Fill in the form below and we will contact you shortly to organised your personalised demonstration of the Noggin platform.
An integrated resilience workspace that seamlessly integrates 10 core solutions into one, easy-to-use software platform.
The world's leading integrated resilience workspace for risk and business continuity management, operational resilience, incident & crisis management, and security & safety operations.
Explore Noggin's integrated resilience software, purpose-built for any industry.
Crisis Management Software
Updated December 7, 2023
If the pandemic has taught us anything, it is that you can’t just plan for crises; you have to test plans consistently, under conditions that approximate the real-world crisis scenario. The failure to exercise and test resilience plans regularly is often given as a reason for the breakdown of business resilience processes during critical events.
The issue predates the pandemic. In the 2018 Deloitte study, Stronger, fitter, better: Crisis management for the resilient enterprise, 90 per cent of organisations reported confidence in their crisis management capabilitiesi. Only 17 per cent of those organisations, however, had performed simulation exercises.
Despite the central role of communications in crisis management, companies didn’t fare much better when it came to crisis communications. A 2016 Nasdaq public relations services study found that a majority of corporate communicators said that their company either lacked a crisis communications playbook (48 per cent) or were unsure of whether they had one (12 per cent)ii.
When looking at the best-practice measures organisations failed to take to prepare themselves for crisis, the picture only got worse. Sixty per cent of organisations did not role play or were unsure if they did. Fewer than half (48 per cent) were actively using a media monitoring platform. Only 24 per cent of company CEOs and other spokespeople were receiving annual media training.
What should organisations be doing to prepare, instead? The expert consensus, here, is for organisations to “make maximum use of the controlled, risk managed environment of exercises and testing.” After all, the practice that builds familiarity and comfort with business resilience practices is only possible in such an environment. When real crises come, the time for practice is over.
In addition to breeding confidence in the crisis management system, program, and the overall competence of the organisation to protect and maintain its prioritised human, physical, and environmental assets, what other roles do exercises and testing play? Exercises and testing also:
Of course, any number of ways exist to conduct exercises and testing. Organisations might not understand which is right for them.
They are in luck. The resilience community came together, developing international standard ISO/DIS 22398, which lays out a best-practice framework for performing resilience testing and exercises. In turn, this guide outlines the most important aspects of the international standard, informing organisations how to get their own best-practice testing and exercise program up and running.
International standard, ISO 22398 describes the procedures necessary for planning, implementing, managing, evaluating, reporting, and improving exercises, as well as the testing designs needed to assess the crisis-readiness of an organisation. The standard itself consists of seven sections, in addition to a forward, introduction, and multiple informative annexes.
The introduction sets up fundamental principles for crisis management exercises and testing, such as the need for performance objectives. Objectives, here, include:
Further, the standard argues that organisations should codify specific policies stipulating that exercises, testing and, implementation procedures should lead to corrective action. To this end, organisations should:
Crisis management terminology to master | |
After-action report | A document which records, describes, and analyses the exercise, drawing on debriefs and reports from evaluators, participants, and observers. |
Drill | An activity which practices a particular skill, often involves repeating the same thing several times. |
Evaluation | A systematic process that compares the results of measurement to recognised criterion, to determine the gap between intended and actual performance. |
Exercise | A process to train for, assess, practice, and improve performance in an organisation. |
Exercise annual plan | A document in which the exercise policy plan has been translated to exercise aims and exercises and the exercise agenda or exercise calendar for a certain year is reflected. |
Scenario | A pre-planned storyline that drives an exercise, the stimuli used to achieve exercise objectives. |
Strategic exercise | Exercises involving top management at a strategic level. |
Testing | Procedure for determining the presence, quality, or veracity of something. |
Training | Activities designed to facilitate the learning and development of knowledge, skills, and abilities, and to improve the performance of specific tasks or roles. |
Understanding theory is good, what matters, though, is practice. The standard excels in making pragmatic recommendations for tangible actions, too, e.g., what organisations need to do before performing tests and exercises.
In the establishing the foundation section, the standard instructs complying organisations that they need to conduct a needs and gap analysis; the purpose of this analysis is to establish the need for exercises and testing in the first place.
Beyond that, pre-testing analysis effectively signals the role of exercises and testing in managing business risks. The practical import in that is it helps stakeholders (including senior leaders) understand that conducting exercises and testing is needed to manage risks.
What questions might organisations ask to get started with this planning stage of the testing process? Common questions include:
Indeed, the genius of the ISO standard, here, is that it enables organisations to move away from generic exercises to a more customised testing program better suited to managing their specific business risks.
From that vantage, the gap analysis not only helps make the case for such a best-practice testing program, but it also indicates what kind of exercise (out of the many available options) that that program should be deploying.
