Hero Background
World-Class Cybersecurity Training & Consultancy

Cyber Crisis Leadership Training for Executives | DORA, NIS2, UK CAF & ISO 27001

Designed for boards and executive leadership teams who need to move beyond cyber awareness and confidently lead during high-pressure incidents.

BOOK A DISCOVERY CALL

A One-Day, Application-level Board Cyber Crisis Leadership Workshop

Course Overview 

Cyber incidents are no longer technical events managed solely by IT. They are business crises that demand rapid, high-stakes decisions from boards and senior executives, often within hours of an attack. Leaders are expected to make judgement calls on regulatory notifications, customer communications, operational continuity, legal exposure and recovery, frequently with incomplete information and under intense scrutiny.

At the same time, regulatory expectations have changed. DORA, NIS2, the UK Cyber Assessment Framework (CAF) and ISO/IEC 27001 all place clear expectations on leadership oversight, competence and evidence of preparedness. Regulators are no longer interested only in whether organisations have cyber controls. They increasingly expect boards to demonstrate that they understand their responsibilities, have exercised their decision-making processes and can evidence regular, meaningful training.

This one-day, application-level workshop is designed to prepare boards and executive leadership teams for those responsibilities. Rather than focusing on cyber awareness or technical concepts, participants spend the day applying judgement, making decisions and leading through realistic cyber crisis scenarios. Through facilitated decision drills, board-level discussions, regulatory exercises and communication challenges, they develop the confidence to lead effectively when every decision matters.

The workshop also serves as the ideal preparation for a live cyber crisis simulation or tabletop exercise. Participants leave with a clear understanding of their governance responsibilities, a practical framework for leading through a crisis and documented evidence of training that supports regulatory, audit and governance requirements.

Why Boards Need Cyber Crisis Leadership Training Now 

Three factors have made board-level cyber crisis leadership a business necessity rather than a nice-to-have.

Regulatory scrutiny is increasing

Across Europe and the UK, cyber regulation has moved from guidance to active supervision. DORA and NIS2 place explicit responsibilities on management bodies, while the UK CAF underpins GovAssure and wider critical infrastructure assessments. Organisations are increasingly expected to demonstrate not only that policies exist, but that boards understand, oversee and regularly exercise their responsibilities.

Accountability now sits in the boardroom

Cyber risk is no longer something boards can delegate entirely to technical teams. Directors are expected to approve cyber risk management, oversee implementation and demonstrate informed decision-making. In many sectors, that accountability now carries potential personal consequences alongside organisational enforcement.

Cyber incidents have become enterprise-wide crises

Modern attacks rarely remain isolated within IT. Ransomware, supply-chain compromise, deepfake fraud and other major incidents quickly involve legal, communications, operations, regulators, customers, suppliers and investors. Successful organisations are those whose leadership teams have already rehearsed how they will make decisions under pressure—not those trying to work it out during a live crisis.

Who is this Workshop for?

Senior, non-technical decision-makers who will be personally accountable in a crisis:

  • Board members and non-executive directors
  • CEO, CFO, COO and C-suite
  • General Counsel / Head of Legal, and Company Secretary
  • Chief Risk & Compliance Officers
  • Communications / Corporate Affairs leaders
  • Business-unit and divisional leaders with crisis roles

No technical background is required. The CISO/CIO are welcome as participants or observers, but the workshop is written for the people who must decide, disclose and defend, not the people who patch.

Benefits of the Board Cyber Crisis Leadership Training

Discharge and evidence mandatory board training duties in a single day

One workshop generates the documented, dated training and competence record that NIS2 Article 20(2), DORA Article 5(4), the UK CAF (A1/B6) and ISO 27001 Clause 7.2 all expect a supervisor, assessor or auditor to inspect.

Reduce directors' and executives' personal exposure

Understand exactly what "approve, oversee and be responsible for" means in practice, helping mitigate the personal liability and management-ban risks under NIS2 and DORA, as well as disclosure obligations under UK MAR.

Make faster, better decisions when it matters

Leaders rehearse deciding under uncertainty, against real regulatory clocks (4/24/72-hour notifications), so the first time they face a live crisis is not the first time they practise it.

Turn a technical topic into confident boardroom leadership — no jargon require

Built for non-technical directors, the day equips leaders to challenge technical, legal and communications advice intelligently rather than defer to it.

