Build. Exercise. Control.: A Practical Approach to Cyber Incident Readiness
by josheph bell
September 5, 2026
Every organization knows that cyber incidents are not a question of if, but when. Yet when an incident actually happens, many organizations find that their response teams are not as ready as they assumed. Responsibilities are unclear. Escalation paths are undefined. Communication breaks down between IT, OT, legal, and management. Minutes turn into hours, and hours turn into extended operational disruption.
At the same time, regulatory requirements are getting stricter. Frameworks like NIS2, KRITIS, and industry-specific standards now expect organizations to demonstrate a structured, tested, and continuously improved incident response capability. Having documentation on a shelf is no longer enough.
Through our experience, the BxC team has identified the need for a service designed to help organizations build a Cyber Incident Response Team (CIRT), test it under realistic pressure, and measure its performance over time.
THE CHALLENGE: MOST TEAMS HAVE NEVER BEEN TESTED
Think about your own organization. If a ransomware attack hit your systems right now, would everyone know exactly who leads the response? Would IT and OT teams know how to coordinate? Would someone be tracking the regulatory reporting deadlines?
In our experience, common challenges include poorly defined roles and responsibilities across departments, undefined escalation paths for critical decisions, limited real-time situational awareness, and response plans that have never been practiced.
The result is longer disruptions, delayed recovery, compliance exposure, and increased financial impact. Incident response should never be tested for the first time during a real incident.
WHY THIS MATTERS NOW
The regulatory landscape is shifting. NIS2, the Cyber Resilience Act, KRITIS, and industry-specific standards all point in the same direction: organizations must be able to demonstrate that they can detect, manage, and respond to cyber incidents in a structured and accountable way. A well-prepared incident response capability is no longer optional. It is a core business requirement.
At the same time, frameworks like IEC 62443 for industrial cybersecurity, ISO 27001 for information security management, and the NIST Cybersecurity Framework all emphasize the need for regular testing and continuous improvement of incident response processes. Having documentation on a shelf is no longer enough. Organizations need to prove that their teams can actually perform when it counts.
OUR APPROACH: BUILD. EXERCISE. CONTROL.
CIRT360 brings into standardization our on the job experience and follows a three-phase approach that takes organizations from setting up a structured response team all the way through to measurable, continuous improvement.
Phase 1: Build
A CIRT that is not clearly defined is not truly in control. The Build phase focuses on establishing a structured Cyber Incident Response Team with clearly defined roles and responsibilities, escalation flows, incident classification schemes, and communication structures.
Depending on where your organization stands, the Build phase can range from a foundational setup (covering RACI definitions, basic templates, and alignment workshops) to an extended governance package that includes incident response policies, general regulatory communication templates, and management escalation guidelines. The goal is to make sure your team knows exactly who does what, when, and how.
Phase 2: eXercise
A CIRT that is not exercised is not operational. The Exercise phase puts your response capability to the test through realistic, scenario-based tabletop exercises. These are not theoretical walkthroughs. They introduce real-world pressure, evolving situations, and the kind of uncertainty that teams face during an actual incident.
Exercises are tailored to your specific environment and industry, whether that is manufacturing, healthcare, energy, or critical infrastructure. Each exercise includes a pre-workshop assessment questionnaire and preparation meetings to understand your IT and OT landscape, followed by a custom-designed scenario that reflects real threats relevant to your sector.
Exercises can be run at both the management level and the technical level. Management-level exercises focus on strategic decisions, regulatory obligations, stakeholder communication, and board accountability. Technical-level exercises go deeper into detection and response workflows, IT/OT segmentation decisions, forensics coordination, and containment strategies.
Phase 3: Control
CIRT360 does not end with a workshop. The Control phase is about making sure your response capability keeps improving. After every exercise, you receive a detailed assessment report that evaluates your team's performance across multiple capability domains, combined with a maturity score that gives you a clear, measurable picture of where you stand.
A CAPABILITY, NOT A CHECKBOX
Building a Cyber Incident Response Team, testing it, and tracking its maturity is not a one-time project. It is a discipline organizations return to as threats, teams, and regulations evolve. The Build–eXercise–Control cycle gives that discipline structure, but the real value shows up in the room, during the exercise itself, in what a team discovers about how it actually behaves under pressure.
That is what the rest of this series looks at. Part 2 steps out of the service brochure and into the exercise room: the patterns we keep seeing across energy, water, pharma, and manufacturing sites once the simulated alarm goes off. Part 3 sits down with two of the people at BxC who design and run these exercises, Natalia and Vaishalini, to talk about what still surprises them.
If a ransomware attack hit your systems right now, would your team be ready? CIRT360 is how you find out, before it is the real thing.
