored to your sector and regulators.
Book a consultation