Skip to content

Sample debrief, illustrative output

This is a pre-rendered example of what your team sees after running an exercise. The decisions, scoring, costings and runbook below are real outputs from a representative ransomware run. Sign up to run your own scenario and download the full debrief pack.

Exercise complete, debrief & review

Solid outcome with refinements

Outcome: Good outcome. Decision quality: sound (63/100). These are two different measures, the outcome is how the scenario ended, decision quality is how your team reasoned under pressure; every scenario is winnable and losable regardless of the calls made.

Financial services and insurance
DECID:R
Exercise complete, debrief & review

Solid outcome with refinements

Outcome: Good outcome
Decision quality: sound (63/100)
Aligned to Custom organisational framework. Standard risk vocabulary is used. Customise this in your organisation profile to match your internal framework.

What happened?

The team made defensible calls under pressure with manageable downside. (Path taken: Full network isolation → Internal command, external support on standby → Notify regulator, manage legal internally → Proactive multi-channel communications → Safety-first prioritisation with mutual aid → Full rebuild with independent security review.)

How this outcome was reached

What changed, and where it left you

Cumulative gains on threat containment (+40) and a final public trust of 72% put you on this outcome path.

What changed across the exercise

Every decision you made added to or took away from each measure. Where each one finished (healthy, strained or critical) shapes how the exercise is rated.

MetricStart → endTotal lossesTotal gainsNetFinal band
Public trust60% → 72%−3+19+12Healthy (≥70%)
Operational capacity80% → 75%−17+12-5Healthy (≥70%)
Threat containment40% → 80%0+40+40Healthy (≥70%)

Decisions that moved the needle

Public trust
  • +6#3 Notify the regulator within the 72-hour window
  • +5#5 Issue a holding statement now, full statement at 17:00
  • +4#4 Refuse to pay; rebuild from verified backups
Operational capacity
  • +12#6 Phased restoration with continuous monitoring
  • -10#2 Disconnect the affected segment from the network
  • -5#4 Refuse to pay; rebuild from verified backups
Threat containment
  • +14#2 Disconnect the affected segment from the network
  • +10#4 Refuse to pay; rebuild from verified backups
  • +8#1 Treat as a credible incident immediately

Where this left the team

  • Public trust ended at 72% (healthy (≥70%)) — net +12 from 60%.
  • Operational capacity ended at 75% (healthy (≥70%)) — net -5 from 80%.
  • Threat containment ended at 80% (healthy (≥70%)) — net +40 from 40%.

How your decisions moved the situation

tick mark = starting value
Public trust
6072% 12
Operational capacity
8075% 5
Threat containment
4080% 40

What did we decide?

How your choices produced the decision-quality score

Each decision is scored on rigour, outcome and confidence calibration (the same model used throughout this debrief and in every export), combined into a 0-100 total.

Decision quality
sound
63 / 100
Mix:4 low-risk2 medium-risk0 high-risk
#DecisionChoiceRiskQualityRating
1Suspicious email reported by finance teamA: Treat as a credible incident immediatelylow63sound
2Encrypted files spreading on the file serverB: Disconnect the affected segment from the networkmedium60sound
3Regulator notification window opensA: Notify the regulator within the 72-hour windowlow59sound
4Attacker demands ransom in cryptocurrencyC: Refuse to pay; rebuild from verified backupsmedium64sound
5Press desk asks for a statementB: Issue a holding statement now, full statement at 17:00low62sound
6Service restoration vs full security reviewA: Phased restoration with continuous monitoringlow67sound

This is the same decision-quality model used in the scoreboard below and in every PDF, Word and PowerPoint export, there is a single source of truth for decision quality across the debrief.

Decision timeline

When each call was made, how long it took, and which choices drove the biggest swings. Highlighted rows are the key calls.

