3.1 Cyber response teams aligned with other response teams internally and externally
- Ensuring the Crisis and Incident Management response framework includes all teams who would be involved in a far-reaching cyber security crisis including the Cyber Incident Response Team, the Crisis Management Team, board and any other response teams internally or externally.
- Ensuring capability exists for events that are extreme or ‘catastrophic’ in nature and that require a significant and coordinated response.
3.2 Robust and integrated scenario-based activities using current and emerging threats
- Utilising scenario-based planning activities to ensure clarity on roles and responsibilities within and between teams and a robust, transparent and defendable decision-making process for all levels of the response.
- Evidence of scenarios designed to uncover vulnerabilities and blind spots, uplift capability and provide assurance to key stakeholders.
3.3 Cyber resilience leadership and embedded critical thinking skills
- Addressing the human elements of cyber resilience by embedding critical thinking into cyber security design and cyber security response teams to enable team-based critical thinking and high-quality decision-making, particularly where there may be incomplete or conflicting information.
3.4 Effective Post Incident Reviews and Cyber Resilience Stakeholder Management
- Reviewing the effectiveness of existing plans, processes, and structures in response to a recent disruption, threat or incident.
- Providing the organisation with learning opportunities by identifying strengths and weaknesses to further improve and continually build cyber resilience.


