Book FREE Consultation

URM is pleased to provide a FREE 30 minute consultation on Transitioning to ISO 27001:2022 for any UK-based organisation. Once an enquiry form has been submitted, we will be in touch to understand the nature of your enquiry and to book a mutually convenient time for a 30-minute consultation slot with one of URM’s specialists.

Cyber Incident Exercising (CIE) Services

As an approved Cyber Incident Exercising (CIE) Assured Service Provider under the National Cyber Security Centre (NCSC) scheme, URM is ideally and uniquely placed to assist you with your cyber incident exercising.

NCSC Cyber Incident Exercising Scheme

As an approved Cyber Incident Exercising (CIE) Assured Service Provider under the National Cyber Security Centre (NCSC) scheme, URM is ideally and uniquely placed to assist you with your cyber incident exercising.  Through the scheme you can be assured that URM meets the NCSC’s rigorous standards for developing and delivering high quality cyber incident exercising, possessing the required skills and experience of creating bespoke and structured cyber incident exercises.

The NCSC CIE scheme, which is administered by IASME, focuses on the development and delivery of two types of cyber exercises:

  • Table-Top –this is a discussion-based exercise where URM designs a scenario developed from information gathered about your organisation, and where participants respond to a developing situation, escalating over time, as they would in a live incident in line with your organisation’s incident response plan.
  • Live-Play –  this type of exercise involves participants carrying out their roles and responsibilities in close to real time and in response to a controlled feed of information, representing a pre-agreed scenario designed by URM and agreed with your organisation.  Typically, URM delivers live play exercises with mature organisations looking for in-depth validation of plans.

The exercises are designed to simulate incidents which have a significant impact on a single organisation.  The scheme does not cover category 1 and category 2 incidents, as defined by the UK cyber incident categorisation system.

APPROVED CYBER INCIDENT EXERCISING (CIE) ASSURED SERVICE PROVIDER

  • CIE Assured Service Providers have been assured by the NCSC to develop and deliver controlled, scenario-based, tailored exercising that conforms to the NCSC CIE Technical Standard. These exercises are delivered for organisations that want to practise, evaluate, and improve their cyber incident response plans in a safe environment.
  • Cyber Incident Exercising. The NCSC's Cyber Incident Exercising (CIE) scheme gives customers confidence that CIE Assured Service Providers meet NCSC standards for high quality cyber incident exercising.

Get in touch

Please note, we can only process business email addresses.

Why URM?

URM is ideally placed to assist your organisation with your cyber incident exercising due to the unique combination of exercising experience and cyber expertise.  Since its formation in 2005, URM has been developing and facilitating incident response exercises.  Our team of incident management and cyber specialists is hugely experienced and skilled in devising challenging, original and appropriate scenarios which will exercise and validate your incident response plans.  Working closely with you, we will ensure the scenarios are realistic, have clear objectives in terms of raising awareness, assess how well participants understand the plans, as well as their own roles and responsibilities and how they work collectively as a team.  URM has worked with a wide range of incident management teams as part its exercising and with different areas of focus, from assessing the capabilities of senior management to IT teams, measuring the effectiveness of communication and identifying gaps between actual and expected time to recover.

One feature of our exercising over the last 10 years has been the increasing number of cyber-related exercises we have developed, addressing such threats as malware attacks, ransomware incidents, data breaches and phishing attempts.  This is an area where URM is able to excel by virtue of its cybersecurity knowledge supported by our CREST accreditation.  Our Technical Team possesses a deep understanding of cybersecurity principles, current threats, and attack methodologies and, as such, is able to develop exercises which are both cutting edge and highly realistic.

Cyber Essentials FAQ

Cyber Essentials – What’s Changing in 2025?

Published on
14/11/2024

URM’s blog discusses upcoming changes to Cyber Essentials, including the changes seen in the Willow Question Set and how they may impact your organisation.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
24/10/2024
Enhancing Security in the Software Supply Chain

URM’s blog discusses the security risks associated with the software supply chain & how both software developers and their clients can mitigate these risks.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
22/8/2024
Pitfalls to Avoid in your Penetration Testing Programme

URM’s blog explores common pen testing mistakes & how to avoid them, and simple improvements you can immediately implement to enhance your security posture.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
1/8/2024
10 Most Common Vulnerabilities Found in Pen Tests

URM’s blog outlines the top 10 most common vulnerabilities we identify when conducting pen tests, the associated risks, and how they can be fixed/avoided.

Read more
"
The partnership approach URM takes is genuine. Our relationship with URM is not hard-nosed or overly commercialised, and feels much closer to a partnership arrangement than any other security consultancy providers we have worked with. If we had a new piece of work that we needed external help with, URM would be our first port of call for assistance.
CISO at University of Surrey
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.