Cyber drills on a weekly basis? Making it mission possible

Icon

Jeffrey James Bryan Carpenter caught our attention at the 37th Annual FIRST.org conference, where he demonstrated how to implement a weekly cyber drill program to build muscle memory and enhance incident response skills within a team. The recap is available here. We invited Jeffrey to elaborate on how he gets both his organisation’s buy-in as well as the inspiration to create the weekly exercises.

Jeffrey has dedicated more than 35 years to improving the state of information security in roles such as incident responder, product security officer, information security officer and leader. He currently is the deputy CISO at Accuray, a medical device manufacturer. Jeffrey spent two decades at the CERT® Coordination Center, based at Carnegie Mellon University’s Software Engineering Institute and he also was Senior Director of Incident Response Consulting and Threat Intelligence at Dell Secureworks. Jeffrey has been inducted into the Incident Response Hall of Fame by the Forum of Incident Response and Security Teams (FIRST).

1. Where do you get the inspiration for designing different cyber drills on a weekly basis? Do you have a set of rules/criteria for designing them?

I have three main sources of inspiration. The first is, whenever I or someone on my team encounters an issue or problem, I ponder if that can be used in a scenario. I have a OneNote page where I write those all down and try to incorporate them into a future scenario.  The second way is I read a lot. I read about incidents in the popular media, read vendor threat reports, and especially case studies (like the British Library and City of Helsinki incidents). In all of my security reading, I also look for issues that would be good to incorporate into a scenario.  And finally, I ask Microsoft Copilot for ideas.

2. How do you get the organisation to commit on doing them so often?
3. What would be your advice for organisations/CISOs willing to start cyberdrills in their organisations?
4. Do you have any advice on getting the management team on board? How is it in your case with getting the approval to dedicate time for weekly practices?

Other news and stories

SOCshare: 2026 July cyber landscape review
SOCshare: 2026 July cyber landscape review
In 2025, NRD Cyber Security saw growth in both its project-based activities and ongoing services
In 2025, NRD Cyber Security saw growth in both its project-based activities and ongoing services
Justas Kaminskas on what CTF is and how to win it
Justas Kaminskas on what CTF is and how to win it
SOCshare June 2026: cybersecurity landscape review
SOCshare June 2026: cybersecurity landscape review
The 3rd edition of the Guide for developing a National Cybersecurity Strategy
The 3rd edition of the Guide for developing a National Cybersecurity Strategy
SOCshare May 2026: News in cyber threat landscape
SOCshare May 2026: News in cyber threat landscape
SOCshare April 2026 review : Adobe Acrobat Reader, Claude and phishing
SOCshare April 2026 review : Adobe Acrobat Reader, Claude and phishing
SOCcare March 2026: A “Little Gift” from the photo shop
SOCcare March 2026: A “Little Gift” from the photo shop