Skip to content

Exercise in a Box is an online tool from the NCSC which helps organisations test and practise their response to a cyber attack.

It is completely free, and you donโ€™t have to be an expert to use it. The service provides exercises, based around the main cyber threats, which your organisation can do in your own time, in a safe environment, as many times as you want. It includes everything you need for setting up, planning, delivery, and post-exercise activity, all in one place.

With the rise of ransomware attacks, more than ever, it is essential that organisations are prepared in case they suffer an attack. Effectively securing an organisation can be difficult as you are only as secure as your weakest link, and with the everchanging face of cybersecurity it is difficult to prepare against possible attacks.

The aims of this exercise are as follows:  

  • Understand how your organisation is prepared to deal with phishing attacks. 
  • Recognise how the configuration of your user accounts plays a major role in your defences.  
  • Gauge how effectively you can recover data and resume operation after a cyber-attack.  
  • Build trusted relationships and develop shared understanding between key stakeholders.  
  • Prepare and train key staff to think about what risks they are exposed to.  
  • Operate in a no-fault environment to check and test cyber security defences and capabilities. 

*If you are a private sector organisation and interested in attending an Exercise in a Box session, send an email to [email protected] and we will get in touch with you.

Registrations for this event have now closed, please see our events page for upcoming Exercise in a Box sessions.