Skip to content

Day 5

Culture, exercises, system recovery and lessons learned

Participants can prove that recovery is safe, monitored, approved by the business owner, and turned into measurable improvement actions.

Training case
D5-BALTNET-REC-001
Programme topics
8, 9, 10
Assignments
P1 · P2 · ID-05

Where this day sits in the chain

Sequence: culture, exercises, recovery, report, lessons.

Rule of the day

A restored backup ≠ a restored service. A lesson ≠ a closed action.

Schedule

How the day runs

TimeTopicFormatOutput
09:00–09:45Security culture; learning and awareness strategiesTheoryBehaviour and competence evidence
10:00–10:45System recovery and lessons learnedTheoryRecovery gates and metrics
10:45–12:00Recovery tabletop exercisePractical P1Recovery plan and GO / NO-GO
13:00–13:45Business recovery and technical reportingTheoryOne fact base, two audiences
13:45–15:00Technical recovery reportPractical P2Report, summary and lessons
15:15–15:45Knowledge checkTestKahoot
15:45–16:00Lessons and reflectionDiscussionPersonal transfer action
Breaks: 09:45–10:00, 12:00–13:00 (lunch) and 15:00–15:15. Sessions run online.

Learning outcomes

By the end of the day, participants can

  1. D5.1Separate declared culture from observed safe behaviour and choose a behaviour metric.
  2. D5.2Define a safe exercise objective, an inject, an observation criterion and a STOP condition.
  3. D5.3Tell containment, eradication, recovery and return to production apart.
  4. D5.4Sequence recovery by service dependencies, RTO / RPO and risk.
  5. D5.5Justify GO / NO-GO with evidence, approvals, monitoring and rollback.
  6. D5.6Write a technical report and an executive summary from one fact base.
  7. D5.7Turn a lesson into an action with an owner, a deadline and verifiable evidence of success.

Practice

Practical assignments

Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.

  1. P1

    Recovery tabletop exercise

    Sequence by dependencies, RTO / RPO and risk; every GO has evidence, an owner and rollback. Controlled injects with a clear STOP condition.
    Duration:
    75 min
    Deliverable:
    Recovery plan and validation sheet
  2. P2

    Report and lessons

    One fact base for two audiences; unknowns marked, no unfounded data-exfiltration claims; measurable actions.
    Duration:
    75 min
    Deliverable:
    Technical report, executive summary, actions

Extra labs

For deeper practice

The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.

  • LAB 3D5-BALTNET-REC-002

    RTO / RPO and financial transaction reconciliation

    Choose a recovery point, calculate the critical path and RTO margin, reconcile restored transactions against a reference and justify GO / NO-GO.

  • LAB 4D5-BALTNET-LEARN-003

    Behaviour change and closing lesson actions

    Separate attendance, improved behaviour and proven completion of an action; design a 20-minute blameless re-run of the tabletop.

Carry on in your environment

Related tools

  • CISO.lt

    ciso.lt

    Information security officer's assistant

    After the course, build your organisation's incident management plan, report templates and security culture measures with CISO.lt.

    • Security policy and procedures
    • Incident management plan and notification
    • Risk assessment
    • NIS2 / GDPR compliance checklists

Previous day

Day 4: Incident investigation, threat hunting, playbooks and SOAR

Day 4

Full programme

Full programme