Independent Assurance

Programme capabilities, methodology and scope

A crisis-decision simulation for executives at banks, insurers and critical-infrastructure operators, run either inside one organisation or as a cross-sector cohort exercise. This page states exactly what the programme does, what it measures, what it is built on, and — explicitly — what it does not yet do.

It is written for due diligence. Every question a procurement, risk or supervisory reviewer would normally have to ask is answered below, in their words.

Scope and methodology

The programme trains and measures executive decision-making during a crisis. It is not a technical incident-response drill, and it does not teach crisis procedures.

Design basis

Scenario design follows ENISA Threat Landscape incident patterns, with German and EU regulatory timing — GDPR Art. 33 notification windows, supervisory escalation — built into the round clocks. Financial figures use EU-primary sources; global, US-weighted sources are used only as cross-checks and are labelled as such wherever they appear.

Session formats

Single-organisation rehearsal, or a cohort session in which multiple institutions answer the same inject in the same live room. Rounds run from 90 seconds to several minutes; a campaign is three linked rounds. Facilitators set scenario, complexity, clock and executive roster before the session opens.

Who sits in the room

Executive seats — CEO, CFO, COO, CISO, General Counsel, Head of Communications — each with its own authority boundary and its own view of the incident. Counterparties such as press, works councils and customers are simulated and react to what participants actually decide, while regulators, supervisors, law enforcement, CERTs, cloud and outsourcing providers, counsel and auditors can take live external seats, flagged as external and scored separately from the host organisation.

What comes out

A timestamped decision log, a composite score with three component axes, badge findings with published rubrics, a Return on Mitigation euro range, and — for cohort sessions — a Divergence Index showing where the sector does not agree with itself. Weaknesses become tracked corrective actions with owners, deadlines and a retest that must pass before they close. Exports as PDF, PNG and shareable link, in English and German.

Criteria-to-capability mapping

Against the criteria commonly applied to executive crisis-readiness programmes. Partial and not-yet-built rows are stated as plainly as the rest.

