Day 5
Culture, exercises, system recovery and lessons learned
Participants can prove that recovery is safe, monitored, approved by the business owner, and turned into measurable improvement actions.
- Training case
- D5-BALTNET-REC-001
- Programme topics
- 8, 9, 10
- Assignments
- P1 · P2 · ID-05
Where this day sits in the chain
Sequence: culture, exercises, recovery, report, lessons.
Rule of the day
A restored backup ≠ a restored service. A lesson ≠ a closed action.
Schedule
How the day runs
| Time | Topic | Format | Output |
|---|---|---|---|
| 09:00–09:45 | Security culture; learning and awareness strategies | Theory | Behaviour and competence evidence |
| 10:00–10:45 | System recovery and lessons learned | Theory | Recovery gates and metrics |
| 10:45–12:00 | Recovery tabletop exercise | Practical P1 | Recovery plan and GO / NO-GO |
| 13:00–13:45 | Business recovery and technical reporting | Theory | One fact base, two audiences |
| 13:45–15:00 | Technical recovery report | Practical P2 | Report, summary and lessons |
| 15:15–15:45 | Knowledge check | Test | Kahoot |
| 15:45–16:00 | Lessons and reflection | Discussion | Personal transfer action |
Learning outcomes
By the end of the day, participants can
- D5.1Separate declared culture from observed safe behaviour and choose a behaviour metric.
- D5.2Define a safe exercise objective, an inject, an observation criterion and a STOP condition.
- D5.3Tell containment, eradication, recovery and return to production apart.
- D5.4Sequence recovery by service dependencies, RTO / RPO and risk.
- D5.5Justify GO / NO-GO with evidence, approvals, monitoring and rollback.
- D5.6Write a technical report and an executive summary from one fact base.
- D5.7Turn a lesson into an action with an owner, a deadline and verifiable evidence of success.
Practice
Practical assignments
Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.
- P1
Recovery tabletop exercise
Sequence by dependencies, RTO / RPO and risk; every GO has evidence, an owner and rollback. Controlled injects with a clear STOP condition.- Duration:
- 75 min
- Deliverable:
- Recovery plan and validation sheet
- P2
Report and lessons
One fact base for two audiences; unknowns marked, no unfounded data-exfiltration claims; measurable actions.- Duration:
- 75 min
- Deliverable:
- Technical report, executive summary, actions
Extra labs
For deeper practice
The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.
LAB 3D5-BALTNET-REC-002
RTO / RPO and financial transaction reconciliation
Choose a recovery point, calculate the critical path and RTO margin, reconcile restored transactions against a reference and justify GO / NO-GO.
LAB 4D5-BALTNET-LEARN-003
Behaviour change and closing lesson actions
Separate attendance, improved behaviour and proven completion of an action; design a 20-minute blameless re-run of the tabletop.
Carry on in your environment
Related tools
CISO.lt
ciso.ltInformation security officer's assistant
After the course, build your organisation's incident management plan, report templates and security culture measures with CISO.lt.
- Security policy and procedures
- Incident management plan and notification
- Risk assessment
- NIS2 / GDPR compliance checklists
Methodological basis and sources
Full programme
Full programme