Sample debrief, illustrative output
This is a pre-rendered example of what your team sees after running an exercise. The decisions, scoring, costings and runbook below are real outputs from a representative ransomware run. Sign up to run your own scenario and download the full debrief pack.
Solid outcome with refinements
Outcome: Good outcome. Decision quality: sound (63/100). These are two different measures, the outcome is how the scenario ended, decision quality is how your team reasoned under pressure; every scenario is winnable and losable regardless of the calls made.

Solid outcome with refinements
What happened?
The team made defensible calls under pressure with manageable downside. (Path taken: Full network isolation → Internal command, external support on standby → Notify regulator, manage legal internally → Proactive multi-channel communications → Safety-first prioritisation with mutual aid → Full rebuild with independent security review.)
What changed, and where it left you
Cumulative gains on threat containment (+40) and a final public trust of 72% put you on this outcome path.
What changed across the exercise
Every decision you made added to or took away from each measure. Where each one finished (healthy, strained or critical) shapes how the exercise is rated.
| Metric | Start → end | Total losses | Total gains | Net | Final band |
|---|---|---|---|---|---|
| Public trust | 60% → 72% | −3 | +19 | +12 | Healthy (≥70%) |
| Operational capacity | 80% → 75% | −17 | +12 | -5 | Healthy (≥70%) |
| Threat containment | 40% → 80% | 0 | +40 | +40 | Healthy (≥70%) |
Decisions that moved the needle
- +6#3 Notify the regulator within the 72-hour window
- +5#5 Issue a holding statement now, full statement at 17:00
- +4#4 Refuse to pay; rebuild from verified backups
- +12#6 Phased restoration with continuous monitoring
- -10#2 Disconnect the affected segment from the network
- -5#4 Refuse to pay; rebuild from verified backups
- +14#2 Disconnect the affected segment from the network
- +10#4 Refuse to pay; rebuild from verified backups
- +8#1 Treat as a credible incident immediately
Where this left the team
- Public trust ended at 72% (healthy (≥70%)) — net +12 from 60%.
- Operational capacity ended at 75% (healthy (≥70%)) — net -5 from 80%.
- Threat containment ended at 80% (healthy (≥70%)) — net +40 from 40%.
How your decisions moved the situation
tick mark = starting valueWhat did we decide?
How your choices produced the decision-quality score
Each decision is scored on rigour, outcome and confidence calibration (the same model used throughout this debrief and in every export), combined into a 0-100 total.
| # | Decision | Choice | Risk | Quality | Rating |
|---|---|---|---|---|---|
| 1 | Suspicious email reported by finance team | A: Treat as a credible incident immediately | low | 63 | sound |
| 2 | Encrypted files spreading on the file server | B: Disconnect the affected segment from the network | medium | 60 | sound |
| 3 | Regulator notification window opens | A: Notify the regulator within the 72-hour window | low | 59 | sound |
| 4 | Attacker demands ransom in cryptocurrency | C: Refuse to pay; rebuild from verified backups | medium | 64 | sound |
| 5 | Press desk asks for a statement | B: Issue a holding statement now, full statement at 17:00 | low | 62 | sound |
| 6 | Service restoration vs full security review | A: Phased restoration with continuous monitoring | low | 67 | sound |
This is the same decision-quality model used in the scoreboard below and in every PDF, Word and PowerPoint export, there is a single source of truth for decision quality across the debrief.
Decision timeline
When each call was made, how long it took, and which choices drove the biggest swings. Highlighted rows are the key calls.
| # | Elapsed | Took | Decision | Risk | Net impact | Conf. |
|---|---|---|---|---|---|---|
| 1 | 04:00 | 04:00 | Treat as a credible incident immediately | Low | +6 | 4/5 |
| 2 | 12:00 | 08:00 | Disconnect the affected segment from the network | Medium | +1 | 4/5 |
| 3 | 20:00 | 08:00 | Notify the regulator within the 72-hour window | Low | +8 | 5/5 |
| 4 | 30:00 | 10:00 | Refuse to pay; rebuild from verified backups | Medium | +9 | 4/5 |
| 5 | 40:00 | 10:00 | Issue a holding statement now, full statement at 17:00 | Low | +5 | 4/5 |
| 6 | 55:00 | 15:00 | Phased restoration with continuous monitoring | Low | +22 | 5/5 |
#2 at 12:00, “Disconnect the affected segment from the network” (+1 net, 27 total swing)
#6 at 55:00, “Phased restoration with continuous monitoring” (+22 net, 22 total swing)
#4 at 30:00, “Refuse to pay; rebuild from verified backups” (+9 net, 19 total swing)
6 decisions over 55:00, averaging 09:10 per call. 6 of 6 decisions had a net positive impact on the headline metrics. The quickest call (#1, 04:00) was "Treat as a credible incident immediately"; the longest deliberation (#6, 15:00) was "Phased restoration with continuous monitoring". The biggest swings came from #2, #6, #4 — these are the calls that moved the headline metrics most.
