Un opérateur majeur du secteur de l’énergie a souhaité confronter les équipes de la DSI et plus largement des chargés de projet aux impacts potentiels d’une crise d’origine cyber sur leurs applications les plus critiques.
Context
A major operator in the energy sector asked Alcyconie to confront, over half a day, the teams of the IT department and more broadly the project managers with the potential impacts of a cyber crisis on their most critical applications.
With a real maturity in crisis management in general, the organization wanted to illustrate the challenges of securing their supply chain, as a potential target of sophisticated cyberattacks.
Between data exfiltration and supply chain paralysis, different scenarios were designed for this morning aimed at encouraging the collective reflection of the participants and identifying the reflexes of each one, in line with their business biases.
Objectifs
- Illustrate critical cyber crisis scenarios that the organization might face today or tomorrow
- Raise awareness among the panel of participants of the specific temporality of cyber crises, particularly in terms of remediation and return to normalcy
- Encourage collective exchanges in the face of a given scenario in order to identify best practices and areas for optimization
- Illustrate the need to structure and train the defined crisis organization in order to anticipate the uncertainty and stress of an exceptional situation of cyber origin
Mission Description
The service took place in two stages:
- The organization of a RETEX session, shared by a CISO from a large organization with similar challenges in order to allow participants to illustrate and concretely understand the reality of a crisis of cyber origin.
- The facilitation, by two senior Alcyconie consultants, of the exercise session around two scenarios specifically designed for the organization.
Challenges and specificities
Evolving within an organization and team accustomed to managing exceptional situations, the challenge of the service was to maintain and capture the interest of the participants by combining both concrete feedback and realistic scenario, a key factor in the success of the service.
Alcyconie’s added value expertise
Alcyconie’s ability to mobilize its network of experts and CISOs in order to illustrate, through concrete examples, the operational realities of technical management of a cyber crisis made it possible to plunge the participants into a realistic situation.
The work, for several weeks, with members of the organization’s technical and security teams was also one of the success factors of the mission, as the participants were able to project themselves into concrete cases, impacting their production tools and systems in a fictitious but realistic way.
Read the article
Real-time crisis - Real-time support for EXECUTIVE COMMITTEES, CISOS, DPO and operational teams
RetailRead the article
Development of a roadmap of cyber crisis management exercises
LuxuryRead the article