Find the gaps before an attacker does

Escalation mapping, board-pack critique and inject drills expose weaknesses in current plans, decision rights and assumptions, while they are still easy and cost-effective to fix.

Maximise return on your cyber drill

Your future tabletop exercises focus on real decision-making, not basic orientation. They also demonstrate compliance with the CAF/Cyber Governance Code requirement for an annual exercise.

Leave with practical, reusable artefacts

Participants take away a personal Cyber Crisis Decision Playbook, regulatory quick-reference guides, an escalation & decision-rights map, and a first-24-hours communications checklist.

Strengthen trust with regulators, insurers, customers and investors

A demonstrable and board-level readiness programme is increasingly a differentiator in insurance negotiations, supplier due-diligence questionnaires, tenders and investor governance reviews.
CYBER ATTACK TABLETOP EXERCISES

Professionally-conducted, engaging, interactive Cyber Drills

Our Cyber Tabletop Exercises are designed & often conducted by the most experienced tabletop facilitator in the world.

Take a look at the video on the right to see what exactly our Cyber Crisis Tabletop Exercises can do for your business.

  • Help you achieve compliance and demonstrate commitment to your cybersecurity posture.
  • Build muscle memory for your key Incident Response Team members.
  • Allow decision-making practice in a dynamic and highly evolved simulated attack scenario. 

 

CYBER ATTACK TABLETOP EXERCISES

Professionally-conducted, engaging, interactive Cyber Drills

Our Cyber Tabletop Exercises are designed & often conducted by the most experienced tabletop facilitator in the world.

Take a look at the video on the right to see what exactly our Cyber Crisis Tabletop Exercises can do for your business.

  • Help you achieve compliance and demonstrate commitment to your cybersecurity posture.
  • Build muscle memory for your key Incident Response Team members.
  • Allow decision-making practice in a dynamic and highly evolved simulated attack scenario. 

Delivery, format & materials

  • Format: In person (preferred for board dynamics) or live-online; single organisation/private cohort so scenarios and duties are contextual to the entity.

  • Group size: Optimised for a real board or top team (typically 8–16), enabling genuine table-group decision work.

  • Pre-work: A short pre-read plus a one-question self-assessment ("what is our board's current escalation trigger for a cyber incident?"), debriefed at the open to surface assumptions.

  • Facilitation: Led by a practising CISO-level facilitator with real incident, regulatory-investigation and board experience — external authority is what makes senior participants engage, debate and commit rather than defer.

  • Contextualisation: Scenarios, threats and regulatory scope tailored to the organisation:
    • Financial services → DORA-led
    • EU essential/important entities → NIS2-led
    • UK operators of essential services, central government, NHS → CAF/GovAssure-led
    • ISO 27001-certified organisations → framed to generate Clause 5.1/7.2/7.3 evidence

Participant materials

  • Personal Cyber Crisis Decision Playbook (board role, escalation triggers, key questions, reporting clock at a glance)
  • Cross-framework director-duty quick-reference card (DORA / NIS2 / CAF / ISO 27001)
  • Escalation & decision-rights map template
  • Regulatory reporting timeline aide-mémoire (DORA dual-clock initial notification, NIS2, UK NIS Regulations & the Cyber Security and Resilience Bill, GDPR, MAR)
  • Stakeholder communications first-24-hours checklist
Delivery, format and materials
Evidence

Post-workshop outputs — the evidence dividend

All four frameworks expect documented evidence, not just activity. The workshop deliberately produces artefacts that double as compliance and audit evidence:

  • Training attendance & completion attestation for each participant (date + content summary) — the record NIS2/DORA supervisors and ISO 27001 auditors ask to see, and which supports CAF A1/B6 and ISO 27001 Clause 7.2 competence evidence.

  • Board action log capturing the commitments and gaps identified during the day — feeds ISO 27001 management review (9.3) and CAF D2 (Lessons Learned).

  • Facilitator observations summary — an independent, high-level read of the board's readiness and priority improvements; useful supporting evidence in a GovAssure/CAF return.

  • Readiness statement confirming the cohort is prepared to proceed to a live simulation (evidencing CAF D1 exercising expectations and the Cyber Governance Code's annual-exercise direction).

Combined with board minutes approving cyber risk-management measures, these artefacts help a board answer the single question every regime is converging on — "show me how you discharged your duties" — on one defensible page.

