CyberOne Blog | Cyber Security Trends, Microsoft Security Updates, Advice

Stories from the SOC: Lessons in Preparedness from the UK's National Resilience Exercise

Written by Daniel Bergner | Jul 22, 2026 8:00:00 AM

When I read about the UK’s planned National Resilience Exercise, what stood out to me wasn’t the scale of it. It was the thinking behind it.

The Government is not assuming its plans will work simply because they have been documented. It is putting them to the test to understand how departments, emergency services and critical national infrastructure work together when they are operating under genuine pressure.

That is exactly how organisations should approach cyber resilience.

Modern disruption rarely fits neatly into one category. A major incident could involve a cyberattack, telecommunications failure, power outage, supply chain disruption or pressure on public services, and in many cases several of these events may happen at the same time.

The biggest challenges are rarely caused by technology alone. They usually arise from uncertainty, incomplete information and the need to make difficult decisions while the situation is still developing.

That raises a practical question for every business leader:

When did your organisation last test whether its incident response plan would actually work?

National preparedness and organisational preparedness may differ in scale, but they are built on the same principle. Success depends on people making informed decisions, communicating clearly and adapting when events do not unfold as expected.

Why the Government Exercise Matters to Business Leaders

One of the biggest misconceptions about resilience is that organisations only need to prepare for incidents that directly target them.

That is rarely how major disruption works.

I have supported incidents where the organisation was not the original victim. The impact reached them because a supplier went offline, a critical technology platform became unavailable, or a trusted partner experienced a security incident that created knock-on effects across the wider supply chain.

Your business does not need to be the primary target to experience the consequences.

A disruption affecting national infrastructure, telecommunications or a widely used cloud platform can quickly affect organisations across every sector. Employees may lose access to critical systems, suppliers may be unable to deliver and customer services may slow down or stop. Internal teams may also need to continue operating without their normal communications tools, which can make coordination much harder.

Resilience planning must therefore go beyond protecting your own environment.

Business leaders should ask:

  • What happens if a critical supplier or technology platform becomes unavailable?
  • Can teams continue operating without their usual systems or communications?
  • Who decides which services should be protected, paused or restored first?
  • How will the organisation respond if several problems occur at once?

Resilience is not only about stopping attacks. It is about keeping the critical parts of the business running when events are outside your control.

A Written Plan Does Not Prove You Are Ready

I have reviewed many cyber incident response plans over the years. Some are extremely detailed, with escalation paths, technical playbooks, communications procedures and governance frameworks.

On paper, they look excellent.

The challenge is that real incidents do not follow a neat process. As new evidence emerges, priorities may shift and key people may be unavailable. Technical teams may need to contain the threat while business leaders work to maintain critical services and manage legal, regulatory and customer obligations, often with only limited visibility of what is actually happening.

A response plan explains what should happen.

An exercise reveals what people will actually do.

That is the real value of testing.

Well-designed exercises uncover issues that documentation alone will never expose. Decision-making authority may not be as clear as expected, technical and business teams may have different recovery priorities and communication procedures may break down if email or collaboration tools are unavailable.

Finding those weaknesses during an exercise is the point.

I would much rather discover them in a meeting room than during a live ransomware incident.

A Serious Cyber Incident Becomes a Business-Wide Response

Another assumption I see regularly is that incident response belongs to the Security Operations Centre or IT team.

It does not.

The technical response may start there, but it rarely stays there.

I remember one incident particularly well. It began with two or three people investigating what appeared to be a contained issue, but as new information emerged the response expanded quickly.

Within hours, incident responders, Security Operations Centre analysts, infrastructure specialists, senior advisers and customer-facing teams were all involved. Each had a different responsibility, but everyone was working towards the same outcome: contain the threat, maintain critical operations and recover safely.

That is how serious incidents tend to develop.

What begins as a technical investigation soon becomes a business response involving executive leadership, legal, compliance, communications, operations, suppliers and external advisers. The organisation must coordinate these groups carefully because each one is making decisions that affect the others.

This is also why early detection matters. Services such as managed extended detection and response, commonly known as MXDR, help organisations identify and contain malicious activity before it develops into a much larger operational problem.

Microsoft Defender XDR, Microsoft’s unified threat detection and response platform, can connect activity across endpoints, identities, email and applications. Microsoft Sentinel, Microsoft’s cloud-based security information and event management platform, can centralise security data and support faster investigation and response.

Technology gives responders visibility and options, but people still need to make the decisions.

Cyber security may lead the technical response, but the business owns the outcome.

What Organisations Should Test Before a Real Incident

Organisations sometimes treat incident response exercises as a compliance activity, where the objective becomes proving that a plan exists rather than proving that it works.

That is the wrong mindset.

The purpose of an exercise is to expose weaknesses while there is still time to address them.

The most valuable exercises introduce uncertainty, challenge assumptions and force difficult conversations. If everyone leaves the room thinking everything went perfectly, the exercise was probably not realistic enough.

There are five areas every organisation should test.

  1. Decision-Making - Everyone should understand who can authorise containment, service shutdowns and recovery, as well as who is empowered to act if the usual decision-makers are unavailable.

  2. Communications - Technical teams should be able to explain the situation in clear business terms, while the organisation should also know how people will communicate if email, telephony or collaboration platforms are unavailable.

  3. Business Continuity - The organisation should agree which services are genuinely critical, what can be paused and what must be restored first so that recovery priorities are clear before an incident occurs.

  4. External Support - Incident responders, insurers, legal advisers, communications specialists and key suppliers should be able to mobilise quickly, and their role should be tested rather than assumed.

  5. Realistic Pressure - The scenario should include incomplete information, changing circumstances and conflicting priorities because that is what a real incident looks like.

Purpose-built cyber incident tabletop exercises are particularly effective because they bring technical teams, business leaders and decision-makers together around the same scenario. They show whether the organisation can make decisions, communicate and recover in practice rather than relying on assumptions.

What This Means for Your Business

A documented cyber incident response plan is essential, but it should never be the finish line.

Prepared organisations understand who has authority to make critical decisions, which services must be maintained or restored first and how teams will communicate if normal systems fail. They also know when external support should be activated and how technical findings will be translated into business decisions.

The organisations that respond best are not always those with the largest security budgets or the longest procedures. They are usually the ones that have practised, tested their assumptions and identified gaps before a real incident forced them to.

Preparedness Must Be Demonstrated

Preparedness is not something you declare, it is something you demonstrate.

Cyber threats will continue to evolve, supply chains will become more interconnected and organisations will depend on more technology, cloud platforms and external providers.

That means incident response cannot be treated as an annual compliance exercise. It must become part of how the organisation builds and maintains resilience.

If your incident response plan has not been tested recently, CyberOne can help you run a practical cyber security assessment or tabletop exercise. We will identify gaps in decision-making, communications, recovery and external support, then provide a prioritised plan to strengthen readiness.

Book a 30-minute cyber preparedness discussion to review your current incident response approach and identify the areas that need testing first.