01

Choose an outcome worth testing.

For example: can the team identify the affected account, find the relevant evidence, reach the right decision-maker and agree a safe next action? Make the expected outcome specific enough to observe.

02

Define the boundaries.

Confirm the systems, people, time window and permitted activities. Use fictional records and an isolated environment where appropriate. Make it clear how the exercise will be stopped and how a real incident takes priority.

03

Include the business conversation.

Bring technical and business roles into the same scenario. Ask how the team would judge service impact, approve an action and communicate uncertainty. The discussion matters as much as a technical result.

04

Record observations without rewriting the outcome.

Keep what actually happened, including missing evidence, delays and unclear ownership. Do not label a scenario successful merely because the exercise ended or a ticket was closed.

05

Apply and revisit the learning.

Assign the improvements, define the evidence of completion and choose a date to retest. A useful exercise leaves the organisation with a clearer process, better evidence or a decision that is easier to make.

Talk to ITS Consulting about your security priorities and how evidence-led review can support the next step.

Talk to the team