When a serious IT incident hits, it is the IT technicians who work on the systems. But many of the decisions that determine how it goes sit with management: whether to shut the business down, what customers and staff are told, who speaks to the press, and when the authorities are notified. That part can be rehearsed, like the technical part.
Why management, specifically, should exercise
Most response plans describe the technical steps in detail. Management's part is often shorter: a name on an escalation list and a reference to a communications plan. Whether that holds only becomes clear when someone has to make the call at two in the morning on incomplete information.
These are typical questions the plan does not fully answer in advance:
- Who has the authority to shut down production or the web shop, and who must be asked first?
- Who steps in if the CEO cannot be reached?
- When does an incident stop being an IT problem and become a matter for the executive team and the board?
- Who approves what is said to customers, staff and the press?
- Who decides if the attacker demands a ransom?
The answers depend on people, not systems. That is why those people need to exercise.
What NIS2 says about management's responsibility
The NIS2 Directive, Directive (EU) 2022/2555, has an article of its own on management: Article 20. It reads: "Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article." (Article 20(1))
It continues: "Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity." (Article 20(2))
The measures management approves are set out in Article 21. Among those that "shall include at least" are "incident handling"; "business continuity, such as backup management and disaster recovery, and crisis management"; and "policies and procedures to assess the effectiveness of cybersecurity risk-management measures" (Article 21(2)(b), (c) and (f)).
The directive does not mention tabletop exercises. An exercise is one way to practise incident handling and crisis management, and to produce documentation that can feed into assessing whether the measures work. Whether that is sufficient in your case is for you and your authority to decide.
In Denmark, the directive is implemented by the Danish NIS 2 Act (lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau, lov nr. 434 af 6. maj 2025). Which requirements apply to you depends on whether and how you fall within its scope.
What a management-level exercise tests
Decisions
The scenario puts management in front of the choices a real incident demands: shut down or stay open, reopen before IT has given the all-clear, pay or refuse. There is rarely one right answer. But there is a difference between a decision the right person makes deliberately and one that gets made because nobody else did.
Communication
Who tells what to whom, and when? The exercise shows whether the organisation speaks with one voice, whether the board is briefed in time, and whether staff hear it from management before they read it in the press.
Authority and notification
The exercise tests whether it is clear who may decide what, and who steps in when a key person is missing. For entities under NIS2, notifying the authorities is part of this. For a significant incident, the directive requires an early warning without undue delay and in any event within 24 hours of becoming aware of it, an incident notification without undue delay and in any event within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification (Article 23(4)). An exercise makes it plain whether anyone owns those deadlines, and whether management knows who judges an incident to be significant.
How a session is set up for management
A management exercise runs as a facilitated session with your own team, like any other tabletop exercise. In practice:
- Choose the scenario. The Incident Response exercise runs from the first alert through triage, escalation, containment, evidence handling, regulatory notification and recovery, with scenarios such as ransomware, data breach, supply-chain compromise and phishing aimed at your executives.
- Describe the organisation. Before the exercise, Countermove builds a profile of your technology, critical systems, regulatory obligations, on-call arrangements and suppliers. If you have an incident response or recovery plan, the exercise is assessed against it.
- Pick the participants. The people who would actually make the decisions: the executive team, the compliance owner, whoever handles communications, and an IT lead who can explain the technical situation.
- Block the time. The session usually takes 2–3 hours. An experienced facilitator runs it, and the participants don't need to prepare.
- Agree the follow-up. Decide beforehand who receives the report and who owns the actions afterwards.
What the report gives the management body
The exercise ends in a written report, reviewed before it reaches you and usually delivered within five working days. It contains:
- an executive summary written for decision-makers, not for engineers
- key takeaways and prioritised actions, each rated high, medium or low
- a readiness scorecard scored by a transparent, weighted method, so you can measure progress from one exercise to the next
- an assessment of your own plan, both as a document and of how closely the team followed it
- a round-by-round record: every situation, every decision, and how it was judged.
For a management body that has to approve and oversee, that is a concrete starting point: a dated report that can be attached as an annex, and a prioritised list of actions that someone can be made responsible for. One exercise does not make you compliant, but because the method and the scorecard stay the same each time, you can show progress year on year. Read more about testing your response under NIS2.
Try a round
On the front page you can try a round, a heavily simplified taste of how an exercise runs. Read more about Countermove's incident response and disaster recovery tabletop exercises.
This page is not legal advice.