Knowledge · Glossary

Cyber Crisis Exercise Glossary

From inject to reporting chain: the terms that keep coming up in crisis exercises, reporting duties and debriefs, precisely explained, sorted alphabetically. Every entry is directly linkable and points onward to where the topic goes deeper.

B

BCM (Business Continuity Management)

Business continuity management (BCM) is the discipline of keeping critical business processes running through a crisis, or restarting them in a controlled order: impact analyses, recovery priorities, emergency plans, and exercises that put all of it to the test. Germany’s reference is BSI Standard 200-4. NIS2 turns BCM into an obligation: Article 21 of the directive (§30 BSIG in Germany) explicitly lists business continuity and crisis management among the required risk-management measures.

BSI Standard 200-4

BSI Standard 200-4 is the German authorities’ reference for business continuity management: it describes how organisations build and run a BCM system, from emergency preparedness to crisis management. The IT-Grundschutz programme itself insists on rehearsal: its emergency-management online course dedicates an entire chapter 8, “Notfälle üben” (rehearsing emergencies), to exercising. Exercise evidence from a documented debrief drops straight into 200-4 documentation, exactly where supervisors expect to see a lived BCM.

BSIG

The BSIG is the German act on the Federal Office for Information Security (BSI), the legal home into which NIS2 was transposed via the NIS2UmsuCG. Three sections shape day-to-day practice: §30 requires risk-management measures including business continuity and crisis management, §32 sets the reporting chain to the BSI (24 h/72 h/1 month), and §38 obliges executive management personally to approve measures, oversee their implementation and attend training regularly.

C

CISO (Chief Information Security Officer)

The CISO (chief information security officer) owns an organisation’s information-security strategy: risks, measures, budgets and the reporting line into executive management. In an incident, the CISO is the hinge between the technical picture and business decisions. Important under NIS2: management accountability cannot be delegated to the CISO: in Germany, §38 BSIG places approval, oversight and training duties personally on executive management.

Crisis Team (Krisenstab)

The crisis team (German: Krisenstab) is the temporary leadership body that steers an organisation through a severe incident: typically executive management, IT and security, legal, communications and the affected business units, with defined roles, deputies and alerting paths. It concentrates decisions that are spread across many shoulders in normal operations. Whether it holds is proven under pressure, not on the org chart: which is why it is the core participant of every tabletop exercise.

D

Debrief

The debrief is the structured evaluation after an exercise: what happened when, who decided what on which information, where the gaps were, and which actions follow from them. A good debrief turns a feeling (“that went okay”) into a defensible finding. Verdus Cyber generates the package automatically: a timeline with decision timestamps, findings and an action list: usable as evidence towards supervisors, auditors and your own board.

DORA

DORA, Regulation (EU) 2022/2554 on digital operational resilience, applies exclusively to financial entities and critical ICT third-party providers, and has applied since 17 January 2025. It mandates digital operational resilience testing including scenario-based tests (Articles 25/26) and brings its own reporting chain: initial report 4 hours after an incident is classified as major, at the latest 24 hours after awareness, intermediate report at 72 hours, final report after one month.

Double Extortion

Double extortion is a two-pronged shakedown: attackers not only encrypt systems, they first exfiltrate sensitive data and threaten to publish it. Even a perfect backup offers no protection against that second threat, and the incident almost inevitably becomes a data-protection and communications case with notification duties of its own. In exercises, double extortion forces exactly the trade-offs between legal exposure, reputation and business that dominate real incidents.

E

EDR (Endpoint Detection & Response)

EDR (endpoint detection and response) monitors endpoints (servers, laptops, workstations) for suspicious behaviour, records activity and enables responses such as isolating an affected machine. Unlike classic antivirus, EDR detects behavioural patterns, not just known signatures. In crisis exercises, EDR typically appears as the source of the first alerts, and as a tool whose findings the crisis team has to interpret and prioritise correctly while the clock is running.

F

Facilitator (Moderator)

The facilitator (German: Moderator) runs a crisis exercise from the controller seat: releasing injects, pacing the pressure, keeping the scenario credible and stepping in when the exercise drifts away from its learning objectives. Good facilitation does not replace scoring, it enables it, by making decisions visible and documentable instead of judged by gut feel. Verdus Cyber separates the controller view from the participant view, so exercise control can steer without showing its hand.

G

GDPR Breach Notification (Art. 33/34)

The GDPR carries its own notification duty for personal-data breaches: under Article 33, the competent supervisory authority must be notified without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Article 34 additionally requires informing the affected persons where a high risk is likely. That clock runs in parallel with the NIS2 reporting chain: one more reason to rehearse both strands together.

I

Incident Response

Incident response (IR) is the organised handling of a security incident: detect, assess, contain, eradicate, recover, and learn from the incident afterwards. IR is primarily the technical-operational layer of incident handling; crisis management by the crisis team sits above it as soon as business operations, communications and reporting duties are affected. How long that road can be is shown by IBM’s Cost of a Data Breach 2025: 241 days on average to identify and contain a breach.

Inject

An inject is a single stimulus that exercise control feeds into a running crisis exercise: a SOC escalation, a press enquiry, a call from your biggest customer, a reporting deadline starting to tick. Injects move the scenario forward, create time pressure and force the crisis team to decide rather than debate. Verdus Cyber ships 65+ ready-made injects across 20+ categories that escalate live in the browser and react to the decisions the team takes.

