Gartner note pushes cyber resilience tests beyond discussion-based drills
A June 2026 Gartner Maverick Insights note is fueling debate over whether cyber exercises are proving resilience or just rehearsing confidence. CYBER RANGES CISO Ed Bisceanu argues organizations need connected validation across tabletop, cyber range, recovery and re-test stages, especially for OT environments where safety and availability matter.
Why it matters: - Cyber exercises are becoming more common across boards, national drills, red and blue teams, and crisis simulations. - The core question is whether those exercises produce evidence of resilience or only a sense of preparedness. - The stakes rise in operational technology, where a technically successful response can still create a safety or availability failure. - Bisceanu argues executive teams should count verified corrections, not exercise volume.
What happened: - Ed Bisceanu, CISO at CYBER RANGES, published an analysis in August 2026 responding to a Gartner Maverick Insights note released in June 2026. - The note argues that if every exercise succeeds, an organization may be rehearsing confidence instead of testing resilience. - Bisceanu said the most important issue is not terminology but evidence. - He framed cyber resilience as the observable result of cybersecurity, cyber-risk management, continuity and recovery done well. - He said resilience does not get manufactured during an attack; the attack exposes earlier decisions.
The details: - Bisceanu separated exercises into four types: learning exercises, rehearsal exercises, assurance exercises and adversarial validation exercises. - Learning exercises build understanding through briefing, coaching and preparation. - Rehearsal exercises test coordination, escalation, communications, hand-offs and sequencing. - Assurance exercises test whether a capability meets explicit criteria under specified conditions. - Adversarial validation exercises challenge assumptions and treat consequential failure as useful if it leads to remediation and retesting. - Gartner’s 2026 tabletop infographic described tabletops as useful for testing response strategy and executive participation. - The same infographic surveyed 75 CISOs. - In that survey, 47% ranked simulating a real-world incident among their top three tabletop challenges. - Also in that survey, 39% ranked measuring effectiveness among their top three tabletop challenges. - Bisceanu said a tabletop can test the quality of a decision, but it cannot prove the system will follow that decision. - He said a mature model links one consequence-led scenario across the boardroom, operational environment and recovery process. - He outlined a sequence that can include executive tabletop, functional or command exercise, instrumented cyber-range exercise, recovery and controlled operational validation, then remediation and retest. - He said evidence should accumulate through decision records, telemetry, control performance, recovery results, assigned actions and retest outcomes. - His three takeaways were to match the exercise to the evidence required, connect executive decisions to technical consequences, and finish only when remediation survives retest. - He said not every tabletop needs to become a live exercise, but assumptions protecting critical services should not be protected by discussion alone. - Bisceanu cited the U.S. Gold Eagle Initiative, announced by the White House on July 14, 2026, as an example of a model that shifts focus from finding weaknesses to validating exploitability, prioritizing impact, assigning responsibility, coordinating remediation and verifying corrections. - He said the initiative is still early and its effectiveness remains unproven. - He said OT security guidance from NIST stresses that digital and physical risk are intertwined and that changes should be tested before deployment when operational impact is possible. - He said NIST also advises considering tabletop exercises or simulations to reduce production OT impact and using automated assessment tools carefully. - He said OT tabletop exercises can address authority, isolation, loss of view or control, remote-access compromise, manual operation, shutdown decisions and communications. - He pointed to CISA recommendations for discussion-based industrial exercises involving loss-of-visibility and loss-of-control scenarios. - He said OT testing can move selected assumptions into an isolated environment such as a cyber range with virtualized control networks, emulated or simulated PLC, HMI and SCADA behavior, historians, engineering workstations and remote-access paths. - He said representative hardware or hardware-in-the-loop can improve fidelity when justified. - He said fidelity must be declared, not assumed. - He said useful measures include detection and escalation time, decision latency, containment without creating a less safe condition, authorized degraded operation, controller logic integrity, restoration sequence, recovery time and successful retest. - He said MITRE ATT&CK for ICS can inform adversary behaviors, but operational consequences and safe-response criteria must come from the asset owner and engineering context. - He warned that tabletops, cyber ranges, recovery tests and OT assurance often sit under different owners, budgets and evidence models. - He said orchestration and integration matter more than simply having technology available.
Between the lines: - The argument is a critique of resilience programs that reward participation over proof. - Bisceanu’s framework pushes organizations toward measurable validation, where failed assumptions force decisions, funding moves and retesting happens. - In OT, the safety constraint makes pure live-fire testing unrealistic, but it also makes discussion-only validation insufficient. - The practical middle ground is graduated fidelity inside an explicit safety envelope. - The piece also suggests many organizations lack a shared evidence model across board, IT, security, engineering and operations.
What's next: - Organizations are likely to face pressure to link tabletop results to technical validation and recovery testing. - OT teams may need more representative environments, stronger scenario design and clearer ownership of remediation. - Boards will likely ask for proof that an exercise-led correction survived retest, not just that the exercise happened. - Bisceanu’s bottom-line recommendation is for cyber range environments where failure can be safe, observable and useful. - He said a cyber range is where a resilience framework is forced to meet consequences.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Sci-Tech News Network
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.