Crisis-readiness criteria mapped to platform capabilities
CriterionStatusHow it is covered
Executive-level focusIn the platformEvery seat is a C-suite or executive-committee role — CEO, CFO, COO, CISO, General Counsel, Head of Communications. Participants make decisions; they do not operate tooling.
Realistic crisis simulationIn the platformSeven three-round campaigns built on ENISA Threat Landscape incident patterns. Timed injects, partial intelligence, moving deadlines, and consequences that carry from one round into the next.
Cross-industry collaborationIn the platformMultiple organisations join the same live session room. Every organisation answers the same inject at the same moment; the facilitator console shows where they diverged.
Sector interdependenciesIn the platformShared-vendor, cloud-concentration and supply-chain campaigns are designed so one firm's containment decision changes another firm's exposure inside the same round.
Decision-making under pressureIn the platformConfigurable round clocks (90 s to several minutes), escalating pressure meters, and a scored penalty for both indecision and unconsidered speed.
Individual and joint exercisesIn the platformSingle-organisation runs for internal rehearsal; cohort runs for cross-sector sessions. Both use the same scenario set, so results are directly comparable.
Clear decision rights and escalation thresholdsIn the platformDecisions are role-scoped. Options that exceed a seat's authority require an explicit escalation or a sign-off gate, and unauthorised action is recorded as a governance finding.
Shared operational pictureIn the platformA live Crisis Network map, an intelligence feed with source attribution and signal/noise tiering, stakeholder pressure widgets, and a consequence feed — identical for every participant in the room.
Decision logs and documented assumptionsIn the platformEvery decision is timestamped with the seat that made it, the information available at that moment, and the option not taken. The Return on Mitigation assumptions panel exposes every benchmark, its source, year and region.
Communications with regulators, media, customers, employeesIn the platformA scored disclosure axis. Campaigns include supervisory ultimatums, journalist deadlines, customer-channel failure, works-council and staff-sentiment consequences.
Cyber, operational, financial and physical scenariosPartialCyber, operational/third-party, financial-crime, physical-security and trust/deepfake campaigns are live. A dedicated geopolitical campaign is not yet in the catalogue.
Handling incomplete, conflicting or misleading informationIn the platformIntelligence items are tiered signal / mixed / noise, some unlock further items, and some are wrong. Campaigns include rumour, synthetic media and a supplier actively denying a true finding.
Psychological safety and executive challengeIn the platformA Challenge window in each round lets any seat contest the emerging decision. Dissent raised and dissent ignored are both scored behavioural markers.
Formal pause points to reassess assumptionsIn the platformFacilitator-controlled live pause, plus a per-run 'Call a Colleague' lifeline that stops the clock for a structured reassessment.
After-action reviewIn the platformDebrief Mode: composite score, Outcome / Process / Behavioural breakdown, per-decision drill-down, badge rubrics, and PDF, PNG and shareable-link exports in English and German.
Measures of performanceIn the platformComposite and per-axis scores, cross-organisation Divergence Index, and Return on Mitigation expressed as a sourced euro range against a no-decisive-action baseline.
Interaction with public authorities and emergency servicesIn the platformRegulators, supervisors, law enforcement, sector CERTs, cloud providers, outsourcing partners, external counsel and auditors can hold live seats in a shared session room alongside the executive team, and are flagged as external in the roster. They also appear as scripted counterparties where no real authority is present.
Information-sharing and data-protection protocolsIn the platformA published cross-organisation information-sharing and data-protection protocol covering what is shared, what is never shared, the attribution rule, GDPR legal basis, competition-law guardrails, retention and the participation undertaking — enforced in-platform by the confidentiality gate, invitation-scoped access and org-local versus flagship data separation.
Mutual-aid and resource-sharing arrangementsPartialMutual aid appears inside scenario options and in the cohort recommendation engine, which flags candidates for sector-wide pre-agreed positions. It is exercised, not yet contractualised in-platform.
Diverse perspectives beyond senior executivesNot yet builtThe current roster is executive-only by design. Frontline, SOC-analyst and branch-manager seats are on the roadmap.
Corrective actions with named owners and deadlinesIn the platformA corrective-action register in the facilitator console: each weakness surfaced in a debrief can be opened as an action with a named owner, organisation, severity, deadline and evidence field, tracked through open, in-progress, blocked and closed, with overdue actions flagged.
Follow-up exercises that retest corrected weaknessesIn the platformEvery action carries a retest loop: schedule a follow-up exercise against a named scenario and round, record the composite before and after, and mark the result passed, partial or failed. An action closes only when a retest passes — a deadline alone never closes it.

Scenario catalogue

Seven campaigns, each three linked rounds. Decisions in an earlier round change the situation participants inherit in the next.

Shared-vendor ransomware

Black Ice Clearing

A shared file-transfer vendor is encrypting three institutions at once. Contain, then survive the supervisor and the press.

  1. R1Silent encryption across three institutions, unclaimed
  2. R2A 25-minute supervisory ultimatum on a joint public statement
  3. R3An internal transcript leaks to a national outlet

Insider financial crime

Silent Ledger

A trusted insider has been re-routing settlement instructions for months. The trail runs through people you trust.

  1. R1€31M of altered settlement instructions carrying valid credentials
  2. R2Forensics implicates a control your own team signed off
  3. R3A whistle-blower takes the audit findings to a journalist

Cloud concentration risk

Static Sky

Your primary region and your documented fallback share one provider. When it fails, everything fails together.

  1. R1Primary and fallback degrade simultaneously
  2. R2The supervisor asks why one vendor takes down both paths
  3. R3A customer-impact figure you gave during the outage was wrong

Software supply chain

Glass Chain

A signed update from a trusted supplier is shipping malicious code into your estate. The supplier is still denying it.