The Regulatory Drivers: What Each Framework Requires of Leaders

 

This workshop is engineered to help boards discharge and evidence specific duties across the four regimes most likely to apply to a UK or EU organisation. The alignment is direct, not decorative. DORA, NIS2 and the UK CAF place explicit, board-level expectations on leadership knowledge and governance; ISO 27001 places its requirement on demonstrable leadership commitment and competence rather than a prescribed course. This workshop satisfies and evidences all four.

 

NIS2 Directive (EU 2022/2555): Cross-sector, 18 critical sectors

  • Article 20(1) — Approve & oversee. Management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity's infringements.
  • Article 20(2) — Mandatory training. Members of the management body are required to follow training sufficient to identify risks and assess cybersecurity risk-management practices and their impact on the entity's services — and to encourage similar training for staff.
  • Article 21(2) — All-hazards measures the board is accountable for, including incident handling, business continuity and crisis management, supply-chain security, and basic cyber hygiene and training.
  • Article 23 — Reporting duties the board must ensure function end-to-end (see the regulatory clock below).
  • Sanctions. Essential entities: up to €10m or 2% of worldwide annual turnover, whichever is higher. Important entities: up to €7m or 1.4%. Plus personal liability for management-body members in accordance with national implementing law, including temporary management bans for essential entities.

DORA (Regulation EU 2022/2554): Financial entities (lex specialis over NIS2)

  • Article 5(2) — Governance. The management body must define, approve, oversee and be responsible for the ICT risk-management framework; bears ultimate responsibility for ICT risk; sets the ICT risk-tolerance level; and approves and reviews business-continuity, response and recovery plans.
  • Article 5(2)(g) — Budget. The board must allocate and review budget for ICT security-awareness programmes and digital operational-resilience training.
  • Article 5(4) — Knowledge & skills. Members of the management body must actively keep their knowledge and skills up to date, including through specific, regular training, proportionate to the ICT risk being managed.
  • Article 13 — Awareness & training across the organisation.

UK NCSC Cyber Assessment Framework (CAF v4.0) — UK operators of essential services, GovAssure (central government), NHS and other regulated sectors

 

CAF is outcome-based and evidence-driven — you must achieve and demonstrate the outcome, not merely tick a control. Board-level governance is its foundation, which is why applied leadership training and exercising are the natural way to evidence it.

  • Objective A / Principle A1 — Governance. Requires board-level accountability and senior ownership of cyber risk, cyber risk integrated into enterprise risk management, and clearly defined roles and responsibilities at executive and non-executive director level. The contributing outcomes (board direction, roles & responsibilities, and decision-making) expect senior decision-makers to have sufficient knowledge to make well-informed cyber decisions — a board-competence expectation this workshop directly serves.
  • Principle B6 — Staff Awareness & Training. A positive security culture and appropriate training across all levels of the organisation, board included.
  • Objective D / Principles D1 & D2 — Response & Recovery Planning and Lessons Learned. Tested response and recovery plans, and improvement from exercises.
  • Companion — the UK Cyber Governance Code of Practice (2025), mapped by GOV.UK to CAF, explicitly directs boards to undertake training to build cyber literacy, to own cyber at executive/NED level, and to ensure incident-response plans are exercised at least annually with relevant internal and external stakeholders.

ISO/IEC 27001:2022 — The international ISMS standard (certification)

 

ISO 27001 does not prescribe a specific board crisis course. Its requirement is demonstrable leadership commitment and competence — which this workshop provides and evidences for the leadership tier.

  • Clause 5.1 — Leadership & commitment. Top management must demonstrate leadership and take accountability for the effectiveness of the ISMS, direct and support people, and set the "tone from the top" — which good practice holds includes mandating and participating in security training.
  • Clause 7.2 — Competence. The organisation must determine and ensure the competence of persons whose work affects information-security performance (which includes decision-making leaders), through education, training or experience, and retain documented evidence of it.
  • Clause 7.3 — Awareness. All persons under the organisation's control must be aware of the policy, their contribution to the ISMS, and the implications of not conforming.
  • Clause 9.3 & incident-management controls (Annex A 5.24–5.27). Leadership oversight of the ISMS through management review, and ownership of incident-management readiness.

cm_alliance_cross_framework_matrix

 

Workshop Agenda

 

Eight modules, each pairing a short expert input with an applied activity, because application-level learning is built by doing the decision, not hearing about it. Timings are indicative and tuned to the group on the day.

