Skip to main content

Starting a Drill

Why drill, how often, and how to set one up.

Regular incident response drills are essential for ensuring your team can execute your playbooks effectively when a real incident occurs. CrownSync Playbooks includes a built-in drill system that lets you simulate incidents, time your response, and generate audit-ready reports that demonstrate your preparedness.

Why Run Drills

Running incident response drills is not merely good practice — it is increasingly a requirement across multiple compliance frameworks and industry standards:

  • ISO 27001— Annex A control A.5.24 (Information Security Incident Management Planning and Preparation) requires that incident response procedures are tested at planned intervals. Drills provide documented evidence of testing.
  • Cyber Essentials Plus (CE+)— While Cyber Essentials focuses on technical controls, CE+ assessors increasingly expect evidence that organisations have tested their incident response capabilities.
  • Cyber insurance— Many cyber insurance policies include conditions requiring regular testing of incident response plans. Failure to demonstrate testing may affect claim outcomes.
  • UK GDPR— Article 32 requires appropriate measures to ensure the ongoing effectiveness of security measures, which includes testing incident response procedures.
  • NIS2 Directive— Operators of essential services must demonstrate that their incident handling procedures are tested and maintained.

How Often to Drill

The National Cyber Security Centre (NCSC) recommends testing your incident response capabilities at minimum once per quarter. However, the appropriate frequency depends on your organisation's risk profile:

  • Quarterly (minimum)— The NCSC baseline recommendation. Rotate through different playbooks each quarter to cover your primary threat scenarios over the course of a year.
  • Monthly— Recommended for organisations in highly regulated sectors (financial services, healthcare) or those with significant personal data processing obligations.
  • After significant changes— Run a drill whenever there is a major change to your IT environment, team structure, or playbook content to validate that procedures still work.
  • After a real incident— Schedule a drill within 30 days of closing a real incident to test the improvement actions identified in the lessons learned review.

NCSC guidance

The NCSC recommends that organisations test their incident response plans regularly and treat drills as learning opportunities rather than pass/fail assessments. The goal is continuous improvement, not perfection. Even a drill that exposes significant gaps is valuable because it identifies those gaps before a real incident does.

Setting Up a Drill

Choose a Playbook

Select which playbook to use as the basis for the exercise. Rotate through different scenarios, prioritise high-risk threats based on your sector, and test recently updated playbooks to validate new content.

Name and Configure the Drill

Give your drill a descriptive name that includes the scenario and date (e.g. “Q1 2026 — Ransomware Tabletop”). Configure options including participants, an optional scenario description, and specific objectives.

Drill setup showing playbook selection and drill name
Select a playbook and name your drill before starting the timed exercise.

Set Participants and Observers

Select which team members will participate. Non-participants can be assigned as observers who watch the drill and note areas for improvement.

Start the Drill

Click Start Drill to begin. The timer starts and all participants are notified. Work through the playbook phases as you would during a real incident.

Assign observers

Assign one or more team members as observers rather than participants. Observers watch the drill without intervening and note areas for improvement. Their independent perspective is invaluable during the post-drill review and is included in the drill report.

Was this page helpful?