If you want your organisation to make hard calls fast in a real cyber incident, you have to practise when the stakes are low.
“Like a rabbit in the headlights”
Decision paralysis is real. A cyberattack is a complex, fast moving problem for your crisis team: Questions on escalation, containment, communication and coordination all hit at once. If ransomware is encrypting your network, you need to move from BAU to a functioning crisis team quickly. That only comes with practice.
Here are 5 areas to improve, speed up response times and reduce the cost of an incident.
1. Clear authority – fast containment
In a cyber-attack many delays occur from not knowing who has the authority to shut systems down or lock accounts.
During the 2023 Capita cyber incident, a high‑priority alert was raised within minutes, yet it appears that no one was clearly authorised to isolate systems or lock accounts.
The infected device stayed online for 58 hours.
This gave the attacker one key advantage – time. With only one SOC analyst on shift and no clear escalation route, people froze instead of acting. The ICO later said that a faster response would have contained the threat.
Define authority. Practise it. Decisions speed up.
2. High quality plans support fast action
Research in hospital emergency departments, an environment with long shifts and urgent life-critical actions, showed that having a checklist dramatically improved performance.
Concise checklists your team can actually use during an incident can speed up response and give members a framework to focus their efforts.
This should come as no surprise. Education research into cognitive load has shown that working memory can only process a limited amount of information at once. The stress of an evolving cyber-attack increases cognitive load, leaving fewer mental resources available for reading and comprehension tasks. Simply put – If your plan is pages of dense text and background information, nobody will use it. build checklists. Keep them printed and available.
3. Practice to identify and improve
Running exercises or simulations identifies issues like approval bottlenecks quickly in a way that is almost impossible from just reading the plans. This gives you the opportunity to fix them in daylight rather than discover them in a crisis.
Until you have worked through your process it can be hard to see the consequences of actions.
- Does the escalation from the help desk to crisis team work?
- If your GC is standing up the team, how does the information get from that initial helpdesk report to them?
- Who are your key stakeholders? Do you have their contact details? or do you need to go through the CEOs inbox to find them?
- How does the plan, playbooks and checklists stand up if we have no SSO or access to O365?
By actually running the plan – doing the actions and not just talking them through, you can strengthen coordination and refine your playbooks.
4. Communication processes must match decision speed
Slow approval chains kill momentum.
In exercises, teams often discover their comms workflow cannot keep pace with the incident tempo, which is a huge red flag.
While it might seem like a good idea to have Comms, IT, Legal and the board sign off on all external communications, is this necessary or practical?
What will they stop focussing on to read through your comms draft? Or will they just ignore the request, leaving you in sign off limbo? (getting drafts pre-approved first can also help here).
5. Practice now to perform later
If you want your team to make fast, confident, correct decisions in a crisis, you need to put them in realistic scenarios and let them practise the hard calls again and again.
In a crisis, it’s easy to freeze, but practice stops that happening.
Cyber-attacks demand quick decisions on escalation, containment and communication.
If you rehearse these actions, they will become instinctive. Clarify authority and write checklist to reduce mental load when stress is high. Run exercises to show you where delays and gaps really are, so you can fix them before an incident. If you can do this, and keep your messaging up to speed, you will be in strong position in the event of an incident.
When the pressure hits for real, you do not rise to the occasion. You fall to the level of your training.