Total
55:00
Average
09:10
Fastest
#1 · 04:00
Slowest
#6 · 15:00
00:0055:00
Improved metricsHurt metricsNeutral / no net changeLarger dot = key call (biggest swing)
#ElapsedTookDecisionRiskNet impactConf.
104:0004:00Treat as a credible incident immediatelyLow+64/5
212:0008:00Disconnect the affected segment from the networkMedium+14/5
320:0008:00Notify the regulator within the 72-hour windowLow+85/5
430:0010:00Refuse to pay; rebuild from verified backupsMedium+94/5
540:0010:00Issue a holding statement now, full statement at 17:00Low+54/5
655:0015:00Phased restoration with continuous monitoringLow+225/5
Key calls, biggest swings

#2 at 12:00, “Disconnect the affected segment from the network” (+1 net, 27 total swing)

#6 at 55:00, “Phased restoration with continuous monitoring” (+22 net, 22 total swing)

#4 at 30:00, “Refuse to pay; rebuild from verified backups” (+9 net, 19 total swing)

6 decisions over 55:00, averaging 09:10 per call. 6 of 6 decisions had a net positive impact on the headline metrics. The quickest call (#1, 04:00) was "Treat as a credible incident immediately"; the longest deliberation (#6, 15:00) was "Phased restoration with continuous monitoring". The biggest swings came from #2, #6, #4 — these are the calls that moved the headline metrics most.

Total crisis cost

Based on sector benchmark

Scale: Mid-market · Eight categories of exposure modelled from your final metrics, sector, scenario type and time on incident. Heuristic estimates intended to provoke debrief discussion, not actuarial figures.

Total exposure
£637k
£637,024
Columns to include in CSV / PDF exportInclude columns:

mostly immediate cash burn, 86% of the cash-vs-trust split lands in the first hours and days. The single biggest line is direct response (decisions).

≈ 0.8% of annual revenue, a material but recoverable hit.

Immediate cash exposure
£547k
Response, downtime, technical recovery & people
Long-tail exposure
£90k
Churn, regulatory, reputation & insurance
Decisions logged
6
Direct response: £351k
Where the money went, top drivers
#1Direct response (decisions)One-off
£351k
55.0% of total

Sum of the 6 decisions the team committed to during the exercise.

Debrief prompts

Which committed decision do you think was the best value for money, and which the worst?

Were any of these spends avoidable with earlier action?

How this £ was calculated
Σ(cost of each committed decision)
Decisions committed:
6
Sum of decision costs:
£350,500
Each option's £ comes from its authored cost or risk × impact × scale multiplier.
Scale band:
Mid-market
Per-decision range £5.0k–£120k
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
#2Technical recovery, forensics & rebuildOne-off
£144k
22.6% of total

Incident response retainer, forensic investigation, and system restoration — sized by containment gap (0%) and incident type.

Debrief prompts

Which technical debt got exposed by this incident?

What would the team rebuild differently if budget were no object?

How this £ was calculated
(top of per-decision range × 2) × (0.4 + containment gap × 1.1) × scenario tech weight
Technical baseline:
£240k
2 × top of per-decision range (£120k) — covers IR retainer + forensics + rebuild for the band.
Containment factor (live):
32%
Live ticker uses 1 − 0.85 × (containment ÷ 100)
Containment gap (final):
0%
Starting threat containment (40%) − final (80%), floored at 0 — improved containment is never a gap
Scenario technical weight:
1.50×
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
#3Reputation & PR recoveryOne-off
£72k
11.3% of total

External comms agency, media monitoring, and paid recovery campaigns to restore brand trust over 6–12 months.

Debrief prompts

Which moment in the exercise did the most reputational damage?

Was there a missed opportunity to take control of the public story?

How this £ was calculated
(0.2% of ARR) × (0.4 + trust damage × 1.6) × scenario rep weight
Baseline budget:
£150k
0.2% of annual revenue
Trust damage:
0%
Scenario reputation weight:
1.20×
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
Remaining categories (3) · £71k
#4People & welfare (overtime, EAP, turnover)One-off
£52k
8.2% of total

~31 staff × 13h overtime, plus employee assistance and projected turnover replacement costs.

Debrief prompts

Did anyone check on the responders' welfare during the exercise?

