We're deep into Crisis Exercising Season, with a record number of scenarios running up to Christmas. While there's been a welcome shift toward more operationally focused exercises, cyber remains the dominant theme - and it continues to expose a critical flaw: organisations still treat cyber incidents as purely technical problems. In reality, cyber risk is a business risk, and this disconnect is more than a missed opportunity - it's a serious vulnerability.
Cyber risk is a business risk
A cyber attack doesn't just affect IT systems - it can halt operations, affect data, disrupt supply chains, damage reputations, and erode trust. These are business impacts that need business solutions. Yet when a cyber crisis hits, all eyes turn to IT. That's like asking the fire brigade to handle your legal, PR, and customer fallout during a blaze. IT's job is to contain the threat. It's the business - executives, legal, comms, operations - that must manage the consequences.
The illusion of preparedness
Cyber exercises are meant to test resilience, but too often they're designed by IT teams, for IT teams. They focus on playbooks, firewalls, threat detection, malware containment, and system recovery - important, but narrow. The result is a false sense of security: the organisation thinks it's ready, but only the technical playbook has been tested.
The challenge of realism
Designing realistic cyber exercises demands cross-functional involvement (legal, HR, comms, finance, and ops in the room, not just IT), relevant scenarios that speak to strategic impacts, authentic intensity that reflects the chaos of a real event, genuine decision-making under fire, and cultural readiness that bridges the gap between technical jargon and executive comfort with ambiguity.
Shifting the mindset
To build true cyber resilience, cyber scenarios need to be less about the technical cause, and more about the business impact.