  1. R14,100 hosts beaconing from a signed vendor update
  2. R2Whether to break publicly with a vendor threatening to withdraw support
  3. R3Your own clients ask whether you shipped the same component

Volumetric attack and extortion

Red Tide

A volumetric attack is drowning customer channels, with a ransom note and a deadline that keeps moving.

  1. R140% of retail customers offline, 90-minute ransom deadline
  2. R2Attackers shift technique and name your largest clients
  3. R3Service restored, but deposits are leaving and cameras are outside a branch

Physical and cyber convergence

North Gate

A break-in at a co-location site coincides with anomalous admin access. Physical and cyber teams disagree on what happened.

  1. R1Forced entry plus two admin logins, cameras offline for 11 minutes
  2. R2Police want the servers; forensics wants images first
  3. R3Badge logs place your own engineer on site; the union is called

Synthetic media and trust

Paper Moon

A synthetic video of a peer-bank CEO is moving money and markets. No system was breached — only trust.

  1. R1A video call 'from' your CFO authorises €12M at a peer institution
  2. R2Verification against a counterparty that has already paid
  3. R3Rebuilding an authorisation process the market no longer believes

Scoring model

One composite score out of 100, built from three axes. Nothing is scored against a single model answer — scoring follows the consequence state the scenario actually reaches.

Outcome

Did the decision reduce real harm?

Containment achieved, customers restored, loss avoided, regulatory position preserved. Measured against the consequence state the scenario actually reaches, not against a model answer.

Process

Was it decided properly?

Decision rights respected, escalation used when authority was exceeded, intelligence consulted before committing, disclosure clocks observed, assumptions recorded.

Behavioural

How did the team behave under pressure?

Dissent raised and heard, silence from a seat that held relevant information, reversal under pressure without new evidence, speed relative to information available.

Per-axis detail

Decision speed, governance discipline, regulatory disclosure, containment quality, stakeholder communication and executive cohesion are each reported separately, so a strong composite cannot hide a single failing dimension.

Divergence Index

For cohort sessions: the share of participating organisations that did not converge on the same response to the same inject. A high index marks the highest-value candidate for a sector-wide pre-agreed decision; a low index marks something worth writing down as a mutual commitment before the next cycle.

Return on Mitigation methodology

A modelled euro value for loss avoided against a no-decisive-action baseline. It is an indicative planning estimate, not a prediction, and it is never shown as a single point figure.

How the figure is built

A baseline loss is modelled from the scenario profile, then each decision moves it: containment-time change, disclosure posture, operational disruption cost, and penalty exposure adjusted for regulatory mitigation credit. The debrief shows a waterfall from baseline to final modelled loss, one row per decision.

Where the range comes from

The band has two components: the natural variance in the underlying benchmarks, and an explicit widening for every assumption in the model that is not yet backed by a verified EU source. The debrief states both parts and how many unsourced assumptions are widening the range on that specific run.

No invented figures

Where a specific EU-sourced number is not verified, the entry ships as empty and marked "needs sourcing" — visible in the interface and tracked in an admin backlog. No substitute figure is imputed from a non-EU source and presented as European.

Comparability

A locked flagship assumption table is the only basis for cross-organisation comparison. Facilitators may edit an organisation-local table for their own internal debrief; those runs are labelled non-comparable on every export, including the PNG scorecard, and are excluded from cohort aggregates.

Sources

Benchmark sources used by the Return on Mitigation model
SourceRegionUsed for
ENISA Threat LandscapeEUIncident patterns, sector pattern weights, dwell-time curve anchor
BSI — Die Lage der IT-Sicherheit in DeutschlandDECost and incident-frequency figures for the German corporate base
Regulation (EU) 2016/679 (GDPR), Art. 33 and 83EU (legal text)Notification deadline, statutory penalty cap, mitigation credit
EDPB decisions / GDPR Enforcement TrackerEUObserved financial-sector fine levels, not a modelled band
Allianz Risk Barometer / Allianz Commercial claims analysisEUCyber risk ranking, business-interruption share of loss
IBM Cost of a Data Breach / Verizon DBIRGlobal, US-weighted — tagged as suchSupplementary cross-check only; never an unlabelled default

Every benchmark value is displayed in the debrief alongside its source, year and region, never hidden behind a tooltip. Indicative planning estimate, not a prediction.