Who was running on adrenaline by the end, and what's the plan for them next time?

How this £ was calculated
overtime + EAP uplift + turnover risk
Affected staff:
31
headcount 500 × (5% + ops damage × 25%)
Overtime hours:
13 h
time on incident × 1.5 + decisions × 2 (min 8h)
Loaded hourly rate:
£65/h
UK blended rate including on-cost
Overtime cost:
£27k
EAP / counselling:
£25k
Headcount × £50 × scenario welfare weight
Turnover risk:
£0
Headcount × trust damage × £400 × welfare weight
Scenario welfare weight:
1.00×
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
#5Insurance premium upliftAnnualised
£18k
2.8% of total

Estimated 15% increase on cyber/crisis cover at next renewal (baseline £120k/yr).

Debrief prompts

Do you actually know what your cyber policy excludes?

Would this incident trigger a premium reset at your next renewal?

How this £ was calculated
baseline premium × (15% + max(containment gap, trust damage) × 45%)
Baseline cyber premium:
£120k/yr
Uplift:
15%
Worse of containment gap / trust damage:
0%
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
#6Operational downtime / lost revenueOne-off
£573
0.1% of total

Approx under 0.1 days of degraded operations at £300k/day, scaled by your final operational capacity (75%).

Debrief prompts

What would have brought operations back online faster?

Did anyone own the call to degrade or restore service, or did it drift?

How this £ was calculated
daily revenue × ops damage × downtime days
Daily revenue:
£300k/day
£75.00m ARR ÷ 250 working days
Ops damage:
5%
Starting operational capacity (80%) − final (75%), floored at 0 — an improvement is never damage
Downtime days:
under 0.1 days
max(time on incident ÷ 24h, ops damage × 0.5)
Time on incident:
55.0 min (0.92 h)
Heuristic estimate calibrated against published incident reports, designed to spark debrief discussion, not to be actuarial.
Total estimated crisis cost£637k

Cost accrual timeline

Cumulative £ per category, minute-by-minute, replaying each decision at the time you actually committed to it. As containment improves, the per-minute crisis bleed slows and category curves flatten.

Final containment 80%
At minute 55
  • #1 · 4mTreat as a credible incident immediately+8 containment
  • #2 · 12mDisconnect the affected segment from the network+14 containment
  • #3 · 20mNotify the regulator within the 72-hour window+2 containment
  • #4 · 30mRefuse to pay; rebuild from verified backups+10 containment
  • #5 · 40mIssue a holding statement now, full statement at 17:000 containment
  • #6 · 55mPhased restoration with continuous monitoring+6 containment
Per-decision response cost (6)
01Treat as a credible incident immediatelyLow£4.5k
02Disconnect the affected segment from the networkMedium£18k
03Notify the regulator within the 72-hour windowLow£9.5k
04Refuse to pay; rebuild from verified backupsMedium£220k
05Issue a holding statement now, full statement at 17:00Low£3.5k
06Phased restoration with continuous monitoringLow£95k
Subtotal, direct response£351k

What did we do well?

What you did well

The judgement calls your team made under pressure that moved things in the right direction, and the worse outcomes those calls quietly avoided.

Avoided outcomes

The worst-case consequences your decisions prevented, based on the alternative paths you didn't take and where the metrics finished.

01

Avoided a collapse of the overall position

high severity

Worst case prevented: If these measures had fallen below 20%, the incident would have run the organisation rather than the other way round: wider compromise, the narrative set by others, and recovery starting from zero.

Instead you: You finished with containment at 80%, public trust at 72% (started at 60%), operational capacity at 75%, keeping enough control to run a structured response.

What should we learn?

Lessons learned

01

Review any decision where resilience was traded for speed and check the trade was deliberate.

02

Document what worked so it can be repeated in future exercises.

03

Identify the one decision you would re-take, and rehearse the alternative.

How to support our people

This run did not surface a specific wellbeing finding, so nothing below is a claim about how your people felt. Use it as a checklist and a set of questions to take back to the team, because the human side of a response is easy to leave out of the plan.

