Introducing the IASME Cyber Exercise Baseline scheme

Sep 22, 2026 | Cyber Exercise Baseline

Cyber security helps prevent cyber incidents. Cyber resilience means being prepared to respond if one happens—and giving people the chance to practise making those decisions before they are under pressure.

Cyber Exercise Baseline is IASME’s new entry-level scheme designed to make cyber incident exercising more accessible to smaller organisations and to help more people develop the skills to deliver it.

The scheme provides a structured, facilitated starting point for organisations that are beginning their exercising journey. It also creates a development route for individuals and providers who want to build cyber incident exercising capability within their own organisation or offer it as a service.

What is cyber incident exercising?

A cyber incident response plan sets out who should act, what decisions need to be made and how an organisation will continue operating during and after a cyber incident. But a plan that has never been discussed or tested may not work as expected.

Cyber incident exercising is the process of practising that response in a safe and controlled environment. It gives people an opportunity to explore their roles, test their assumptions and identify practical improvements before a real incident occurs.

Exercising is not a test of an organisation’s technical defences. It is about examining the response: how information is shared, how decisions are made, how business priorities are balanced and how the organisation would recover. It can involve technical teams, but it should also include the wider organisation — such as senior leaders, communications, finance, legal, HR and business continuity teams.

In simple terms, exercising helps organisations build the muscle memory they need to respond when the stakes are high.

The role of the IASME Cyber Exercise Baseline scheme

Cyber incident exercising is relevant to every organisation, not only large enterprises. Smaller organisations can be particularly exposed to the impact of a cyber incident as they often have fewer resources, less specialist expertise and less time available to prepare.

According to the government’s Cyber Breaches Survey, 77% of UK businesses do not have a cyber incident response plan at all. Even where a plan exists, people may not know their responsibilities or understand how the plan would work in practice.

The existing NCSC Cyber Incident Exercising scheme provides a high-quality, assured service involving experienced providers offering a variety of industry and threat landscape-appropriate, bespoke exercises. This is an important option for organisations with mature response plans or more complex requirements. However, some smaller organisations may not yet need, or be ready for, that level of service.

The IASME Cyber Exercise Baseline scheme is intended to provide an accessible starting point. It is designed for organisations that want to begin exercising with a practical, supportive and structured session before progressing to more tailored or advanced exercises as their needs develop.

There is also a need to develop the people who can deliver these services. Individuals and organisations may be interested in cyber incident exercising but lack accessible training, practical experience or a clear route into the field. The IASME Cyber Exercise Baseline scheme is intended to help address that gap.

How will the scheme work?

The IASME Cyber Exercise Baseline scheme is based on facilitated entry-level cyber exercises that will help organisations practise their response to a cyber attack.

Many organisations lack the confidence or experience to run an exercise on their own or turn the discussion into meaningful actions. A trained facilitator can provide structure, guide the conversation, encourage participation from different parts of the organisation and help identify practical next steps.

The scheme has two linked elements: support for participating organisations and development for facilitators and providers.

Support for participating organisations

The scheme will provide an affordable and accessible way for organisations to:

  • Discuss and test their incident response arrangements
  • Identify gaps in their cyber incident response plan
  • Improve understanding of roles and responsibilities
  • Receive practical recommendations for improvement

Where an organisation does not yet have a response plan, the facilitator can use a template plan and self-assessment before the exercise to support the organisation. Following the session, the organisation will receive a simple report outlining what was explored, the gaps identified and the improvements recommended.

A certificate will be issued upon completion of the facilitated cyber exercise and will remain valid for one year. This provides clear evidence to customers and supplier that the organisation has undertaken a cyber exercise within the previous 12 months – an increasingly common requirement for business partners.

Development for facilitators and providers

The scheme is initially open to IASME’s network of Certification Bodies and Assured Service Providers, providing a clear opportunity to develop capability in facilitating cyber incident exercises.

Start with facilitator training

The first step is the Cyber Incident Exercise Facilitator Training Course. This is a two-day, in-person course combining guided learning, group work and practical exercise delivery. No previous experience or technical expertise is required. It is particularly suited to organised, confident communicators who can guide discussions, ask constructive questions and create a safe environment to test decisions and make mistakes.

Participants learn about cyber incidents and incident management, take part in facilitated exercise scenarios and explore the principles of exercise design, development, and evaluation. They will also create an exercise and put it into practice, gaining hands-on experience of facilitating a discussion and capturing lessons.

After the course, candidates complete an assessment focused on the course content and if successful, receive a certificate that provides evidence of their foundational facilitator training.

The course is not affiliated with the NCSC and is intended to help people begin facilitating exercises within their own organisation or start developing the knowledge and experience needed to offer exercising services.

A pathway that can grow with experience

The IASME Cyber Exercise Baseline scheme is intended as a starting point for individuals who want to develop the knowledge and experience needed to build a career in cyber incident exercising.

  • Attend the Cyber Incident Exercise Facilitator Training Course
  • Complete the assessment
  • Receive a digital certificate
  • Begin facilitating entry-level exercises, subject to the relevant IASME requirements
  • Gain practical experience and develop the ability to tailor exercises
  • Progress towards more advanced roles and services as capability grows

In time, experienced facilitators may be able to work towards the IASME Team Lead test and, subject to the usual requirements and assessment process, progress towards the NCSC Cyber Incident Exercising Assured Service Provider scheme.

This creates a route from foundational learning to practical delivery and, potentially, to more advanced professional roles.

What happens next?

If your organisation is considering its first cyber incident exercise, the IASME Cyber Exercise Baseline scheme is intended to provide a practical place to start.

If you are interested in developing facilitation skills or building an exercising service, the facilitator training course offers a route into this growing area of cyber resilience.

The aim is simple: to make cyber incident exercising more accessible, more achievable and more useful for organisations that are ready to begin.

Find out more

To discuss the Cyber Incident Exercise Facilitator Training Course or register your interest in the IASME Cyber Exercise Baseline scheme, contact [email protected].