Live external-stakeholder seats

Regulators, supervisors, law enforcement, sector CERTs, cloud and outsourcing providers, external counsel and auditors can take live seats in a shared session room, marked as external so their contributions are never mixed into the host organisation's own scores.

Who can be invited

Facilitators invite external stakeholders by email into dedicated seats. Each seat has its own briefing view, authority boundary and colour-coded external flag in the roster. The same room therefore contains both the executive team and the real counterparties it would need to coordinate with in a live incident.

Scored separately

External seats are flagged so their actions are never merged into the host organisation's composite score. They can still influence the scenario — a supervisor can issue an ultimatum, a cloud provider can confirm a root cause — but the scoring boundary protects every participant's data.

Corrective-action register & retest loop

Weaknesses surfaced in a debrief become tracked actions with owners, deadlines and evidence. An action closes only when a retest passes — a deadline alone never closes it.

From debrief to action

Any finding from the composite score, a per-axis breakdown or a badge rubric can be opened as a corrective action in the facilitator console. Each action carries a named owner, organisation, severity, deadline and evidence field, and is tracked through open, in-progress, blocked and closed states, with overdue items flagged.

Retest-to-close

Every action carries a retest loop: schedule a follow-up exercise against a named scenario and round, record the composite score before and after, and mark the result passed, partial or failed. The register therefore shows measured improvement, not asserted improvement.

Information-sharing protocol

A published cross-organisation information-sharing and data-protection protocol governs what is shared, what is never shared, and how attribution and retention work.

What it covers

The protocol defines the attribution rule, the GDPR legal basis for processing, competition-law guardrails, retention periods and the participation undertaking every organisation signs. It is enforced in-platform by facilitator-approved access, a confidentiality and ethics acknowledgement before every session, and invitation-scoped session rooms.

Aggregate-only cohort analytics

The Divergence Index reports how organisations split on a given inject, never a named firm's weaknesses. Organisation-local benchmark tables are kept separate from the locked flagship table and never feed cohort aggregation, so runs scored against local assumptions are clearly labelled non-comparable.

Twelve due-diligence questions, answered

The questions a reviewer would otherwise have to send us. Answered here so they do not have to.

1.Which industries and external stakeholders participate in the cross-sector exercise?

Banks, insurers and critical-infrastructure operators occupy live seats in a shared session room. External-stakeholder seats are now live too: regulators, supervisors, law enforcement, sector CERTs, cloud and outsourcing providers, external counsel and auditors can be invited into the same room and are flagged as external in the roster, with their own briefing view. Where no real counterparty is present, journalists, works councils, customers and suppliers still act as scripted counterparties that respond to what participants actually decide.

2.Are regulators, government bodies, emergency services, suppliers or infrastructure providers involved?

Both. They can be seated: the facilitator invites a regulator, supervisor, police liaison, CERT, cloud provider, outsourcing partner, external counsel or auditor by email into a dedicated external seat, marked as external so their contributions are never mixed into the host organisation's own scores. Where no real party attends, they are modelled as active counterparties with their own agendas — supervisory ultimatums, police evidence seizure, a supplier denying a true finding and threatening to withdraw support mid-incident.

3.What types of scenarios are simulated?

Seven three-round campaigns: shared-vendor ransomware, insider financial crime, cloud concentration failure, software supply-chain compromise, volumetric attack with extortion, physical-and-cyber convergence, and synthetic-media trust attack. Each round is a self-contained inject whose consequences carry into the next. A dedicated geopolitical campaign is not yet in the catalogue.

4.How are incomplete, conflicting or deliberately misleading information handled?

Intelligence items are tiered signal, mixed and noise, and carry a named source — treasury operations, external forensics, social listening, a journalist. Some items unlock others only when pulled in the right order; some are simply wrong. Participants never see the full picture, and the scoring rewards recognising which sources were worth trusting under time pressure.

