Train · Resolv Academy
Executive cyber briefings
Focused sessions and tabletop exercises that equip boards and leadership teams to govern cyber risk and lead through an incident.
The challenge
Boards are accountable for cyber risk but are often briefed in either technical jargon or vendor alarm. Neither supports good decisions.
The first time many leadership teams discuss ransom payment, public disclosure or shutting down a service is during a live incident, when the cost of hesitation is highest.
Our briefings give leaders a clear understanding of the threats relevant to their organisation, the questions to ask, and practice making incident decisions in a safe setting.
Our method
How the work is done.
- 01
Context gathering
We review your sector, regulatory obligations and recent security reporting so the session reflects your real exposure.
- 02
Threat briefing
A plain-language account of the threats facing organisations like yours, how attacks unfold and what they cost.
- 03
Governance session
Leaders work through risk appetite, oversight responsibilities and the questions to put to their security team, using NIST CSF as the frame.
- 04
Tabletop exercise
A facilitated incident scenario in which leaders make decisions on containment, notification, communication and recovery as events develop.
- 05
Debrief and actions
We record decisions, gaps and follow-up actions, and report them to the sponsor.
Deliverables
What you receive.
- Tailored threat briefing pack
- Board-level questions to ask the security function
- Facilitated tabletop exercise with a sector-relevant scenario
- Exercise report with observations and recommended actions
- Incident decision checklist for leadership
Engagement options
Ways to buy it.
- 01Half a day
Board briefing
A single session for a board or committee.
- 021 day
Leadership tabletop
Briefing plus a facilitated incident exercise.
- 0312 months
Annual programme
Recurring briefings and exercises timed to the governance calendar.
Standards
Frameworks we work to.
- NIST CSF
- NIST SP 800-61
- ISO 27001
- ISO 22301
Questions
What buyers ask us.
Is technical knowledge required?
No. The sessions are designed for non-technical leaders.
Are the sessions confidential?
Yes. Discussion and exercise results are shared only with the sponsor and those they nominate.
Can the exercise use our own incident plan?
Yes, and we recommend it. Testing the real plan is the most useful outcome of an exercise.
Who facilitates?
Practitioners from our security practice who work on incident response and governance engagements.
Related services
Often delivered together.
Secure
Virtual CISO
Senior security leadership on a part-time basis: strategy, risk ownership, board reporting and programme direction without a full-time hire.
Secure
Incident response
Investigation, containment and recovery when a breach is suspected or confirmed, run to NIST SP 800-61 and documented for regulators and insurers.
Secure
Governance, risk & compliance
Gap assessments, risk registers, policies and audit readiness against ISO 27001, SOC 2, PCI DSS and NIST CSF, built to be used rather than filed.
Discuss executive cyber briefings.
A senior engineer reviews every enquiry and replies within one business day.