 

cm_alliance_workshop_agenda_v2

 

Every module maps to at least one duty in each applicable regime, and the workshop produces the documented evidence of training and competence that all four now expect an assessor or supervisor to be able to inspect on a single page. 

Cyber Crisis Leadership Training for the Board - Workshop Modules

  • Module 1: The 2026 threat landscape through a board lens

    NIS2 Art 20(2); DORA Art 5(4); CAF A2 (Risk Management); ISO 27001 7.2.

    Not a threat taxonomy — a translation of the current landscape into board consequences.

    Covers:

    - AI-accelerated and industrialised ransomware
    - Deepfake-enabled fraud and authorised-payment scams 
    - Third-party/supply-chain and ICT-provider compromise
    - Attacks on backups and on incident responders themselves.

    The emphasis throughout: Why the modern cyber crisis is an enterprise business crisis, not a technical failure.

    Applied activity: "So what for us?" — in table groups, participants map the top three threats to their own organisation's critical/essential services and name the board decision each would force.

  • Module 2: Your duties on the line: DORA, NIS2, CAF & ISO 27001

    NIS2 Art 20(1)&(2); DORA Art 5(2),(4); CAF A1 (Governance); ISO 27001 5.1 & 7.2.

    The heart of the regulatory alignment.
    - What "approve," "oversee" and "ultimate responsibility" mean in practice 
    - The non-delegable nature of accountability (you can delegate execution to a CISO, never the duty to understand and direct)
    - Personal liability in accordance with national implementing law 
    - Entity-level fines and management-ban exposure under NIS2/DORA
    - CAF's expectation of informed board decision-making
    - ISO 27001's demand for demonstrable leadership commitment and competence

    Above all: What a supervisor or assessor will actually ask the board to evidence.

    Applied activity: The one-page defence. Groups draft the answer they would give a supervisor/assessor who asks, "Show me how this board discharged its duties" — then stress-test whether their real-world evidence trail (board minutes, training records, competence evidence, CAF returns) could produce it today.

  • Module 3: The board before, during & after an incident

    NIS2 Art 21(2); DORA Art 5(2); CAF D1 (Response & Recovery); ISO 27001 A.5.24–5.27.

    The lifecycle model.

    Before: Setting risk appetite, approving plans, assuring readiness, asking the right pre-incident questions.

    During: The board's distinct role versus the incident team's — governance, not hands-on response; escalation triggers; the crisis-governance structure and who holds which decision.

    After: Recovery oversight, lessons-learned, remediation accountability and reporting to the regulator and market.

    The Crisis Cadence — running the board through a long incident. Real ransomware recoveries routinely run for weeks or months; the board's role is sustained oversight, not a single crisis meeting.

    This segment sets the board's rhythm for a live incident: meeting frequency, duration and a standing agenda; the upward information flow — what the incident team reports, in what format, how often; the decision log as a governance artefact — who keeps it, what it must capture, and why it becomes the board's defence file; and endurance — deputies, succession when key people are unavailable, and managing fatigue across a multi-week incident.

    Applied activity: Escalation mapping. Participants build their own escalation and decision-rights map — who convenes the board, at what threshold, with what authority — and identify where it currently breaks. Each group then drafts the standing agenda and reporting cadence for "day 5" of a live incident and nominates who keeps the decision log.

  • Module 4: Deciding under uncertainty

    Duties served: DORA Art 5(2) (risk tolerance) & Arts 28–30 (ICT third-party risk); NIS2 Art 20 (oversight judgement) & Art 21(2)(d) (supply-chain security); CAF A1 (decision-making) & A4 (Supply Chain).

    The core executive skill a crisis demands: making consequential, often irreversible decisions on incomplete and contradictory information, against a running clock.

    Frameworks for triage under ambiguity, avoiding both paralysis and premature certainty, separating the reversible from the irreversible, and knowing which decisions are the board's to make versus the executive's.

    Not Our Breach, Still Our Problem — the supplier-side incident. A distinct decision problem arises when the incident is at a third party: limited information rights, reliance on the supplier's timeline — yet the reporting duties remain yours.

