There's a type of crisis exercise that's really just designed to be "survived", to be passed without anyone looking bad. The scenario is easy, the unexpected events (injects) are gentle and predictable, everyone plays their role well, and the after-action report praises the organization for being ready. But this kind of exercise is just theater. And it's actually worse than doing no exercise at all, because it creates a false sense of confidence.
The purpose of failure
An exercise is a tool for finding weaknesses while they're still cheap to fix. So its value is directly tied to what actually breaks. If a simulation breaks nothing, it hasn't really measured anything, except how gentle the scenario was. Yet it still produces the same comfortable, confident feeling as genuine readiness. And that's exactly the danger.
High-reliability organizations flip this instinct on its head: they treat an exercise that reveals no failures as a failed exercise, and they redesign it.
“Failing well” means failure that is planned, clear, and contained::
- Designed
because the exercise deliberately stresses the specific parts of the organization you chose to test. - Clear
when something breaks, you can name exactly what it is and fix it. - Contained
it breaks in a safe setting (a room, on a Tuesday, with coffee), not in the real world where it would cause real damage.
Stress the joints, not the people
The useful things an exercise should be testing are rarely individual people. Instead, they're the connections between functions or teams, because that's where real incidents actually fail.
- Decision rights under ambiguity.
Design your exercise's unexpected events (injects) around situations where it's genuinely unclear who should make the decision; for example, an operational call that also carries legal risk, or a communications call that also affects safety. Then watch whether the decision-making rules you agreed on in advance actually hold, or whether they collapse into "whoever is most senior decides." - Information flow.
Feed different pieces of information to different participants, some of it contradictory, and one or two pieces deliberately wrong. The test is whether the organization can assemble a shared picture that clearly separates what's confirmed from what's assumed, or whether three different versions of reality end up running in parallel. - The approval bottleneck.
Every organization has a bottleneck, usually the point where communications and legal have to sign off together. Time how long that takes. If your exercise measures how long a holding statement takes to get approved, you'll get a concrete number that leadership will remember. - Tempo under fatigue.
At least once a year, run an exercise that goes beyond the comfortable two hours. The quality of decisions made at hour five is a completely different thing from the quality of decisions made at hour one, and leadership should experience that reality in a rehearsal, before it happens for real.
Design principles
Objectives as hypotheses. Write each exercise objective as something that can be proven or disproven, like "the crisis team can produce a cleared external statement within 45 minutes." That way the exercise can genuinely confirm or refute it. But if you phrase objectives as vague themes, like "test communications" you'll end up with findings that are just compliments.
Real decisions, real margins. Participants should create the real outputs needed for an incident—like the official statement, the list of stakeholders to call, and the decision log. Don’t just talk about what you’d create. Describing instead of doing can hide problems.
Senior participation, not observation. If an exercise is just watched by executives from the sidelines, it’s testing the wrong people. The biggest mistakes in real incidents happen at the leadership level and those mistakes only show up when leaders are actively involved.
No-fault capture, sharp findings. The environment should encourage people to speak up but expose flaws without mercy. Findings should focus on systems, processes, and workflows—not individuals—and must be written clearly. If a problem is sugarcoated, it will resurface during a real crisis, and the cost will be much higher.
The exercise report that matters fits on one page: what broke, why, who owns the fix, and when it is retested.
The fix cycle is the point
An exercise program is an ongoing cycle, not a one-time event: stress the system, find the weaknesses, fix them, and test again. Every issue gets assigned to someone with a deadline. The next exercise should retest past fixes and new areas. After a few rounds, you don’t just have a team that’s seen a scenario you have an organization that’s already uncovered and fixed its weak spots before a real crisis does.