{"id":16179,"date":"2026-05-06T09:06:59","date_gmt":"2026-05-06T09:06:59","guid":{"rendered":"https:\/\/newestek.com\/?p=16179"},"modified":"2026-05-06T09:06:59","modified_gmt":"2026-05-06T09:06:59","slug":"train-like-you-fight-why-cyber-operations-teams-need-no-notice-drills","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16179","title":{"rendered":"Train like you fight: Why cyber operations teams need no-notice drills"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p>St. Michael\u2019s Hospital in Toronto recently executed a full Code Orange simulation: A mass casualty emergency protocol requiring the activation of every clinical and operational team across the hospital. As a Level 1 trauma centre, it conducts large-scale exercises involving teams across the entire hospital: Emergency, surgery, communications, administration. The exercise is not a compliance event. It is an operational doctrine. The assumption is straightforward: The first time your team encounters a mass casualty event should not be the first time your team has encountered a mass casualty event.<\/p>\n<p>Cybersecurity is moving in the right direction. Detection has improved markedly but how teams train to respond has not yet caught up, and predictability has a ceiling. Scenarios distributed in advance, schedules agreed weeks ahead, playbooks handed out before anyone enters the room. I understand why. Scheduled exercises satisfy compliance requirements, cross-train teams and surface documentation gaps. But they cannot build the one capability that determines whether a real incident goes well or catastrophically wrong.<\/p>\n<p>The fix is not more planning. It is more surprise. And the reason why is not just operational. It is neurological.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Detection is the catalyst, not the problem<\/h2>\n<p>Security leaders often frame incident response readiness as a detection challenge. Build better alerts, tune the SIEM, reduce noise. Detection matters, but it is not where most organizations fail. Mandiant\u2019s M-Trends 2025<a href=\"https:\/\/services.google.com\/fh\/files\/misc\/mandiant_m-trends_2025_report.pdf\"> <\/a><a href=\"https:\/\/services.google.com\/fh\/files\/misc\/mandiant_m-trends_2025_report.pdf\">report<\/a>, drawing on more than 450,000 hours of incident response investigations, documents a long-term reduction in attacker dwell time from 205 days in 2014 to 11 days in 2024. Detection is getting better.<\/p>\n<p>Detection is the catalyst, not the problem. What determines whether a response goes well is the state of the people who receive it. A team conditioned to act under genuine pressure will compress the time between detection and effective response. A team that has only ever rehearsed under controlled, low-stakes conditions will not, regardless of how sophisticated their tooling is.<\/p>\n<p>Building several no-notice programs has taught me something that no tabletop exercise ever surfaced. The failure patterns that emerge under genuine pressure are consistent across organizations: Unclear roles, slow decision-making and communication breakdowns that transform a manageable compromise into a full crisis. These are not process failures. They are the predictable result of people operating under acute stress without prior exposure to it. A plan that has never been tested under pressure is not a plan. It is a document.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Why the brain undermines the playbook<\/h2>\n<p>Under genuine threat stimulus, the human nervous system does not behave the way a tabletop exercise assumes it will. When the sympathetic nervous system activates in response to a perceived threat, it redirects neural resources away from executive function, working memory and language processing. The prefrontal cortex, the part of the brain that reads playbooks, reasons through options and communicates clearly, is progressively suppressed as physiological arousal intensifies. Teams do not fail under pressure because they lack knowledge. They fail because the neurological state that pressure induces makes that knowledge inaccessible at the moment it is needed most.<\/p>\n<p>This is why scheduled exercises cannot replicate the conditions they are meant to prepare teams for. Without genuine threat stimulus, the sympathetic nervous system is never fully engaged. Participants perform competently because they are not under real arousal. The behavior that feels fluent in the exercise room degrades when the same behavior is demanded under actual threat conditions, because the neurological state is entirely different.<\/p>\n<p>The Yerkes-Dodson principle, established in 1908 and validated extensively since, describes this as an inverted U. Performance rises with arousal up to an optimal point, then falls sharply as arousal continues to increase.<\/p>\n<div class=\"extendedBlock-wrapper block-coreImage undefined\">\n<figure class=\"wp-block-image size-large is-resized\"> width=&#8221;1024&#8243; height=&#8221;575&#8243; sizes=&#8221;auto, (max-width: 1024px) 100vw, 1024px&#8221;&gt;<figcaption class=\"wp-element-caption\"><em>The Yerkes-Dodson inverted-U curve: Performance rises with arousal to an optimal point, then falls sharply.