Total crisis cost
Based on sector benchmarkScale: Mid-market · Eight categories of exposure modelled from your final metrics, sector, scenario type and time on incident. Heuristic estimates intended to provoke debrief discussion, not actuarial figures.
mostly immediate cash burn, 86% of the cash-vs-trust split lands in the first hours and days. The single biggest line is direct response (decisions).
≈ 0.8% of annual revenue, a material but recoverable hit.
Sum of the 6 decisions the team committed to during the exercise.
Which committed decision do you think was the best value for money, and which the worst?
Were any of these spends avoidable with earlier action?
How this £ was calculated
- Decisions committed:
- 6
- Sum of decision costs:
- £350,500
- Scale band:
- Mid-market
Incident response retainer, forensic investigation, and system restoration — sized by containment gap (0%) and incident type.
Which technical debt got exposed by this incident?
What would the team rebuild differently if budget were no object?
How this £ was calculated
- Technical baseline:
- £240k
- Containment factor (live):
- 32%
- Containment gap (final):
- 0%
- Scenario technical weight:
- 1.50×
External comms agency, media monitoring, and paid recovery campaigns to restore brand trust over 6–12 months.
Which moment in the exercise did the most reputational damage?
Was there a missed opportunity to take control of the public story?
How this £ was calculated
- Baseline budget:
- £150k
- Trust damage:
- 0%
- Scenario reputation weight:
- 1.20×
Remaining categories (3) · £71k
~31 staff × 13h overtime, plus employee assistance and projected turnover replacement costs.
Did anyone check on the responders' welfare during the exercise?
Who was running on adrenaline by the end, and what's the plan for them next time?
How this £ was calculated
- Affected staff:
- 31
- Overtime hours:
- 13 h
- Loaded hourly rate:
- £65/h
- Overtime cost:
- £27k
- EAP / counselling:
- £25k
- Turnover risk:
- £0
- Scenario welfare weight:
- 1.00×
Estimated 15% increase on cyber/crisis cover at next renewal (baseline £120k/yr).
Do you actually know what your cyber policy excludes?
Would this incident trigger a premium reset at your next renewal?
How this £ was calculated
- Baseline cyber premium:
- £120k/yr
- Uplift:
- 15%
- Worse of containment gap / trust damage:
- 0%
Approx under 0.1 days of degraded operations at £300k/day, scaled by your final operational capacity (75%).
What would have brought operations back online faster?
Did anyone own the call to degrade or restore service, or did it drift?
How this £ was calculated
- Daily revenue:
- £300k/day
- Ops damage:
- 5%
- Downtime days:
- under 0.1 days
- Time on incident:
- 55.0 min (0.92 h)
Cost accrual timeline
Cumulative £ per category, minute-by-minute, replaying each decision at the time you actually committed to it. As containment improves, the per-minute crisis bleed slows and category curves flatten.
- #1 · 4mTreat as a credible incident immediately+8 containment
- #2 · 12mDisconnect the affected segment from the network+14 containment
- #3 · 20mNotify the regulator within the 72-hour window+2 containment
- #4 · 30mRefuse to pay; rebuild from verified backups+10 containment
- #5 · 40mIssue a holding statement now, full statement at 17:000 containment
- #6 · 55mPhased restoration with continuous monitoring+6 containment
Per-decision response cost (6)
What did we do well?
What you did well
The judgement calls your team made under pressure that moved things in the right direction, and the worse outcomes those calls quietly avoided.
Avoided outcomes
The worst-case consequences your decisions prevented, based on the alternative paths you didn't take and where the metrics finished.