    DORA's ICT third-party provisions and NIS2 Article 21(2)(d) place supply-chain security and incident obligations on the entity, not the supplier. The segment covers the contractual levers the board should already have demanded: notification clauses, audit rights and step-in rights.

    Applied activity: Inject drills. Short, escalating injects (a single odd login → media rumour → confirmation that regulated data is affected → attacker contacts board members directly). Groups must decide and justify with the information they have — then see how new information reframes the last call. The culminating supplier inject: "Your critical SaaS provider has confirmed a breach but will say nothing further for 48 hours. The DORA clock question: has your incident started?"

  • Module 5: The regulatory clock & legal exposure

    Duties served: NIS2 Art 23; DORA Arts 17–23 & RTS 2025/301; UK NIS Regulations; CAF D1 & sector reporting; GDPR Arts 33–34; UK MAR (listed entities).

    The reporting timelines rehearsed as board decisions, not compliance trivia.

    - DORA's initial notification — one report, two clocks: due within 4 hours of classifying the incident as major, and no later than 24 hours from becoming aware of it; the intermediate report follows within 72 hours of the initial notification and the final report within one month.

    -
    NIS2's 24h/72h/1-month cadence. The UK NIS Regulations' statutory 72-hour notification for operators of essential services — and the direction of travel:

    -The
    Cyber Security and Resilience Bill now before Parliament proposes a two-stage UK regime with an initial notification within 24 hours to both the sector regulator and the NCSC, a full report within 72 hours, direct customer notification, and penalties of up to £17m or 4% of global turnover — so boards should rehearse to the tighter cadence now. Plus the hard legal calls boards actually face: ransom-payment decisions and sanctions exposure, preserving legal privilege over investigations, disclosure obligations, and the interaction with insurers.

    The Second Clock — market disclosure for listed entities. For listed companies, a cyber incident can constitute inside information under the UK Market Abuse Regulation, triggering an obligation to disclose to the market as soon as possible unless the strict conditions for delaying disclosure are met.

    This clock runs independently of, and often faster than, DORA/NIS2/GDPR notifications, and directors of listed companies carry personal exposure for disclosure failures. (Delivered for listed cohorts; contextualised out for private companies.)

    Calling the Cavalry — law enforcement, the NCSC and who can actually help. When and why to engage the NCSC, Action Fraud and the NCA — and what each can and cannot do. The critical fact boards get wrong: NCSC engagement is voluntary and advisory; it is not a regulatory notification and discharges no reporting duty. The segment also covers how law-enforcement engagement interacts with insurers, legal privilege and disclosure — the reason it sits in this module.

    Applied activity: Beat the clock. Against a live scenario timeline, groups decide what must be notified, to whom, and by when — including, for listed cohorts, the MAR question "is this inside information yet?" — and draft the two-line "what we know / what we don't" statement for the first regulatory contact.

  • Module 6: Stakeholders & Communications under fire

    Duties served: NIS2 Art 21(2) & Art 23; CAF D1; ISO 27001 7.4 (communication).

    What each audience expects and how those expectations conflict: staff, customers, regulators, media, investors, partners and the attacker.

    Sequencing and consistency across channels; the risks of saying too much, too little, or too soon; spokesperson discipline; and the reputational half-life of the first 24 hours.

    Applied activity: The holding statement & the hostile question. Groups draft a customer holding statement, then face rapid-fire media/regulator questions from the facilitator — experiencing how wording written for one audience is read by all of them.

  • Module 7: How boards fail — and what good looks like

    Duties served: All of the above — the synthesis module (maps to CAF A1/D2 and ISO 27001 9.3/10 continual improvement).

    The recurring, avoidable failure patterns: treating cyber as "the IT team's problem," freezing on decisions, over- or under-communicating, unclear decision rights, no pre-agreed escalation, untested plans, and confusing activity with control.

    Set against the positive standard: what genuine board-level cyber resilience looks like — clear roles and risk appetite, rehearsed escalation, decisive-but-humble decision-making, coordinated response, and a defensible evidence trail.

    Applied activity: Failure-to-standard. Each group takes one classic failure mode and defines the specific practice, artefact or behaviour that would prevent it in their organisation, feeding directly into the action commitments at close.

  • Module 8: Applied decision drill & pre-simulation readiness

    Duties served: DORA Art 5(4), NIS2 Art 20(2), CAF B6 & D2, ISO 27001 7.2 (applied, evidenced training/competence).