<\/em><\/figcaption><\/figure>\n<p><a href=\"https:\/\/commons.wikimedia.org\/wiki\/File:HebbianYerkesDodson.svg\" target=\"_blank\" class=\"imageCredit\" rel=\"noopener\">Wikimedia Commons, CC-Zero<\/a><\/div>\n<p>What repeated no-notice drills do is shift a team\u2019s position on that curve. By building familiarity with threat-level arousal, they raise the threshold at which stress becomes performance-impairing. The stimulus is no longer novel. The cascade is shorter. Executive function stays online longer. Untrained teams encounter the steep right side of that curve for the first time during a real incident.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Stress inoculation: The science behind the drill<\/h2>\n<p>The formal psychological framework for what no-notice drills produce is stress inoculation training, first developed by psychologist Donald Meichenbaum in the 1970s and refined across four decades of applied research. The mechanism operates in three phases: Conceptualization, in which individuals understand their own stress response; skills acquisition, in which coping repertoires are built under controlled conditions; and application, in which those skills are tested through graduated, realistic exposure to the stressor itself. The application phase is not optional. It is where the inoculation occurs.<\/p>\n<p>The most rigorous contemporary validation of this framework in operational team settings comes from<a href=\"https:\/\/profiles.rice.edu\/faculty\/eduardo-salas\"> <\/a><a href=\"https:\/\/profiles.rice.edu\/faculty\/eduardo-salas\">Eduardo Salas<\/a>, Allyn R. &amp; Gladys M. Cline Chair Professor of Psychology at Rice University and one of the most cited researchers in the world on team performance under stress. His central finding is directly applicable here: Stress inoculation training produces improvements that transfer to novel, unfamiliar stressors, not just the scenarios that were rehearsed. The inoculation generalizes. A team trained under realistic pressure performs better when the pressure takes an unexpected form.<\/p>\n<p>Applied to cybersecurity operations, the implication is direct. No-notice drills do not build scenario-specific knowledge. They build a conditioned physiological and cognitive response to threat stimulus: Shorter sympathetic activation cascades, faster recovery of executive function and the ability to make sound decisions before the moment passes. Comfort. Poise. Calm but steady action-on.<\/p>\n<p>No-notice drills build three outcomes that scheduled exercises cannot.<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Instinct: <\/strong>Analysts who have been genuinely surprised before respond faster the next time, not because they followed a procedure, but because the threat is no longer neurologically novel. The sympathetic cascade is shorter. Decision-making begins sooner.<\/li>\n<li><strong>Trust: <\/strong>When the script disappears, teams rely on each other\u2019s judgment.<a href=\"https:\/\/www.hbs.edu\/faculty\/Pages\/profile.aspx?facId=6451\"> <\/a><a href=\"https:\/\/www.hbs.edu\/faculty\/Pages\/profile.aspx?facId=6451\">Amy Edmondson<\/a>, Novartis Professor of Leadership and Management at Harvard Business School, has spent three decades establishing that psychological safety built before a crisis is the precondition for effective performance during one. Teams that have experienced speaking up under pressure without negative consequence are measurably more able to do so again when it matters most. No-notice drills create exactly that experience. They surface the communication gaps and authority ambiguities that only emerge under genuine stress, the ones a tabletop never reaches.<\/li>\n<li><strong>Organizational honesty: <\/strong>Every organization that runs a surprise exercise finds something broken. An outdated escalation contact. A permissions gap. An executive who does not know what to do on a call at 3:00 a.m. The question is not whether those gaps exist. They do. The question is whether you find them before your adversaries do.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><a><\/a>How to build the program<\/h2>\n<p>Following Meichenbaum\u2019s application phase and Salas\u2019s guidance on graduated stress exposure, an effective no-notice program begins contained and builds toward full-chain complexity. Here is what works in practice.<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Start with anomaly injection: <\/strong>Seed realistic signals into production telemetry without announcement: An unexpected privileged account login, a credential used from an implausible geography, a misconfigured asset surfacing in cloud inventory, a ransomware detection in EDR. Observe what happens naturally. Which alerts fire. Who triages. How long before escalation begins.