Three Lessons Organizations Learn During Their First Cyber Exercise

September 17, 2026

A cyber exercise does more than test technology. It reveals whether an organization’s people, plans and communication processes will work under pressure.

Organizations spend considerable time and money on security tools, policies and incident response plans. Those investments are important, but they do not guarantee an effective response. When a cyber incident occurs, employees must make decisions quickly, coordinate across departments, and continue working with incomplete information.

A cyber exercise provides a safe place to test those capabilities. It may be a discussion-based tabletop exercise or a technical scenario involving security staff. Either approach can reveal problems that were not obvious on paper.

Here are three lessons organizations often learn during their first exercise.

1. Responsibilities Are Not as Clear as Everyone Believes

Most employees understand their normal job responsibilities. During a cyber incident, those responsibilities can change quickly.

Who has the authority to disconnect a critical system? Who contacts executive leadership? When should the organization notify law enforcement, legal counsel, its insurance provider, or outside vendors? Who communicates with employees, customers or the media?

When these questions have not been answered in advance, confusion can delay the response and increase the damage. Technical staff may wait for executive approval while leadership waits for a recommendation from the technical staff. Communications, legal and operational personnel may not know when they should become involved.

An exercise makes these problems visible. It helps participants understand their own responsibilities and how their decisions affect the rest of the organization.

After an exercise, the organization should document who has decision-making authority, identify primary and backup contacts, and confirm that everyone understands when and how to report an incident.

2. Response Plans Do Not Always Match Current Operations

Many organizations have an incident response plan. Fewer organizations have tested that plan recently.

Plans can become outdated as personnel, technology, vendors, and business processes change. Contact information may be incorrect. A critical service may have moved to the cloud. A new vendor may now manage an essential system. Backup procedures that worked two years ago may no longer fit the current environment.

During an exercise, participants often discover that the plan describes how the organization operated in the past, instead of how it operates today.

This discovery does not mean the plan has failed. Finding problems during an exercise is much better than finding them during an actual emergency. The exercise has done exactly what it was intended to do. It identified weaknesses while the organization still has time to correct them.

Organizations should treat the incident response plan as a living document. Staff should review it regularly, update it after major operational changes, and revise it based on lessons from exercises and actual incidents.

3. Communication and Decisions Matter as Much as Security Tools

Cyber incidents may begin as technical events, but responding to them requires the entire organization.

Security tools can detect suspicious activity, block malicious traffic, or help analysts investigate an attack. They cannot decide whether to shut down a public service, notify affected individuals, activate a continuity plan, or release a public statement.

Those decisions require cooperation among technical staff, leadership, legal counsel, communications personnel, human resources, emergency management, and outside partners. An exercise often shows that detecting the problem is not the greatest challenge. The real challenge is helping everyone understand the situation and agree on what to do next.

Communication procedures should identify what information leaders need, how they will receive updates, and which communication methods are available if normal systems stop working. Technical staff should also practice explaining their findings in plain language so leaders can make informed decisions.

Exercise, Learn and Improve

The purpose of a cyber exercise is not to prove that an organization is perfectly prepared. No organization is. The purpose is to uncover gaps, strengthen working relationships, and make practical improvements before a real incident occurs.

A successful exercise should end with a review of what happened, a list of improvements needed, an assigned owner for each task, and realistic completion dates. Without those steps, valuable lessons can become meeting notes that disappear into a shared folder.

Organizations do not need a complicated scenario to begin. A focused discussion involving the right people can reveal weaknesses in responsibilities, plans and communication procedures.

The first cyber exercise may expose uncomfortable problems. That is not failure. It is progress. Every problem discovered during an exercise is one less surprise waiting during a real emergency.


Steven Washkowiak is the Cybersecurity Project Coordinator at the University of Arkansas’ Criminal Justice Institute.

Share the Post:

Join the NCPC mailing list