Avoided a collapse of the overall position
high severityWorst case prevented: If these measures had fallen below 20%, the incident would have run the organisation rather than the other way round: wider compromise, the narrative set by others, and recovery starting from zero.
Instead you: You finished with containment at 80%, public trust at 72% (started at 60%), operational capacity at 75%, keeping enough control to run a structured response.
What should we learn?
Lessons learned
Review any decision where resilience was traded for speed and check the trade was deliberate.
Document what worked so it can be repeated in future exercises.
Identify the one decision you would re-take, and rehearse the alternative.
How to support our people
This run did not surface a specific wellbeing finding, so nothing below is a claim about how your people felt. Use it as a checklist and a set of questions to take back to the team, because the human side of a response is easy to leave out of the plan.
During the incident
- Make rest and handover mandatory, and rotate responders so no one works more than a single shift without a break.
- Feed people. Order food in, keep water and caffeine available, and protect time for meals away from screens.
- Name a single point of contact for staff questions so the response team isn't interrupted constantly.
- Be explicit that nobody will be blamed for the initial incident. Blame slows reporting on the next event.
- Communicate clearly and often, even when there's nothing new. Silence breeds rumour and anxiety.
In the first 72 hours after
- Hold a short, structured 'hot debrief' focused on what happened and what people need now, not on judgement.
- Offer time off in lieu for those who worked extended hours, and protect it (don't pull people back into BAU immediately).
- Signpost your Employee Assistance Programme (EAP), occupational health, and any internal mental-health first-aiders.
- Watch for warning signs: sleep disruption, withdrawal, irritability, or staff repeatedly replaying the incident.
- Thank people specifically and publicly. Generic 'thanks team' messages land flat after a hard week.
Longer term
- Run a 'cold debrief' 2 to 4 weeks later when emotions have settled and lessons can be captured calmly.
- Review whether on-call rotas, response retainers, or staffing levels need to change so the same people aren't always carrying the load.
- Update the staff member who triggered the incident (if any) on what changed as a result, closing the loop and reinforcing a no-blame culture.
- Track whether anyone leaves the team in the 6 months after the incident. Burnout often surfaces late.
- Build staff support into your incident response plan as a named workstream, with an owner, not as an afterthought.
Confidence and pacing detail
Confidence evolution
Self-rated confidence per decision (1 to 5). A rising line means the team grew into the situation.
Across 6 of 6 decisions the team rated themselves, confidence started at High (4/5), ended at Very high (5/5), and averaged 4.3/5 (peak 5/5, trough 4/5). Confidence stayed broadly steady — the team neither lost nor gained meaningful certainty as events unfolded.
What should we do next?
Recommendations
Turning what you learned into concrete next steps. Give each one an owner and a date.
- 1.Review any decision where resilience was traded for speed and check the trade was deliberate.
- 2.Document what worked so it can be repeated in future exercises.
- 3.Identify the one decision you would re-take, and rehearse the alternative.
Action planning: based on these lessons, what three things will your team commit to doing within the next 30 days?
Debrief discussion
Use these questions to guide your team's debrief while the exercise is still fresh.
Values anchor, self-check
Would I be comfortable if this decision and my reasoning were read out loud?
Who could be harmed by this choice — and have we acknowledged them?
Am I being honest about what I don't yet know?
Could I defend this to the board, the regulator and the people affected?
If I'm wrong, will the trail show I acted in good faith?
Questions for supervisors / facilitators
Where did the team make a strong call — and was it acknowledged?
Where was a call rushed, anchored or under-evidenced?
Can the team's reasoning be tied back to the values anchor?
What's the one lesson worth taking back to live operations?
Download your report before leaving
Aggregated session data (scenario, metrics, and decisions) is saved anonymously to help improve future exercises. The full detailed report, including participant names, role assignments, the complete decision journey, and the post-incident review questions, is only available as a PDF or Word download. When you close this page, that detail is lost. Download the report now to keep a complete record.
Take this sample debrief with you
A watermarked sample of the post-exercise debrief, same format your team gets after a real run. PDF for circulation, CSV for analytics.
Sample data is illustrative, figures and outcomes are pre-scripted, not generated from a live exercise.
Like what you see?
Run your own scenario to generate a debrief tailored to your team, including PDF, Word, PowerPoint and CSV exports.
Bundles your team dynamics observations, team-layer scores, debrief responses, media training notes, and any tagged timeline moments into one printable handout.