<\/li>\n<li><strong>Trigger full-chain activation: <\/strong>Once detection occurs, let the scenario cross organizational boundaries into Legal, Communications, Risk and the executive layer. This is where most exercises fail to go, and where the most expensive gaps live. In my experience running large-scale Fusion operations across multiple geographies, technical teams typically detect and triage with reasonable competence. The exposure sits in cross-functional latency: The time it takes decision-makers outside the SOC to become meaningfully engaged. That latency is invisible until you measure it under real conditions.<\/li>\n<li><strong>Debrief fast and without blame: <\/strong>Conduct a blameless post-mortem within 24 hours. Capture what surprised people, what slowed them and what they needed but did not have. Assign follow-ups in days, not months. The learning velocity of the program is almost entirely a function of how quickly the feedback loop closes.<\/li>\n<li><strong>Measure what matters: <\/strong>Mean time to detect and mean time to respond are necessary but insufficient. Add mean time to acknowledge, mean time to escalate and cross-functional activation time. A team that measurably cuts its acknowledgement time after three surprise drills has improved operational capability. A team that updates its playbook after a tabletop has improved its documentation.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><a><\/a>The leadership obstacle<\/h2>\n<p>The most common objection to no-notice drills is political rather than operational. Leadership is mindful of team embarrassment, perceived panic and audit exposure. These concerns are worth addressing directly: Run the first drills at small scale, brief leadership on the stress inoculation framework before you begin and be explicit that the goal is to find gaps, not to grade performance. Every gap found is a program success, because it is.<\/p>\n<p>The harder conversation is about what happens when those concerns win. The cost of never being surprised in training is being surprised for the first time during a real incident, when the damage clock is already running. PagerDuty\u2019s Failure Friday program reached a weekly cadence because that trade-off was made explicit and decided correctly: Structured surprise became part of normal operational rhythm rather than a periodic ordeal. The embarrassment of a drill that surfaces gaps is recoverable. The embarrassment of a breach that exposes them is not.<\/p>\n<p>No-notice programs fail when leadership treats mistakes as evidence of failure. They succeed when the post-mortem question is what we learned, not who missed it.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The standard worth holding<\/h2>\n<p>St. Michael\u2019s Hospital does not discover gaps in its mass casualty response during actual mass casualty events. Emergency medicine settled this question decades ago: You train under realistic pressure, across every team that would need to activate, before the event that requires it. Aviation reached the same conclusion. Military doctrine is built on it. The science, from Meichenbaum established that graduated exposure to realistic stress builds lasting resilience. Salas validated that finding across every high-consequence operational domain. And Edmondson at Harvard showed that psychological safety enabling teams to perform under crisis must be cultivated long before the crisis arrives. Three researchers, three disciplines, one conclusion.<\/p>\n<p>Too often, cybersecurity operations teams face their first genuine no-notice pressure event during an actual incident. That is a choice many organizations make by default, not by design and it is a choice with a known and preventable cost.<\/p>\n<p>The gap between a team that performs under pressure and one that collapses under it is not talent, tooling or process. The science, the doctrine and the operational evidence all point in the same direction. Teams that train under realistic pressure perform better when the pressure is palpable. The question is not whether to build this capability. It is how quickly you can get started, and the answer is simpler than most leaders expect: Seed an anomaly. Observe what happens. Debrief within 24 hours. That is the first drill. Everything else builds from there.<\/p>\n<p>Build the instinct and neurological memory now, before you need it. Because by the time you need it, it is already too late to build.<\/p>\n<p><strong>This article is published as part of the Foundry Expert Contributor Network.<\/strong><br \/><strong><a href=\"https:\/\/www.csoonline.com\/expert-contributor-network\/\">Want to join?<\/a><\/strong><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>St. Michael\u2019s Hospital in Toronto recently executed a full Code Orange simulation: A mass casualty emergency protocol requiring the activation of every clinical and operational team across the hospital. As a Level 1 trauma centre, it conducts large-scale exercises involving teams across the entire hospital: Emergency, surgery, communications, administration. The exercise is not a compliance event. It is an operational doctrine. The assumption is straightforward:&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16179\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16179","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16179"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16179\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}