Beyond Blue supported a high-profile UK government organisation by reviewing its Cyber Incident Response Plan and delivering a tailored operational tabletop exercise. Using recognised frameworks including NCSC CAF, NIS2, and ISO/IEC 27035, we identified improvement opportunities, upskilled participants, and tested incident response procedures through a realistic cyber crisis scenario. The engagement provided assurance over existing arrangements and delivered actionable recommendations to strengthen cyber resilience and operational preparedness.

Public sector – cyber incident response plan review and operational tabletop crisis exercise

Beyond Blue supported a high-profile UK government organisation by reviewing its Cyber Incident Response Plan and delivering a tailored operational tabletop exercise. Using recognised frameworks including NCSC CAF, NIS2, and ISO/IEC 27035, we identified improvement opportunities, upskilled participants, and tested incident response procedures through a realistic cyber crisis scenario. The engagement provided assurance over existing arrangements and delivered actionable recommendations to strengthen cyber resilience and operational preparedness.

Context & Problem

Our client is a high profile UK government organisation whose Digital Services department plays a central role in delivering critical operations and services. Recognising the growing sophistication of cyber threats across UK government and the wider public sector, the department sought to validate and strengthen its cyber incident response capabilities.

Having recently developed a Cyber Security Incident Response (CSIR) plan, the organisation wanted assurance that the document was fit for purpose before testing it in a live scenario, so a focused, structured review of the plan was agreed as the foundation for the engagement.

The client's primary goal was to run a Cyber Incident Operational Tabletop Exercise to validate the Digital Services IT team's coordination across departments and their internal and external communications during a crisis. The focus was firmly on the IT team's role, escalation pathways, use of documented procedures, and communication flows under pressure supporting the client's strategy to deliver an exercise by year end, embed cyber resilience, and prepare the wider organisation for more advanced crisis scenarios.

Beyond Blue’s Approach

Beyond Blue delivered a phased engagement that combined a focused review of the client's Cyber Incident Response Plan with the design and delivery of a tailored operational tabletop exercise. As an NCSC-accredited Cyber Incident Exercising provider, we brought a trusted methodology aligned with national standards, providing assurance that outcomes would stand up to industry and regulatory scrutiny.

Our approach comprised three core phases:

  • Document review. To ensure a focused and meaningful review of the client's Cyber Incident Response Plan (CIRP), Beyond Blue structured the assessment into core review areas derived from recognised best-practice frameworks, including the NCSC's Cyber Assessment Framework (CAF 4.0), NIS2, and ISO/IEC 27035. These reflect the components required for coordinated, timely, and resilient incident response. We assessed how effectively the plan would support likely incident types such as ransomware, identified gaps and weaknesses, and validated our initial findings through a focused stakeholder discussion. A review report set out key strengths, gaps, and prioritised recommendations, and directly informed the design of the subsequent exercise to ensure it was realistic and grounded in operational context.
  • Participant upskilling. Ahead of the exercise, we delivered a pre-exercise training session introducing the key principles of crisis exercising and cyber incident management, expected crisis team behaviours, and relevant real-world case studies. This established a common baseline of knowledge across all participants, ensuring they felt confident and well prepared to contribute fully on the day.
  • Operational tabletop exercise. We designed and delivered a bespoke operational-level tabletop exercise built around a credible, scenario-driven cyber crisis tailored to the client's technical and operational environment, including realistic attack vectors observed across government and the public sector. The exercise moved participants from the initial alert through a series of key decision points. Realistic injects were introduced throughout to drive the response and keep participants engaged, with a strong focus on how the team communicated internally.

Following this, we delivered a comprehensive post-exercise report capturing observations against the agreed objectives, with recommendations grouped into themes and prioritised by criticality and ease of implementation.

Want to speak to us?

If you would like to discuss a cyber or resilience problem with a member of the team, then please get in touch however you feel most comfortable. We would love to help you and your business prepare to bounce back stronger.