Cyberattack simulation for companies: the complete guide
October 7, 2026 · 5 min read · Also in Spanish
What a cyberattack simulation is, which kind you need, how to prepare and run one with your executive team, and what evidence it should leave.
A cyberattack simulation is a rehearsal in which the people who would respond to a real attack (leadership, security, legal, finance and communications) make decisions on a credible scenario, against the clock, without touching any system. It shows, before an attacker does, who decides what, with which information and how fast.
This guide covers the kinds of simulation, which one your company needs, how to prepare and run it, and what should be on paper when it ends.
What a cyberattack simulation is
It's a decision exercise, not a technical test. A facilitator presents what's happening ("the billing servers show a ransom note") and each person decides what to do from their role. The situation then moves on according to what was decided.
It's also called a tabletop exercise (TTX), a cyber crisis simulation or a cyber drill. They are the same thing: a rehearsal in a room or a video call, not on the network.
Kinds of simulation: which one you need
- Executive tabletop (CEO, CISO, CFO, legal, communications): tests the business calls, such as stopping operations, paying or not, and notifying regulators and customers.
- Technical tabletop (incident response team, IT, suppliers): tests detection, containment and restore.
- Red team / purple team (offensive and defensive security): tests whether a real attack is detected and stopped.
- Phishing simulation (all staff): tests whether people click.
The first two are tabletop exercises; the last two are technical tests. For leadership, the executive tabletop teaches the most: the expensive decisions (halting billing, paying a ransom, notifying a regulator) aren't made by IT.
How to prepare one in a week
- Set one concrete goal. For example: "do we know who can authorize shutting down operations, and how fast?"
- Pick a scenario that could happen to you. Ransomware, a data breach, a fake voice or video of the CEO, a supplier compromise, DDoS extortion or leaked cloud keys. Use your systems, your customers and your regulators.
- Invite the people who actually decide. If the CFO isn't there, nobody tests the payment decision.
- Write two to four events. Each with questions per role and realistic options. No option should be obviously right.
- Set the rules. No blame, a time limit per decision, and private answers before the discussion, so nobody follows the most senior person.
- Prepare the record. Time of each decision, who answered, who missed it.
For a complete scenario to start with, see the ransomware tabletop for the board or the CEO deepfake scenario.
How to run it
One hour fits three events. For each one:
- Present the situation in two or three sentences, with concrete facts (time, systems, figures).
- Let people decide privately. Each role answers before seeing what the others chose.
- Reveal at once and discuss the differences: that's where disagreements nobody knew about show up.
- Make the next event depend on what was decided. If nobody told legal, the journalist calls sooner.
What you should have when it ends
A good simulation leaves evidence, not impressions:
- The decision log, with time, role and rationale.
- Missed or late decisions.
- The impact of each decision on continuity, security, legal exposure, trust and recovery.
- Control coverage: which requirements of your framework (ISO 27001, SOC 2, NIST, PCI DSS, NIS2, DORA) were exercised and which showed a gap.
- An action plan with an owner and a date for each gap.
That report is what an auditor will ask for. The tabletop exercise guide details what each framework expects.
What the rules ask for
Many standards expect an incident response plan that has been tested: PCI DSS every 12 months, DORA at least yearly with cyber-attack scenarios, and NIS2 expects incident and crisis management plus training for management bodies. We cover them in detail in the NIS2 tabletop exercise and DORA scenario testing guides.
A simulation certifies nothing on its own: your auditor or authority decides what meets a requirement. But without a documented exercise, it's hard to show the plan works.
Frequently asked questions
How often should we run a cyberattack simulation?
At least once a year, and again after big changes: a merger, a new critical system, a leadership change or a real incident. Use a different scenario each time.
How long does it take?
A useful executive simulation takes 45 to 90 minutes. Longer is tiring; shorter leaves no time to decide.
Do we need a consultancy?
Not necessarily. A consultancy brings an experienced facilitator; a platform brings ready scenarios, timed decisions and the report. Many companies combine both.
Does it work remotely?
Yes. With private decisions per role, remote works as well as a room, and leaves a better record.
Critios is a platform for running cyberattack simulations with your executive team: 13 ready scenarios (or one drafted with AI for your company), private decisions per role revealed at once, escalations that follow what the team chose, and a report with the decision log and control coverage. Try the demo or simulate your crises with us.
