Training in the pro league

Emergency and crisis team drill

  Practice real-life emergencies

  Test the effectiveness of defined measures

  Significantly reduce damage in an emergency

Talk to our experts

 

500+ customers place their trust in us – from startups to large companies

 

Your goal

You want to check the effectiveness of the organizational and technical measures defined in your emergency management.

 

Our service

We simulate an incident in an emergency and crisis management drill and evaluate the recovery measures you have taken.

 

The result

Your team has practiced the emergency and crisis situation and you know whether your emergency measures really work and avert the crisis.

 

Emergency and crisis team drills

What do football players from top teams, experienced firefighters and confident members of crisis teams have in common? They regularly practise familiar and, above all, unusual situations - despite fixed roles and defined procedures. This is because changing line-ups and different problem constellations mean that every exercise is important preparation for an emergency, even for professionals.

 

The composition

Are all relevant areas appropriately represented? Do all those involved know their tasks, competencies and areas of responsibility? How can the cooperation be improved?

 

The processes

Does notification of the required persons work? Are the intended processes known, applicable, complete and understandable? Is documentation used?

 

The equipment

Is the necessary equipment available (rooms, infrastructure, ICT, documents, etc.)? Can this be used in a suitable manner? What is the potential for optimization?

Training for the worst case scenario

Fortunately, the worst-case scenario occurs very rarely. Nevertheless, it is important to be prepared for it, because despite all preventive measures, targeted attacks, technical defects or force majeure cannot be ruled out. This is why, for example, the German Federal Financial Supervisory Authority (BaFin) requires all credit institutions to conduct regular emergency tests. In addition, regular emergency and crisis drills are, among other things, a prerequisite for successful certification in the area of information security in accordance with the internationally recognized ISO 27001 standard.

But companies should also train emergencies regularly in their own interest, because in emergencies or crises, other authorities and other processes apply. Being a security service provider, we know a lot about emergencies and crisis scenarios from practical experience. Our focus is on events related to information security.

1. Selection of the exercise

How real should it be?

Selection of the exercise

Depending on the planned need, the available resources and the maturity of your emergency/crisis management, different types of exercises can be considered. These differ in both exercise content and overall effort, as well as in the insight gained:

  • Plan briefings: Discussion and verification of existing emergency/crisis documentation for timeliness, completeness and accuracy with individual specialists and areas.
  • Technical/organizational functional tests: verification of individual technical measures (e.g., switchover tests between redundantly designed systems) or organizational precautions (e.g., availability of emergency equipment).
  • Alerting exercises: Test of information and escalation procedures and associated responses and (theoretical) outcomes.
  • Staff exercise: training of the cooperation of the emergency/crisis staff (e.g. roles and responsibilities, substitutes, etc.).
  • Full-scale exercise/simulation: Exercise of all processes with the involvement of all required areas (emergency/crisis staff, external specialists if necessary) based on a complex incident (e.g. cyber attack, blackout, data leaks, manipulation of data, etc.).
2. Exercise preparation

What does the scenario look like?

Exercise preparation

Realistic and target-oriented exercises require thorough planning and preparation. Therefore, HvS-Consulting designs the exercise scenario together with a few "insiders" on the basis of the existing emergency/crisis management precautions. This includes, for example, the joint elaboration of the contents of the exercise, the definition of the objectives and the flow of the exercise, the identification of the necessary areas and staff for the preparation and execution, the clarification of important parameters (e.g. is the exercise announced in advance).

Especially in the case of large-scale exercises such as simulations, it is also important to prepare the feeds and associated material during the preparation phase and to anticipate the likely activities and reactions of the decision-makers and solution teams.

3. Exercise execution

Is your emergency management up to speed?

Exercise execution

To ensure that an exercise reflects practice as closely as possible, it is important that the parameters are clear to all participants and that clear "rules of the game" are established and adhered to. Accordingly, a good briefing is important for the direction team, which initiates the various events and confronts the exercise participants with them, respectively. All exercise participants should know these rules to ensure that the exercise proceeds in an orderly manner and does not "take on a life of its own" in an unforeseen manner.

Another important aspect of the exercise is the observation of the progression, so that corrective action can be taken if necessary. An initial feedback - with regard to emergency/crisis management as well as preparation and execution - is usually shared out of fresh experience in the immediate aftermath of the actual exercise part.

4. Feedback & evaluation

Review and refine your system

Feedback & Evaluation

The be-all and end-all of the exercise is the evaluation and preparation of the scenario. The aim must be to have the knowledge available in case of an emergency and to be able to implement the necessary measures correctly.

It makes sense to hold a "lessons learned workshop" in the medium term. Optimization potential, positive feedback - but also mistakes and errors - can be reviewed and evaluated from a distance.

In the long-term follow-up, the consistent implementation of the results and measures must be ensured in order to bring the crisis exercise to sustainable success.

Realistic exercise scenarios 

Our emergency and crisis team exercises are not based on theoretical models, but on real incidents and current threat situations. We create a realistic, customized exercise scenario for you that reflects the relevant risks - adapted to your industry, company size and IT structure. 

Supply chain attack

Illustration Supply Chain Attack

Ransomware

Illustration Ransomware als Szenario für Notfall-und Kriesenstabsübungen

Bad Insider

Illustration Bad Insider als Szenario für Notfall-und Kriesenstabsübungen

Information leakage

Illustration information leakage als Szenario für Notfall-und Kriesenstabsübungen

Outage of supplier

Illustration outage of supplier als Szenario für Notfall-und Kriesenstabsübungen

Outage of buildings

Illustration outage of buildings als Szenario für Notfall-und Kriesenstabsübungen

DDoS

Illustration DDoS als Szenario für Notfall-und Kriesenstabsübungen

Blackout

Illustration blackout als Szenario für Notfall-und Kriesenstabsübungen

APT 

Illustration advanced persistant threat (APT) für Notfall-und Kriesenstabsübungen

Outage of cloud service

Illustration outage of cloud service für Notfall-und Kriesenstabsübungen

 

Do you want to practice and test an  emergency?

We will show you different scenarios and references for crisis team drills in a web meeting.

Yes, let's talk

More services for emergency and crisis management

Emergency & crisis organization preview

Customize crisis management: Be confidently prepared for emergencies with clear organization, defined processes and suitable equipment.

Read more
Establishing a BCMS Preview

Protect your company with tailor-made business continuity management: avoid IT failures, minimize risks, secure core processes. Request support now!

Read more