5.Are executives tested on public communication and stakeholder trust?

Yes. Disclosure is a scored axis in its own right. Campaigns force public statements against supervisory deadlines, comment to national press inside ten minutes, correction of a customer-impact figure given wrongly during an outage, and internal communication to staff and works councils.

6.Does the exercise examine decision rights and escalation procedures?

Yes. Options are scoped to the seat. Choosing an option beyond a seat's authority requires an explicit escalation or sign-off gate; proceeding without one is recorded as a governance finding and reduces the Process score. Who escalated, to whom, and how long it took are all in the run log.

7.How is cross-sector information sharing managed legally and securely?

There is a published cross-organisation information-sharing and data-protection protocol: what is shared, what is never shared, the attribution rule, the GDPR legal basis, competition-law guardrails, retention periods and the participation undertaking every organisation signs. It is enforced in-platform — facilitator-approved access, a confidentiality and ethics acknowledgement before every session, invitation-scoped session rooms, aggregate-only cohort analytics (the Divergence Index reports how organisations split, never a named firm's weaknesses), and a locked flagship benchmark table kept separate from organisation-local assumptions that never feed cohort aggregation. Contact details left on the site are captured only with explicit, separately recorded consent, with marketing contact as a distinct opt-in.

8.Are participants required to make documented decisions with assumptions and review triggers?

Every decision is committed explicitly and logged with a timestamp, the deciding seat, the intelligence available at that moment, and the option rejected. The Return on Mitigation assumptions panel shows every benchmark behind the euro figure with its source, year and region, always visible alongside the number.

9.What is included in the after-action review?

Debrief Mode gives the composite score and its Outcome, Process and Behavioural components; a per-round decision drill-down with the counterfactual; earned badges with published rubrics; the Return on Mitigation waterfall from baseline loss to modelled loss; and the full assumptions panel. It exports as PDF, PNG scorecard, and a shareable link, in English and German.

10.Are corrective actions assigned, tracked and retested?

Yes. Any weakness surfaced in a debrief can be opened as a corrective action in the facilitator console with a named owner, organisation, severity, deadline and evidence field, and tracked through open, in-progress, blocked and closed, with overdue actions flagged. Each action carries a retest loop: a follow-up exercise is scheduled against a named scenario and round, the composite score before and after is recorded, and the retest is marked passed, partial or failed. An action closes only when a retest passes — a deadline alone never closes it, so the register shows measured improvement rather than asserted improvement.

11.How is performance measured?

Four ways. Composite score out of 100 with its three component axes. Per-axis scores across decision speed, governance discipline, disclosure, containment quality, stakeholder communication and executive cohesion. Divergence Index — the percentage of a cohort that did not converge on the same answer to the same inject. Return on Mitigation — a euro range for loss avoided against a no-decisive-action baseline, always shown as a range with its uncertainty band and sources.

12.Can the exercise be adapted to regional, regulatory or organisation-specific risks?

Facilitators build rounds from the admin console: scenario, round count, clock length, complexity, participant roster and which executive seats are live. Organisation profile inputs — sector, employee band, records-at-risk band, currency — feed an organisation-local benchmark table used for that firm's own debrief. Runs scored against local assumptions are marked non-comparable and excluded from cross-organisation aggregates. The full interface, scenarios and debrief are available in English and German.

Known gaps and roadmap

Stated deliberately. A readiness programme that hides its own gaps is the wrong supplier for this audience.

  • Contractualised mutual-aid and resource-sharing arrangements, rather than mutual aid exercised inside scenarios.
  • Non-executive seats — SOC analyst, branch manager, frontline operations.
  • A dedicated geopolitical scenario campaign.

The corrective-action register, the retest loop, live external-stakeholder seats and the published information-sharing protocol are now built — the items that turn a well-instrumented simulation into a measurable readiness improvement cycle. The remaining gaps are listed above rather than hidden.