Pre-work, done by us
We establish which reporting obligations genuinely apply to you, the windows attached to each, and what your existing incident plan says — so the exercise tests the plan you have rather than one we imagined.

Service · Board simulation
Technical exercises rehearse containment. Boards do not contain anything. They decide what to tell a regulator on a clock they did not set, whether to keep trading, what to say publicly, and who speaks — usually with partial information and a legal team still reading the contract. That is the exercise nobody runs.
In this region the regulatory deadline usually arrives before technical certainty does. Bahrain's central bank rules put the CBB on a phone call within one hour of an incident. Oman's data protection law runs a 72-hour breach notification. Qatar and Saudi Arabia each have their own reporting expectations attached to their assurance regimes, and a group operating across three Gulf states is on three different clocks simultaneously, in three languages, with three sets of consequences for getting it wrong.
A board that has never rehearsed this defaults to waiting for facts. That is the single most expensive instinct in the room, and it is entirely reasonable — which is why it has to be surfaced in an exercise rather than in an incident.
So the scenario is built backwards from your actual obligations. Not a generic ransomware tabletop with the country name changed: your regulators, your reporting windows, your contractual notification terms, and the specific question of who is authorised to speak when the chief executive is on a plane.
Half a day, with the board and the executives who would actually be in the room. No technical prerequisites and no preparation asked of participants.
We establish which reporting obligations genuinely apply to you, the windows attached to each, and what your existing incident plan says — so the exercise tests the plan you have rather than one we imagined.
Three to four injects across a compressed timeline, run in English or Arabic or both as the board needs. Decisions are recorded as they are made, including the ones that get deferred — the deferrals are usually the finding.
Regulatory notification under uncertainty, public and customer communication, whether to keep operating, third-party and supply-chain notification, and the authority question: who decides, and what happens when that person is unreachable.
What was decided, what could not be decided and why, the gaps in delegated authority the exercise exposed, and a short list of things to change — written for the minutes, not for the security team.
Which of these apply is established in the pre-work. Most groups are surprised by at least one.
The most prescriptive mandated-assessor rule verified anywhere in the GCC, and the tightest reporting clock: the CBB notified within one hour by phone. It also requires a qualified CISO with authority to implement the strategy, and penetration testing by internal and external independent parties with the external party changed at least every two years.
Breach notification within 72 hours, enforceable since February 2026, alongside a 45-day window for data subject requests. The DPO mandate is unconditional, so there is a named officer whose statutory duties run alongside the board's commercial judgement — and may not align with it.
Kuwait's framework, in force since December 2025, is explicitly about operational resilience rather than controls alone — continuity of service delivery is the assessed outcome. Qatar's assurance regime attaches to a certification the NCSA can act on, which makes an incident a certification event as well as a security one.
It is not a technical tabletop, not a penetration test, and not an assessment of your security controls — if you want those, they are separate engagements and two of them are gated to licensed firms in some of these markets. It is also not a pass or fail. Boards that make poor decisions in a simulation have had a good day; the finding is worth more than the reassurance. We do not publish or share what happens in the room, and the board pack is yours.
Tell us the sector, the countries you operate in, and who would actually be in the room. The scenario is built from your obligations, so the pre-work starts there.