K

Kill Chain

The cyber kill chain is a phase model of an attack: from reconnaissance through initial access and lateral movement to the final impact: encryption or data theft. For exercises it is a useful script skeleton: injects can be staged along the phases, so the crisis team experiences how an attack unfolds over hours instead of treating it as a single event. The techniques within each phase are described in far more detail by MITRE ATT&CK.

KRITIS

KRITIS is the German term for critical infrastructure: organisations whose failure would cause significant supply shortages or endanger public safety, in energy, water, healthcare or digital infrastructure, for example. KRITIS operators are regulated under the BSIG; energy utilities additionally face §11 EnWG and the IT security catalogue of the Federal Network Agency (BNetzA). With NIS2, cyber regulation now reaches far beyond the classic KRITIS circle into the broader economy.

M

MITRE ATT&CK

MITRE ATT&CK is a freely available, continuously maintained knowledge base of real-world attacker tactics and techniques, from initial access to exfiltration. The matrix organises attacks into tactics (why a step is taken) and techniques (how). Defenders use it to align detection, response and exercise scenarios with observed adversary behaviour rather than guesswork. In Verdus exercises, ATT&CK is one of the frameworks debrief scoring is mapped to: alongside NIST CSF, ISO 27001, DORA and NIS2.

N

NIS2

NIS2 is the EU cybersecurity directive (EU) 2022/2555, transposed in Germany by the NIS2 implementation act (NIS2UmsuCG), in force since 6 December 2025. The BSI estimates roughly 29,500 companies in scope in Germany alone, split into essential and important entities. The core duties: risk management including crisis management, a staged incident-reporting chain to the authority, and personal approval, oversight and training obligations for the management body.

P

Playbook / Runbook

A playbook describes how an organisation responds to a specific incident type, ransomware or data exfiltration, say: roles, decision points, communication paths, reporting duties. A runbook is its more operational sibling: concrete, often technical step-by-step procedures for a single system or task. Both are only as good as their last rehearsal: whether a playbook holds under time pressure, and whether deputies even know it exists, only shows in an exercise.

R

Ransomware

Ransomware is malware that encrypts systems or data and demands payment for their release, today usually combined with data theft and a publication threat (double extortion). According to Sophos’ State of Ransomware 2024, 59% of organisations were hit. For crisis teams it is the reference scenario: pay or refuse, internal and external communications, reporting duties, recovery order. Our free simulation lets you feel one minute of that pressure yourself.

Readiness Score

The readiness score condenses a crisis team’s performance in an exercise into a comparable result: Verdus Cyber scores every timestamped decision across eight competencies and maps the profile to frameworks such as NIST CSF, ISO 27001, MITRE ATT&CK, DORA and NIS2. Instead of a gut feeling you get a board-ready readiness profile that shows strengths and where to invest next. Re-running the same scenario months later makes progress visible as a delta.

Reporting Chain (24 h / 72 h / 1 month)

The NIS2 reporting chain (§32 BSIG in Germany) requires three staged notifications of significant incidents to the authority: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. The clock starts at awareness, not at recovery. Teams that only work out on the day who reports, and who holds the portal credentials, lose exactly the hours that matter. Verdus exercises ship dedicated, timestamped reporting-chain injects for precisely this.

RTO / RPO

RTO (recovery time objective) and RPO (recovery point objective) are the two core recovery metrics: the RTO states how quickly a process or system must be available again after an outage; the RPO states how much data loss (measured as the time span since the last backup) is acceptable at most. Both belong in BCM and are set by the business, not by IT alone. Whether the assumptions are realistic shows up in an exercise, not in a spreadsheet.

S

Scenario

The scenario is the narrative frame of a crisis exercise: the starting situation, attacker behaviour, affected systems and the chain of events along which injects are delivered. A good scenario is plausible for your own sector and leaves the crisis team genuine room to decide, instead of quizzing them along a pre-drawn path. Verdus Cyber publishes nine sector-specific scenarios, freely accessible without an email gate and with a print function for your own exercise.

SIEM (Security Information & Event Management)

A SIEM (security information and event management system) collects and correlates security-relevant events from across the IT estate (logins, network traffic, alerts), surfacing attacks that would look harmless on any single system. It is the SOC’s central situational-awareness tool. In exercises, the SIEM provides the raw material for early injects: isolated anomalies the crisis team has to assemble into a coherent picture while facts are still scarce.

SOC (Security Operations Center)

The SOC (security operations center) is the unit that monitors, triages and escalates security events around the clock, run in-house or bought as a service. In a real incident it is usually the first to raise the alarm: the decisive minutes pass between the SOC alert and the crisis team convening. Exactly that interface (when the SOC escalates, to whom, and with how much detail) therefore belongs in every serious crisis exercise.

T

Tabletop Exercise (TTX)

A tabletop exercise (TTX) is a structured rehearsal of a severe cyber incident, run around the table: the crisis team works through a realistic scenario and takes the decisions the real day would demand, without touching production systems. What gets tested is people, roles, decision paths and communication under uncertainty, not the technology. Modern platforms replace the slide deck with live, escalating injects on a running clock and record every decision for the debrief.

Terms clarified. Now rehearse them.

In thirty minutes we will show you how injects, scenarios and debriefs combine into a defensible exercise for your organisation.