Scope and fit
Critical infrastructure exercises should test shared understanding between technical response and service operation. Use scenarios that make consequences visible without putting live process systems at risk.
Choose a consequence-based scenario
Select an event that affects a named service or process, such as loss of a remote access path or integrity concern in a supporting system. Keep technical details realistic for the organization.
Include operational and external partners
Invite control engineers, site leaders, IT, security, communications, vendors, and relevant public-sector counterparts. Clarify what is simulated and which contacts are real.
Record recovery assumptions
Ask who can authorize isolation, manual operation, restoration, and external notification. Debrief the sequence and assign improvements, then repeat a narrower exercise to validate the changes.
Decisions and tradeoffs
Use this table as a working review record. Replace assumptions with evidence from the target environment.
| Decision area | Working guidance |
|---|---|
| Choose a consequence-based scenario | Select an event that affects a named service or process, such as loss of a remote access path or integrity concern in a supporting system. Keep technical details realistic for the organization. |
| Include operational and external partners | Invite control engineers, site leaders, IT, security, communications, vendors, and relevant public-sector counterparts. Clarify what is simulated and which contacts are real. |
| Record recovery assumptions | Ask who can authorize isolation, manual operation, restoration, and external notification. Debrief the sequence and assign improvements, then repeat a narrower exercise to validate the changes. |
Implementation questions
What should the team decide about choose a consequence-based scenario?
Select an event that affects a named service or process, such as loss of a remote access path or integrity concern in a supporting system. Keep technical details realistic for the organization. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about include operational and external partners?
Invite control engineers, site leaders, IT, security, communications, vendors, and relevant public-sector counterparts. Clarify what is simulated and which contacts are real. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
What should the team decide about record recovery assumptions?
Ask who can authorize isolation, manual operation, restoration, and external notification. Debrief the sequence and assign improvements, then repeat a narrower exercise to validate the changes. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.
Plan, build, verify, operate
Choose a consequence-based scenario: Select an event that affects a named service or process, such as loss of a remote access path or integrity concern in a supporting system. Keep technical details realistic for the organization. Record the result and the next owner before changing the next boundary.
Include operational and external partners: Invite control engineers, site leaders, IT, security, communications, vendors, and relevant public-sector counterparts. Clarify what is simulated and which contacts are real. Record the result and the next owner before changing the next boundary.
Record recovery assumptions: Ask who can authorize isolation, manual operation, restoration, and external notification. Debrief the sequence and assign improvements, then repeat a narrower exercise to validate the changes. Record the result and the next owner before changing the next boundary.
Deployment checks
Turn the page into a reviewable handover by assigning each check to a person and retaining its result.
Run a Cyber Exercise for Critical Infrastructure Decision-Makers: decision 1
Write down the boundary, owner, dependency, and proof required for run a cyber exercise for critical infrastructure decision-makers before implementation begins.
Run a Cyber Exercise for Critical Infrastructure Decision-Makers: decision 2
Write down the boundary, owner, dependency, and proof required for run a cyber exercise for critical infrastructure decision-makers before implementation begins.
Run a Cyber Exercise for Critical Infrastructure Decision-Makers: decision 3
Write down the boundary, owner, dependency, and proof required for run a cyber exercise for critical infrastructure decision-makers before implementation begins.
Exercise with safety first
A critical-infrastructure cyber exercise needs safety and operational continuity ahead of realism. Define participating functions, scenario boundary, controller, communications, approved data, decisions to rehearse, excluded systems, safety contacts, and stop authority. Do not turn an exercise into unapproved activity against operational technology, life-safety systems, or production services.
Use a tabletop, simulation, or isolated range unless live activity is separately authorised with safeguards. Capture decisions, assumptions, communications, and improvement actions with owners and dates. An exercise result reflects the scenario and participants, not a guarantee about future resilience.
The operator owns safety, operational authority, and response decisions. DeployOpen can help facilitate the agreed exercise and document improvement work.
Handover and ownership
Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.
Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

