1.Which industries and external stakeholders participate in the cross-sector exercise?
Banks, insurers and critical-infrastructure operators occupy live seats in a shared session room. External-stakeholder seats are now live too: regulators, supervisors, law enforcement, sector CERTs, cloud and outsourcing providers, external counsel and auditors can be invited into the same room and are flagged as external in the roster, with their own briefing view. Where no real counterparty is present, journalists, works councils, customers and suppliers still act as scripted counterparties that respond to what participants actually decide.
2.Are regulators, government bodies, emergency services, suppliers or infrastructure providers involved?
Both. They can be seated: the facilitator invites a regulator, supervisor, police liaison, CERT, cloud provider, outsourcing partner, external counsel or auditor by email into a dedicated external seat, marked as external so their contributions are never mixed into the host organisation's own scores. Where no real party attends, they are modelled as active counterparties with their own agendas — supervisory ultimatums, police evidence seizure, a supplier denying a true finding and threatening to withdraw support mid-incident.
3.What types of scenarios are simulated?
Seven three-round campaigns: shared-vendor ransomware, insider financial crime, cloud concentration failure, software supply-chain compromise, volumetric attack with extortion, physical-and-cyber convergence, and synthetic-media trust attack. Each round is a self-contained inject whose consequences carry into the next. A dedicated geopolitical campaign is not yet in the catalogue.
4.How are incomplete, conflicting or deliberately misleading information handled?
Intelligence items are tiered signal, mixed and noise, and carry a named source — treasury operations, external forensics, social listening, a journalist. Some items unlock others only when pulled in the right order; some are simply wrong. Participants never see the full picture, and the scoring rewards recognising which sources were worth trusting under time pressure.
5.Are executives tested on public communication and stakeholder trust?
Yes. Disclosure is a scored axis in its own right. Campaigns force public statements against supervisory deadlines, comment to national press inside ten minutes, correction of a customer-impact figure given wrongly during an outage, and internal communication to staff and works councils.
6.Does the exercise examine decision rights and escalation procedures?
Yes. Options are scoped to the seat. Choosing an option beyond a seat's authority requires an explicit escalation or sign-off gate; proceeding without one is recorded as a governance finding and reduces the Process score. Who escalated, to whom, and how long it took are all in the run log.
7.How is cross-sector information sharing managed legally and securely?
There is a published cross-organisation information-sharing and data-protection protocol: what is shared, what is never shared, the attribution rule, the GDPR legal basis, competition-law guardrails, retention periods and the participation undertaking every organisation signs. It is enforced in-platform — facilitator-approved access, a confidentiality and ethics acknowledgement before every session, invitation-scoped session rooms, aggregate-only cohort analytics (the Divergence Index reports how organisations split, never a named firm's weaknesses), and a locked flagship benchmark table kept separate from organisation-local assumptions that never feed cohort aggregation. Contact details left on the site are captured only with explicit, separately recorded consent, with marketing contact as a distinct opt-in.
8.Are participants required to make documented decisions with assumptions and review triggers?
Every decision is committed explicitly and logged with a timestamp, the deciding seat, the intelligence available at that moment, and the option rejected. The Return on Mitigation assumptions panel shows every benchmark behind the euro figure with its source, year and region, always visible alongside the number.
9.What is included in the after-action review?
Debrief Mode gives the composite score and its Outcome, Process and Behavioural components; a per-round decision drill-down with the counterfactual; earned badges with published rubrics; the Return on Mitigation waterfall from baseline loss to modelled loss; and the full assumptions panel. It exports as PDF, PNG scorecard, and a shareable link, in English and German.
10.Are corrective actions assigned, tracked and retested?
Yes. Any weakness surfaced in a debrief can be opened as a corrective action in the facilitator console with a named owner, organisation, severity, deadline and evidence field, and tracked through open, in-progress, blocked and closed, with overdue actions flagged. Each action carries a retest loop: a follow-up exercise is scheduled against a named scenario and round, the composite score before and after is recorded, and the retest is marked passed, partial or failed. An action closes only when a retest passes — a deadline alone never closes it, so the register shows measured improvement rather than asserted improvement.
11.How is performance measured?
Four ways. Composite score out of 100 with its three component axes. Per-axis scores across decision speed, governance discipline, disclosure, containment quality, stakeholder communication and executive cohesion. Divergence Index — the percentage of a cohort that did not converge on the same answer to the same inject. Return on Mitigation — a euro range for loss avoided against a no-decisive-action baseline, always shown as a range with its uncertainty band and sources.
12.Can the exercise be adapted to regional, regulatory or organisation-specific risks?
Facilitators build rounds from the admin console: scenario, round count, clock length, complexity, participant roster and which executive seats are live. Organisation profile inputs — sector, employee band, records-at-risk band, currency — feed an organisation-local benchmark table used for that firm's own debrief. Runs scored against local assumptions are marked non-comparable and excluded from cross-organisation aggregates. The full interface, scenarios and debrief are available in English and German.