Countermove

Incident response & disaster recovery

Find out how you actually respond when it matters.

Realistic tabletop exercises built around your own systems, plans and people - documented in a report your management can act on.

Two types of exercise

Both run as a facilitated session with your own team - nothing to install, and nothing for the participants to prepare.

Incident Response

From the first alert through triage, escalation, containment, evidence handling, regulatory notification and recovery. Scenarios such as ransomware, data breach, supply-chain compromise and phishing aimed at your executives.

Disaster Recovery

Tests your recovery plan across five phases: declaration, stabilisation, recovery, validation and return to normal operations. Scenarios such as ransomware, a virtualisation or storage failure, and the loss of Active Directory.

How it works

Three steps. The session usually takes 2–3 hours - we handle the rest.

01

Preparation

We build a profile of your organisation: technology, critical systems, regulatory obligations, on-call arrangements and suppliers. If you have an incident response or recovery plan, we assess the exercise against it.

02

The exercise

An experienced facilitator runs the session with your team. Each round brings a new development, and what you decide shapes what comes next - exactly as in a real incident.

03

The report

You get a written report with the findings and a prioritised list of actions, reviewed before it reaches you. Usually within five working days.

Try a round

A heavily simplified taste of how an exercise runs.

What you get

A report management can read and IT can work from.

  • An executive summary written for decision-makers, not for engineers.
  • Key takeaways and prioritised actions, each rated high, medium or low.
  • A readiness scorecard scored by a transparent, weighted method, so you can measure progress from one exercise to the next.
  • An assessment of your own plan - as a document, and how closely the team followed it.
  • Round by round: every situation, every decision, and how it was judged.
See a sample report (PDF)

A fictional company, but a real report - produced by the platform after a nine-round Disaster Recovery exercise.

Easy to document for auditors and regulators

The requirements come down to this: test your response, and assess whether it works. The report is your evidence - dated, specific and ready to attach as an annex.

NIS2

Article 21 expects business continuity and recovery to be tested, and the effectiveness of the measures assessed. A single exercise covers both.

ISO/IEC 27001

Gives you a completed, documented test to point to for incident management (A.5.24–A.5.28) and ICT readiness for business continuity (A.5.29–A.5.30).

DORA

Financial entities must regularly test their ICT response and recovery plans. The exercise gives you the test and the documentation in one go.

One exercise does not make you compliant - but it closes the gap where the requirement reads "test it and document it". Because the method and the scorecard stay the same, you can show progress year on year instead of starting from scratch.

Curious how your team would handle it?

Call or email, and we’ll work out whether an exercise makes sense for you - and which type fits.