Recently I spent half a day taking part in a Cyber Attack Hydra simulation at the University of Lancashire (where I undertook my MSc Agile Leadership Studies). I went expecting to learn more about cyber security. Instead, I found myself thinking much more deeply about leadership, governance and decision making. The event was kindly funded by the Office of the Lancashire Police and Crime Commissioner, with monies recovered through the Proceeds of Crime Act.
We often talk about cyber resilience as though it is a technical challenge. We discuss firewalls, backups, monitoring tools, patching regimes and cyber awareness training. All of those things matter. However, sitting in a room with a cyber incident unfolding in front of me highlighted something that is easy to overlook. Technology rarely creates the biggest challenge during a major incident. People do.
Just as service excellence comes from continual improvement, cyber resilience comes from continual practice.
Plans Are Not Practice
Most organisations have plans.
We have incident response plans, business continuity plans, communication plans, risk registers, insurance policies and governance frameworks. We invest significant effort creating them, reviewing them and storing them in places where we can find them when needed.
What we do less often is practise using them.
There is a huge difference between reading a document and applying it under pressure. It is one thing to agree a process around a meeting table. It is another to follow that process when information is incomplete, time is limited and every decision appears to carry risk.
The simulation brought that difference into sharp focus.
The Hard Questions
What struck me was how quickly the conversation moved away from technology.
The difficult decisions were not about servers or software. They were about people.
- Who needs to know?
- What do we tell staff?
- What should customers hear?
- At what point do we communicate externally?
- Who has the authority to make a decision?
- What level of risk are we willing to accept?
- How do we balance operational continuity against protecting information?
These are leadership questions rather than technical questions. They sit at the intersection of governance, communication, customer service, compliance and organisational culture.
A successful cyber response depends on far more than technical expertise.
The Value of Different Perspectives
One of the most valuable parts of the experience was listening to others.
People approached exactly the same scenario from very different viewpoints. Some prioritised customers. Some focused on operational continuity. Others concentrated on communications, compliance or organisational reputation.
Nobody was necessarily wrong.
In fact, the exercise reinforced something I have long believed. Better decisions often come from bringing together different experiences and different perspectives, rather than relying on a single expert voice.
The discussion that followed the decision making was often more valuable than the decision itself.
Decision Making Under Pressure
As someone involved in IT service management, governance and data protection, I found the emphasis on rationale particularly interesting.
The exercise encouraged participants to record not just what they decided, but why they decided it.
That matters.
In reality, we are rarely judged solely on outcomes. We are often judged on whether our decisions were reasonable based on the information available at the time. Good governance is not about always making the perfect decision. It is about demonstrating a clear thought process, understanding the risks and being able to explain the reasoning behind the actions taken.
That principle applies whether we are responding to a cyber incident, handling a data breach or navigating a major service disruption.
Where ITIL and SDI Come In
The experience also reinforced something that sits at the heart of both ITIL and the Service Desk Institute‘s guidance. Service management is ultimately about creating value through people processes and technology.
We often focus heavily on the process and technology elements but major incidents quickly expose the importance of the human side Collaboration communication leadership risk based thinking and continual learning are not just nice-to-have skills They are essential capabilities The Hydra simulation felt like a practical exercise in many of the behaviours that ITIL and SDI encourage It demonstrated that service excellence is not proven when everything is working as expected It is proven when an organisation faces uncertainty works together effectively and makes sound decisions under pressure.
ITIL’s Information Security Practice Guide includes “Exercising and testing information security management plans” as one of the four core Practice Success Factors.
It explicitly states:
“Untested plans rarely work as intended, if they work at all. Therefore, testing is a critical part of the overall information security management practice.”
The guide goes on to say that:
“Exercises should be conducted at planned intervals and whenever significant changes occur in the policies, plans, and controls.”
A Safe Place to Learn
Perhaps the most powerful aspect of the Hydra approach is that it creates a safe environment for difficult conversations.
- No real customers are affected.
- No real systems are compromised.
- No real reputational damage occurs.
Yet the experience is realistic enough to expose assumptions, challenge thinking and create genuine reflection.
It allows people to learn lessons before those lessons become expensive.
That feels increasingly important in a world where incidents are becoming more frequent, more complex and more visible.
Building Resilience Before You Need It
The biggest lesson I took away from the day was that resilience is not built during a crisis.
It is built beforehand.
It is built through conversations, exercises, simulations and shared experiences. It is built when teams challenge each other respectfully, explore different options and become comfortable making decisions together.
- When an incident occurs, organisations do not suddenly discover resilience.
- They reveal the resilience they have already developed.
- Technology remains important. Processes remain important. Plans remain important.
But if the day taught me anything, it is that resilience ultimately comes down to people, relationships and the quality of the decisions we make when the pressure is on.
My 1TakeOn
Many organisations spend years building plans for cyber incidents but very little time rehearsing them. The real test of resilience is not whether the plan exists. It is whether people can work together, think clearly and make good decisions when the unexpected happens. Practising those skills before a crisis may be one of the most valuable investments an organisation can make.