During the incident

  • Make rest and handover mandatory, and rotate responders so no one works more than a single shift without a break.
  • Feed people. Order food in, keep water and caffeine available, and protect time for meals away from screens.
  • Name a single point of contact for staff questions so the response team isn't interrupted constantly.
  • Be explicit that nobody will be blamed for the initial incident. Blame slows reporting on the next event.
  • Communicate clearly and often, even when there's nothing new. Silence breeds rumour and anxiety.

In the first 72 hours after

  • Hold a short, structured 'hot debrief' focused on what happened and what people need now, not on judgement.
  • Offer time off in lieu for those who worked extended hours, and protect it (don't pull people back into BAU immediately).
  • Signpost your Employee Assistance Programme (EAP), occupational health, and any internal mental-health first-aiders.
  • Watch for warning signs: sleep disruption, withdrawal, irritability, or staff repeatedly replaying the incident.
  • Thank people specifically and publicly. Generic 'thanks team' messages land flat after a hard week.

Longer term

  • Run a 'cold debrief' 2 to 4 weeks later when emotions have settled and lessons can be captured calmly.
  • Review whether on-call rotas, response retainers, or staffing levels need to change so the same people aren't always carrying the load.
  • Update the staff member who triggered the incident (if any) on what changed as a result, closing the loop and reinforcing a no-blame culture.
  • Track whether anyone leaves the team in the 6 months after the incident. Burnout often surfaces late.
  • Build staff support into your incident response plan as a named workstream, with an owner, not as an afterthought.
Confidence and pacing detail

Confidence evolution

Self-rated confidence per decision (1 to 5). A rising line means the team grew into the situation.

Start
4/5
End
5/5
Average
4.3/5
Peak
5/5
Trough
4/5
Delta
+1
Trend
steady
54321
4
4
5
4
4
5
1
2
3
4
5
6

Across 6 of 6 decisions the team rated themselves, confidence started at High (4/5), ended at Very high (5/5), and averaged 4.3/5 (peak 5/5, trough 4/5). Confidence stayed broadly steady — the team neither lost nor gained meaningful certainty as events unfolded.

What should we do next?

Recommendations

Turning what you learned into concrete next steps. Give each one an owner and a date.

  1. 1.Review any decision where resilience was traded for speed and check the trade was deliberate.
  2. 2.Document what worked so it can be repeated in future exercises.
  3. 3.Identify the one decision you would re-take, and rehearse the alternative.

Action planning: based on these lessons, what three things will your team commit to doing within the next 30 days?

D

Debrief discussion

Use these questions to guide your team's debrief while the exercise is still fresh.

Values anchor, self-check

?

Would I be comfortable if this decision and my reasoning were read out loud?

?

Who could be harmed by this choice — and have we acknowledged them?

?

Am I being honest about what I don't yet know?

?

Could I defend this to the board, the regulator and the people affected?

?

If I'm wrong, will the trail show I acted in good faith?

Questions for supervisors / facilitators

?

Where did the team make a strong call — and was it acknowledged?

?

Where was a call rushed, anchored or under-evidenced?

?

Can the team's reasoning be tied back to the values anchor?

?

What's the one lesson worth taking back to live operations?

Download your report before leaving

Aggregated session data (scenario, metrics, and decisions) is saved anonymously to help improve future exercises. The full detailed report, including participant names, role assignments, the complete decision journey, and the post-incident review questions, is only available as a PDF or Word download. When you close this page, that detail is lost. Download the report now to keep a complete record.

Take this sample debrief with you

A watermarked sample of the post-exercise debrief, same format your team gets after a real run. PDF for circulation, CSV for analytics.

Sample data is illustrative, figures and outcomes are pre-scripted, not generated from a live exercise.

Like what you see?

Run your own scenario to generate a debrief tailored to your team, including PDF, Word, PowerPoint and CSV exports.

Bundles your team dynamics observations, team-layer scores, debrief responses, media training notes, and any tagged timeline moments into one printable handout.