An Example of Crisis Simulation Workshop

An Example of Crisis Simulation Workshop

At 08:15 on a Monday, an infrastructure operator receives credible reports that a cyber intrusion may have disrupted a regional control system. Social media claims a major outage is imminent. A regulator requests an immediate briefing. The chief executive is travelling overseas, and a supplier has stopped responding. This example of crisis simulation workshop is designed to test what matters before the event: whether leaders can establish facts, make defensible decisions and maintain institutional control while information remains incomplete.

A well-designed simulation is not a presentation with a dramatic scenario attached. It is a controlled decision environment. It exposes the assumptions, authorities, information gaps and stakeholder pressures that can slow a response when the cost of delay is financial, operational or reputational.

What this crisis simulation workshop tests

The workshop brings together the executive team, operational leadership, legal counsel, communications, cyber security, risk, government affairs and relevant external partners. Its objective is not to predict every detail of a future incident. It is to assess whether the organisation can make proportionate, well-evidenced choices under pressure.

The scenario is deliberately plausible rather than cinematic. A suspected intrusion has affected a critical supplier platform, creating uncertainty around service continuity and data integrity. There is no confirmed evidence of customer harm, but the consequences could escalate quickly. Participants must decide what to verify, whom to inform and which protective actions are justified before the full picture is available.

This distinction matters. Crisis performance rarely fails because leaders lack a plan. It fails because the plan assumes clear facts, available decision-makers and stable communications. A simulation should recreate the friction between what an organisation needs to know and what it can know in time.

The scenario: the first six hours

The exercise begins with a short intelligence brief. It contains verified information, unverified reporting and clear intelligence gaps. Participants are told that an anomalous system event was detected overnight; a supplier has reported a technical issue; and a journalist has contacted the press office with specific allegations. The initial brief identifies source confidence and separates observed facts from assessment.

The incident lead must first determine the operating posture. Is this a technical disruption, a cyber incident, a potential safety issue or a developing reputational crisis? That classification affects escalation, resourcing and notification obligations. Participants are not rewarded for choosing the most dramatic label. They are assessed on whether their reasoning is explicit, proportionate and open to revision.

Inject one: conflicting technical evidence

Thirty minutes into the session, technical teams report that the suspected compromise may be isolated. At the same time, an external threat-monitoring provider identifies indicators consistent with a wider campaign against the sector. Neither source is conclusive.

The executive group must choose whether to isolate affected systems, activate continuity arrangements and inform the board. Each option carries a trade-off. Isolation may reduce exposure but interrupt services. Waiting may preserve operations but increase the risk of unmanaged harm. Alerting the board early improves oversight, yet poorly framed information can create unnecessary alarm.

The facilitator should press for decision discipline: What is known? What is assessed? What would change the decision? Who owns the next verification task, and by when? These questions prevent a crisis room from becoming a forum for competing opinions.

Inject two: stakeholder pressure accelerates

At the 90-minute point, a regulator asks whether the organisation has experienced a reportable event. A major customer requests assurance that its data and services are unaffected. Meanwhile, an employee shares a screenshot of an internal alert online, prompting speculation.

This is where technical response and institutional response must operate together. Legal counsel may advise caution in external statements. Communications may need a holding line. Operations may need customer-specific contingency measures. Government affairs may need to prepare senior stakeholders for a possible notification.

The workshop tests whether these functions work from one verified operating picture. If each team develops its own account of the incident, inconsistency becomes a crisis multiplier. The question is not whether every stakeholder receives identical language. It is whether every message is consistent with the best-supported facts and the agreed decision posture.

Inject three: a leadership constraint

The chief executive cannot join for two hours. The designated deputy is available but has not previously led a major incident. A non-executive director requests direct access to the technical team, while the incident commander believes this will disrupt response activity.

This inject exposes a common weakness: nominal governance without usable delegation. Participants must identify who has authority to approve expenditure, external notifications, operational shutdowns and public statements. They also need a route for board oversight that does not bypass the incident structure.

A credible workshop does not assume that seniority resolves ambiguity. It examines whether authority is documented, understood and trusted when time is limited.

How to run the workshop credibly

The strongest simulations are built on an organisation’s real risk landscape, operating model and stakeholder environment. Generic ransomware narratives can be useful for awareness sessions, but they seldom test the difficult choices facing a regulated utility, financial institution, NGO or public body.

Preparation begins with a focused intelligence baseline. This may include sector threat patterns, regulatory thresholds, supplier dependencies, public narratives, critical assets and known decision bottlenecks. AI-enabled research can accelerate the identification of relevant signals and scenario variables, but human verification remains essential. A simulation based on weak assumptions will produce rehearsed but unreliable confidence.

The facilitator should set clear rules at the outset. The exercise is a learning environment, not a performance review. Participants should act within their real roles and authorities. Information should arrive in timed injects, with enough ambiguity to require judgement but not so much that the scenario feels arbitrary.

Four artefacts make the session operationally useful:

  • an initial intelligence brief that distinguishes fact, assessment and uncertainty;
  • an incident log that records decisions, rationale, owners and deadlines;
  • a stakeholder map that ranks audiences by urgency, obligation and potential impact; and
  • an observer framework that assesses decisions against agreed criteria rather than personal preference.

The observer framework is especially valuable. It should examine speed, but not treat speed as the sole indicator of quality. A rapid decision made from poor intelligence can create avoidable exposure. Equally, a technically perfect assessment delivered after the decisive moment has passed is of limited value. Effective crisis leadership balances tempo, verification and consequence.

What leaders should assess afterwards

The debrief should begin immediately after the scenario, while decisions and uncertainties are still visible. It should not become a broad discussion of what participants would ideally do with more resources, more time or better information. The central question is whether the organisation performed effectively with the capabilities it has now.

Start with the decision record. Were critical decisions made at the right level? Was the rationale documented? Did participants identify thresholds that would trigger escalation, notification or operational restrictions? If different functions reached different conclusions from the same evidence, that is a signal to examine the common operating picture.

Then assess information flow. Did the incident team receive decision-ready intelligence, or raw updates requiring senior leaders to interpret technical detail for themselves? Were assumptions clearly labelled? Could the group distinguish a missing fact from an unresolved analytical judgement?

Finally, assess stakeholder control. The quality of a crisis response is often judged externally before the technical event is fully understood. Organisations should test whether they can communicate uncertainty without appearing evasive, show appropriate concern without making premature commitments, and maintain credibility with regulators, customers, employees and investors.

The output should be a prioritised improvement plan rather than a long catalogue of observations. Assign owners, define deadlines and identify which issues require a process change, a revised authority matrix, additional intelligence capability or a further simulation. GVI’s approach to strategic simulations treats this output as the core value of the exercise: fully operational insights that leadership can act on with confidence.

When a different format is needed

A tabletop workshop is not always sufficient. If an organisation needs to test technical recovery, call-centre capacity or cross-border coordination, a functional or live exercise may be more appropriate. These formats generate richer evidence, but they require more preparation, can disrupt normal operations and may be unsuitable where confidentiality is highly constrained.

Conversely, a board-level simulation may need less operational detail and more emphasis on strategic choices: capital allocation, market disclosure, political engagement and continuity of leadership. The right format depends on the decision that needs testing, not on the desire to make the exercise more elaborate.

The practical value of a crisis simulation lies in making uncertainty discussable before it becomes urgent. Leaders do not need a rehearsed script for every eventuality. They need tested decision rights, verified intelligence channels and the discipline to act when the evidence is incomplete.