Exercises companies might undertake include:
Alert exercise | The purpose of an alert exercise is to test the organisation by alerting the involved participants and getting them to arrive at a designated place within a certain time. It can also be used to test an alert mechanism. This type of exercise is primarily applied to internal staff. |
Start exercise | A start exercise usually builds upon the alert exercise, testing how fast the emergency management organisation can be activated and start carrying out their tasks. A start exercise is therefore a means to test and develop the ability to get started with crisis management processes. |
Staff exercise | A staff exercise is designed to increase the ability to work with internal processes, staff and information routines in order to create a common operational picture and suggest decisions. |
Decision exercise | A decision exercise is primarily used to exercise decision making process within an organisation, e.g., the ability to take fast and clear decisions on actions and to initiate cooperation between those responsible and stakeholders, under time pressure. |
Management exercise | This type of exercise is a combination of alert exercise, start exercise, staff exercise, decision exercise, and system exercise. The focus is often on the roles, organisation, SOPs, etc. |
Cooperation exercise |
A type of exercise where coordination and cooperation between management levels is exercised. A cooperation exercise can be carried out both, in large and small scales. A cooperation exercise may consist of: “Vertical” coordination (between national, regional, and local levels); “Horizontal” coordination in a sector where public and private stakeholders participate. |
Crisis management exercise | A crisis management exercise simulates crisis conditions and gives personnel the opportunity to practice and gain proficiency in their plan roles. |
Strategic exercise |
Strategic exercise refers to comprehensive exercise activities at strategic level (e.g., interministerial crisis staff, political-administrative staff, cross-sector and cross-departmental management staff, crisis management organisation of corporate management). Aims include improving the integrated crisis reaction ability in exceptional threat and danger situations (crisis situations) and developing a comprehensive coordination and decision culture. |
Exercise campaign | An exercise campaign is a series of recurrent exercises with a common generic organisational structure. |
The standard offers even more room for exercise customisation than that. Besides type, exercises themselves can be broken down into discussion or operations based. The former helps participants familiarise themselves with existing plans, policies, agreements, and procedures.
Operations-based exercises, on the other hand, help stakeholders validate plans, policies, agreements, and procedures. They also allow for the clarification of roles and responsibilities as well as the identification of resource gaps in an operational environment.
Of course, even these two categories include multiple sub-categories, examples of which include:
Alert exercise | Discussion-based | Operations-based |
Definition | Also called “dilemma exercises,” serve to familiarise participants with current plans, policies, agreements, and procedures. | Validate plans, policies, agreements, and procedures; clarify roles and responsibilities; and identify resource gaps in an operational environment. |
Examples |
|
|
So far, the standard has counselled the importance of testing and exercises for ensuring business resilience. It has also advised organisations to perform a needs and gap analysis to determine the kind of exercise that makes the most sense for their resilience needs. As mentioned, exercises consist of broad types (discussion- and operations-based), with multiple sub-categories falling under each. The remaining question, though, is what should organisations do once they have determined the type of exercise they need to conduct?
The standard doesn’t provide a play-by-play for each specific type of scenario. It does, however, give organisations a set of six generic stages through which exercises go through. Those stages include:
The primary purpose of exercises and testing is to inform stakeholders which business resilience practices are working as planned and which are not. That is why the after-action report, the natural terminus of the (cyclical) testing process, is perhaps the most important deliverable of all.
Most organisations would have heard of the after-action report, a staple of post-crisis analysis. The post-testing afteraction report does something similar, in that it (a) gives organisations an overview of the exercises and testing performed; (b) reports on any successes against performance objectives; (c) elucidates what went well; (d) lays out the issues identified; (e) lists subsequent remediation actions to be taken and by whom.
Of course, post-testing after-action reports differ in substance from post-crisis after-action reports; the former, by definition, details what happens in the more controlled exercise environment. What, then, are discussion points one might see in the former but not the latter? Discussions might include:
Finally, the COVID-19 crisis upped the ante on business resilience: crisis management planning is no longer enough. In order to be crisis ready, organisations will need to build and promote best-practice crisis testing and exercise programs, as well.
International standard ISO 22398 provides a framework for such programs. The onus now is on the individual organisations, starting with their senior staff, to do the hard work of implementing these programs, giving them all of the resources needed, including advanced crisis management software like Noggin Crisis, to manage all stages of the crisis management lifecycle.
i. Peter Dent, Roda Woo, and Rick Cudworth, Deloitte Insight: Stronger, fitter, better: Crisis management for the resilient enterprise.
ii. Seth Arenstein, PR News. PR News/Nasdaq Survey: Nearly Half of Organizations Shun Crisis Preparation. Available at http://www.prnewsonline.com/pr-newsnasdaq-survey-nearly-half-organizations shun-crisis-preparation/.