All insights
2026-03-05·Relcanto team·Resilience

Building incident response muscle memory

Why regular cyber simulations matter — and how to make them useful rather than theatrical.

Incident response plans fail in the moment for predictable reasons: nobody knows who decides, contact details are stale, the communications approvals path is undefined, and the technical team is improvising while the executive team is waiting for a briefing that nobody is writing.

Make the scenario uncomfortable

A useful simulation puts real decisions in front of real decision makers. Ransomware with encrypted backups. A third-party breach where your data is in someone else's environment. An insider incident involving a senior employee. If everybody leaves the room agreeing it went well, the scenario was too kind.

Exercise the seams

Most failures happen between teams rather than inside them: security to IT, IT to legal, legal to communications, communications to the board, and the whole organisation to its regulators, insurers and customers. Design the exercise so those handovers are tested explicitly, including out of hours and when a key person is unavailable.

Close the loop

Every exercise should produce a short list of owned actions with dates, and the next exercise should open by reviewing them. A cadence of one executive tabletop and two or three technical exercises a year builds genuine muscle memory; an annual box-ticking session builds a false sense of readiness.