    A consolidated mini-drill that runs the full arc — detection, escalation, decision, reporting, communication — at pace, so participants apply every module together.

    This is the on-ramp: it establishes the shared vocabulary, roles and expectations participants need to step into a full cyber crisis simulation / tabletop wargame ready to perform rather than learn the format cold.

    Outcome statement: Participants understand their role in a cyber crisis and are ready to apply that knowledge in a realistic exercise.

How It Connects to the Simulation

 

This workshop is designed to be delivered as the first half of a two-part engagement:

  1. Day 1 — This workshop: Builds the context, duties, decision frameworks and shared language.
  2. The simulation: A facilitated, injection-driven cyber crisis tabletop/executive wargame in which the board applies it all under realistic pressure — followed by an independent after-action report highlighting strengths, gaps and remediation.

Running the workshop first materially raises the value of the simulation: leaders arrive fluent in escalation, the regulatory clock and their decision rights, so the exercise tests judgement rather than being consumed by orientation. It also directly evidences CAF's expectation of annual exercising (D1/D2) and the "applied competence" bar in ISO 27001. It can be delivered standalone, or repeated annually to satisfy the "regular training" expectation across all four regimes.

Frequently Asked Questions About the Board Cyber Crisis Leadership Training

  • 1. What is the Cyber Crisis Leadership for the Board workshop?

    It is a one-day, application-level executive workshop that prepares boards and senior leadership teams to lead through a cyber crisis. Rather than raising awareness, it rehearses the actual decisions, escalations, regulatory notifications and communications leaders must make during a cyber incident, aligned to DORA, NIS2, the UK Cyber Assessment Framework (CAF) and ISO 27001.

  • 2. Is cyber security training for board members legally required?

    For many organisations, yes. NIS2 Article 20(2) requires members of the management body of essential and important entities to follow cybersecurity training. DORA Article 5(4) requires financial-entity board members to keep their ICT-risk knowledge and skills up to date through specific, regular training. The UK CAF and the UK Cyber Governance Code of Practice expect boards to build cyber literacy, and ISO 27001 requires demonstrable leadership competence with retained evidence. 

  • 3. Who should attend the workshop?

    Board members and non-executive directors, the CEO, CFO, COO and wider C-suite, General Counsel and the Company Secretary, Chief Risk and Compliance Officers, communications leaders, and business-unit leaders with crisis roles. It is written for the people who must decide, disclose and defend during an incident — not the technical team.

  • 4. Do participants need a technical background?

    No. The workshop is designed specifically for senior, non-technical decision-makers. All content is expressed in the language of governance, risk, liability, decisions and communication. CISOs and CIOs are welcome as participants or observers.

  • 5. How is this different from standard cybersecurity awareness training?

    Awareness training explains what cyber risk is; this workshop rehearses what leaders personally do, decide and say when an incident happens. It operates at the “apply and evaluate” level — using decision drills, injects, mock regulator and media exchanges, and board-pack critique — and it produces documented training evidence that awareness sessions typically do not.

  • 6. Which regulations and frameworks does the workshop cover?

    Four regimes are mapped module by module: the EU NIS2 Directive (including Article 20 duties, liability and sanctions), DORA for financial entities (including Article 5 governance and the incident-reporting RTS), the UK NCSC Cyber Assessment Framework (CAF) used in GovAssure and NIS Regulations oversight, and ISO/IEC 27001:2022 leadership, competence and incident-management requirements. It also covers GDPR breach notification, the UK Cyber Security and Resilience Bill and, for listed companies, UK Market Abuse Regulation disclosure. 

  • 7. What are the cyber incident reporting deadlines a board must know?

    Under NIS2: an early warning within 24 hours of awareness, an incident notification within 72 hours and a final report within one month. Under DORA: an initial notification within 4 hours of classifying an incident as major (no later than 24 hours from awareness), an intermediate report within 72 hours and a final report within one month. GDPR requires notifying the ICO or data-protection authority within 72 hours where personal data is involved, and listed companies may need to disclose to the market as soon as possible under MAR. The workshop rehearses decisions against all of these clocks.

  • 8. What evidence does the workshop produce for regulators and auditors?

