The Fourth Hour

EXECUTIVE SUMMARY
The Fourth Hour is a high-pressure, scenario-based cyber crisis simulation proposed for National Cybersecurity Awareness Month. It will bring together senior executives and the business, technical, legal, communications, risk, compliance, human resources and operational functions that must act as one when a cyber incident threatens an organisation.
The exercise places participants four hours into a fast-moving incident, after the first alarms, but before the full consequences are known. At this point, systems may be unavailable, customers and partners are demanding answers, regulators may need to be notified, the media narrative is forming and threat actors are increasing the pressure. Participants must interpret incomplete information, establish command, make defensible decisions and communicate with confidence.
The central question: by the fourth hour, is the organisation controlling the crisis, or is the crisis controlling the organisation?
AIM
To strengthen organisational cyber resilience by testing the ability of leaders and cross-functional teams to coordinate, decide, communicate and sustain critical operations during a rapidly escalating cyber crisis.
OBJECTIVES
- Assess the organisation’s ability to recognise when a technical incident has become a business crisis.
- Test crisis governance, command structures, escalation thresholds and decision rights.
- Examine coordination between executive leadership, technology, security, legal, communications, risk, compliance, human resources and operations.
- Practise decision-making with incomplete, conflicting and time-sensitive information.
- Test internal, customer, regulator, partner and public communication processes.
- Identify gaps in incident response plans, business continuity arrangements, third-party dependencies and recovery priorities.
- Generate practical, prioritised actions for improving preparedness after the exercise.