Cyber crisis management exercise CIO team

Un opérateur majeur du secteur de l’énergie a souhaité confronter les équipes de la DSI et plus largement des chargés de projet aux impacts potentiels d’une crise d’origine cyber sur leurs applications les plus critiques.

Context

A major operator in the energy sector asked Alcyconie to confront, over half a day, the teams of the IT department and more broadly the project managers with the potential impacts of a cyber crisis on their most critical applications.

With a real maturity in crisis management in general, the organization wanted to illustrate the challenges of securing their supply chain, as a potential target of sophisticated cyberattacks.

Between data exfiltration and supply chain paralysis, different scenarios were designed for this morning aimed at encouraging the collective reflection of the participants and identifying the reflexes of each one, in line with their business biases.

Objectifs

  • Illustrate critical cyber crisis scenarios that the organization might face today or tomorrow
  • Raise awareness among the panel of participants of the specific temporality of cyber crises, particularly in terms of remediation and return to normalcy
  • Encourage collective exchanges in the face of a given scenario in order to identify best practices and areas for optimization
  • Illustrate the need to structure and train the defined crisis organization in order to anticipate the uncertainty and stress of an exceptional situation of cyber origin

Mission Description

The service took place in two stages:

  • The organization of a RETEX session, shared by a CISO from a large organization with similar challenges in order to allow participants to illustrate and concretely understand the reality of a crisis of cyber origin.
  • The facilitation, by two senior Alcyconie consultants, of the exercise session around two scenarios specifically designed for the organization.

Challenges and specificities

Evolving within an organization and team accustomed to managing exceptional situations, the challenge of the service was to maintain and capture the interest of the participants by combining both concrete feedback and realistic scenario, a key factor in the success of the service.

Alcyconie’s added value expertise

Alcyconie’s ability to mobilize its network of experts and CISOs in order to illustrate, through concrete examples, the operational realities of technical management of a cyber crisis made it possible to plunge the participants into a realistic situation.

The work, for several weeks, with members of the organization’s technical and security teams was also one of the success factors of the mission, as the participants were able to project themselves into concrete cases, impacting their production tools and systems in a fictitious but realistic way.

Expertises

Would you like to discover or participate in our training courses?

Contact us

Want to know more? To be contacted again? Click here!