    Each engagement generates a training attendance and completion attestation for every participant, a board action log, a facilitator observations summary and a readiness statement. Together these support NIS2 and DORA supervisory reviews, CAF/GovAssure returns and ISO 27001 Clause 7.2 competence evidence — helping the board answer “show me how you discharged your duties” on a single defensible page.

  • 9. What is a cyber crisis tabletop simulation, and how does the workshop connect to it?

    A cyber crisis simulation (or tabletop exercise / executive wargame) is a facilitated, scenario-driven rehearsal in which the leadership team responds to an unfolding incident under realistic pressure. This workshop is the purpose-built first half of that engagement: it establishes the duties, decision frameworks, escalation model and shared vocabulary so the simulation tests judgement rather than orientation. It can also be delivered standalone.

  • 10. How often should a board repeat cyber crisis training?

    At least annually. DORA requires “regular” training proportionate to ICT risk, NIS2 expects ongoing board competence, and the UK Cyber Governance Code of Practice directs boards to exercise incident-response plans at least once a year. Annual delivery — ideally paired with a live simulation — keeps the evidence trail current and captures regulatory change.

  • 11. What are the penalties if a board fails to meet these obligations?

    NIS2 provides fines of up to €10 million or 2% of worldwide annual turnover for essential entities (€7 million or 1.4% for important entities), plus personal liability for management-body members and possible temporary management bans under national implementing law. The UK Cyber Security and Resilience Bill proposes penalties of up to £17 million or 4% of global turnover. Beyond fines, boards face regulatory scrutiny, disclosure exposure, insurance consequences and reputational damage.

  • 12. Does PCI DSS require board cyber crisis training?

    No — unlike NIS2 and DORA, PCI DSS contains no explicit board-training mandate. It does, however, require formally assigned executive accountability for information security (Requirement 12.1.3–12.1.4), annual security awareness training for all personnel (Requirement 12.6), and annual testing of the incident response plan with trained response personnel (Requirement 12.10). A payment-card breach is exactly the kind of enterprise crisis this workshop rehearses — running the acquirer, card-brand, forensic-investigator and GDPR clocks in parallel — and the workshop’s documented evidence pack supports those PCI DSS executive-accountability and response-testing requirements, even though the standard itself does not mandate board training.

  • 13. Can the workshop be tailored to our sector and delivered privately?

    Yes. It is delivered as a private, single-organisation cohort (typically 8–16 leaders), in person or live-online, with scenarios and regulatory scope contextualised to the entity: DORA-led for financial services, NIS2-led for EU essential and important entities, CAF/GovAssure-led for UK operators of essential services, central government and the NHS, and framed to generate Clause 5.1/7.2/7.3 evidence for ISO 27001-certified organisations.

  • 14. Is Board cyber training mandatory under the UK Cyber Assessment Framework (CAF)?
    The CAF requires boards to achieve and evidence outcomes — informed decision-making (A1) and organisation-wide training including leadership (B6) — that applied board training is the recognised way to demonstrate. For NIS-regulated operators and GovAssure bodies, those outcomes are assessed by regulators, making the training effectively mandatory. The UK Cyber Governance Code of Practice, mapped to the CAF, then explicitly directs board members to undertake cyber literacy training. 
Read what our clients have to say about our Cyber Crisis Leadership Training for Executives

We pride ourselves on providing an exceptional service to our clients, but you don’t just have to take our word for it. Read what our clients have to say about working with us.

"The overall objective was to demonstrate & raise awareness amongst the board members. It is a regulatory obligation to ensure that the board are aware of their duties when it comes to incident response & cyber management. It was very important to run this workshop in my opinion… because although we have incident response plans internally, it was imperative to test them & the board’s engagement with a well-defined scenario created by myself and Amar. 

 

The muscle memory for the board and raising awareness among them regarding roles and responsibilities were the key tangible benefits. We’ve also been able to test the board’s decision-making skills which was vital. Improved awareness amongst board members regarding Cyber Incident Response and other Cybersecurity issues was evident, especially after the second workshop in 2021. For many organisations, I would recommend that it should be on their agenda to run a workshop like this, especially from a board perspective."  

Mudassar Ulhaq

CIO - Waverton Investment Management

"The facilitator conducted the fact finding and then planned the ransomware scenario to make it relevant and contextual to our organisation. Further, the exercise was conducted in a way that made the scenario feel real for the participants. They were encouraged to think like and respond as they would in an actual crisis.
 
Amar is a great facilitator. He is highly experienced which makes his insights very useful to all participants. But more importantly, he really knows how to engage a room full of business executives who may not always be in the loop with all technical aspects of cyber and ransomware prevention and response.

The ransomware tabletop exercise conducted by Cyber Management Alliance gave us exactly the kind of output we were expecting and met all our objectives. 
The executive report shared with us at the end was insightful and highlighted our strengths and weaknesses clearly. We know what needs to be worked upon and where we need more clarity. Thanks CM-Alliance and Amar for this extremely helpful and critical exercise in our overall cyber resilience strategy."

Catherine Butterill

Head of IT Operations, Directorate of Digital Services - Northern Lincolnshire And Goole NHS Foundation Trust

"We selected Cyber Management Alliance to conduct a non-technical, scenario-based, cyber-attack table-top exercise for members of our senior management.  Amar Singh is an excellent facilitator and is highly experienced which makes his insights useful to all participants. He engaged our incident response handling team and presented highly technical concepts in a non-technical, easy to understand manner.

The session and scenarios were relevant to our business and the tabletop ransomware exercise was conducted in a deeply engaging and conducive manner and the session met our objectives.”

Jenny Kray

Chief Finance Officer - Ashling Partners

"We needed something that’s more like a true demonstration of the capability of the business to actually respond. I wanted to get a fresh approach and that's why we opted for CM-Alliance’s CCTE Assessment.

Amar and I spent a good amount of time talking through options and planning the right scenario(s) for the tabletop test; We tried our best to design the scenarios to be challenging enough and both engaging and exciting to be a part of. The CCTE & the corresponding audit conducted has given us insights to reinforce our cyber strategy by continuing to help build the picture of where we were, where we are now and our next focussed steps. We will be engaging CM-Alliance on an annual basis.”

Neil Mallon

Strategic Technology Leader - Aster Group, UK

"The sessions and scenarios were relevant to our business and the tabletop ransomware exercises were conducted in a deeply engaging manner. The ransomware communication response templates were comprehensive and completely relevant to our business context and the accompanying communication plan was fit-for-purpose. Amar Singh is an excellent facilitator and is highly experienced which makes his insights useful to all participants. Importantly, Amar knows how to engage a room full of business executives and is able to present highly technical concepts in a nontechnical, easy to understand manner.”

Kanoksak Keekarjai

Head of Global Security, Risk and IT Compliance - SIG Global

"Cyber Management Alliance Ltd assigned their top and experienced security consultants to deliver our requirements. The consultants worked closely with my team and conducted output focused workshops to then plan, produce and conduct deeply engaging tabletop exercises.


CM-Alliance’s methodology and approach helped extract the most relevant information and data to enable them to construct highly relevant attack scenarios. 

 

Both the technical and executive tabletop sessions conducted by Cyber Management Alliance Ltd met all our objectives. The attendees from both the sessions were impressed with the facilitation and the outcome-driven approach and left the participants more informed and aware of the response processes and procedures.”

Nadeem Bashir

IT Compliance Manager - Otsuka Pharmaceutical Europe Ltd

"I can see the vast knowledge that the trainer Amar has come with in cybersecurity, incident response and disaster recovery. There's really a lot to learn in the cybersecurity space. In fact, if you think you know a lot before, you'll discover that there's a lot for you to learn. I think this training is something that is for everybody, not just for the IT people. I recommend it for everybody in the bank."
Yusuf Bello Mohammed

Head of Service Support - IT Department

"The trainer is really knowledgeable... not just knowledgeable, he was able to communicate that knowledge which was very important for me. The way the issues were presented and the conversation was carried on was very impressive. He was able to bring everybody talking, get everybody interacting, get everyone to chip in with different perspectives. In the end, it was a major learning experience."
Ifeanyi Jude Muonagor

Head of Security, IT Department - Central Bank of Nigeria

Why not book a discovery call to discuss your requirements?

Want more information on our Cyber Crisis Leadership Training for Executives? Book a no-obligation discovery call with one of our consultants. 

Let us show you why our clients trust us and love working with us.
All trademarks, service marks, trade names, product names, service names and logos appearing on the site, or on printed or digital material are the property of their respective owners, including in Cyber Management Alliance Ltd. Any rights not expressly granted herein are reserved.
Footer Top Background Image
Simply fill in your details to request a FREE callback