We build websites, we host websites, and we would quite like them to stay online. So Planet IT's cyber security event at Milton Park had our attention. The day gave our team a rare chance to sit inside a cyber incident as it unfolded, without anyone actually having to phone their insurer, hide under a desk or explain to the board why the website had vanished. Through a live simulation, our team saw how quickly small warning signs can turn into much bigger problems, and how much harder decisions become when technical uncertainty, commercial pressure and human instinct all pile in at once. We came away with the questions every organisation should ask before something goes wrong, and were quietly relieved that most of them were ones we'd already asked ourselves.
A small typo, a slow website and a very bad day
A member of staff clicks a link in an email.
It looks convincing. The sender seems familiar. Nothing explodes. No dramatic red skull appears on screen. Nobody in a black hoodie starts cackling in a dark room lit only by command line windows.
A little while later, their computer feels slow. Some files are missing. Elsewhere, the webstore is crawling, but it is launch day and extra traffic was expected. The business has national press in the office, a major new product going live, and a lot of people who really, really need everything to work.
So what do you do?
That was the setup for Planet IT’s cyber security event at Milton Park, where the Versantus team spent the day taking part in a live cyber attack simulation. The event split attendees into two parallel groups, one for technical teams and one for business leaders, with both sides responding to the same unfolding incident from very different angles.
It was interesting. It was uncomfortable. It was also a useful reminder that cyber incidents are not just technical problems. They are decision-making problems, communication problems, authority problems and, very often, human problems.
Cyber security is a specialist field, and events like this are a useful reminder that there is always more to learn. What we took away were questions, prompts and practical reminders that are worth bringing back into any organisation that depends on digital systems, client data, websites, cloud services or email. For most businesses, that makes it a conversation worth having sooner rather than later.
The warning signs do not always wave a flag
In a controlled cyber simulation training room, everyone knows something bad is coming.
That is the whole premise. You have turned up to a cyber security event. You are not there because someone wants to show you a perfectly healthy IT setup and then send you home with a sandwich.
But even with that knowledge, it was easy to see how a real incident could creep up on a team.
A slow website on a big launch day might be heavy traffic. A missing file might be user error. A sluggish laptop might be one of those annoying laptop things that happens because laptops enjoy testing the limits of human patience.
At each stage, the sensible response in the moment was not always the dramatic one.
- Do you investigate the suspicious email?
- Do you check the affected server?
- Do you pause and gather more evidence?
- Do you shut everything down?
The uncomfortable question is this one. At what point does being measured become being too slow?
That is not an easy call to make when the company is under pressure, customers are waiting, senior people want answers and the press are in the building. It is even harder if nobody has already agreed who has the authority to make the big decisions.
Having the tools is not the same as being ready
It is tempting to think about cyber security as a shopping list.
Buy the software. Set the rules. Add the monitoring. Make everyone use multi-factor authentication. Tell people not to click weird links. Sit down with a cup of tea.
The simulation made it feel much messier than that.
Tools matter, of course. Processes matter too. But the day kept coming back to judgement under pressure. People had to make decisions with incomplete information, while other parts of the business were asking why systems were slow, why customers were leaving the webstore, and why the IT team had not magically fixed everything yet.
That pressure makes decision making even trickier.
If a two-person IT team believes there is a serious incident unfolding, can they shut down servers? Should they? Who do they need to tell first? What happens if the CEO disagrees? What happens if waiting another ten minutes gives attackers more time to delete data, damage backups or move through the business?
These are not questions you want to answer for the first time while something is actually on fire.
Write the playbook before everyone needs it
One of the strongest takeaways from the day was the need for a playbook.
Not a 200-page document that lives in a forgotten folder and gets opened once every three years when someone remembers compliance exists. A useful playbook. One that sets out likely scenarios and helps people make calm decisions when the situation is not calm.
For a digital team, those scenarios might include things like:
- A client calls to say their website has disappeared.
- A platform shows signs of unexpected data loss.
- Users suddenly cannot log in.
- A server is behaving oddly.
- A third-party service reports a breach.
- A staff account appears to be compromised.
The point is not to predict every possible disaster with eerie precision. The point is to agree the basics before the pressure hits, and make sure everyone knows their role. This is just the sort of thing we keep written down for the sites we host, less impressive-sounding than it should be, right up until the day you need it.
Who is responsible for the first response?
Who communicates with clients?
Who decides whether systems should be taken offline?
What is the threshold for calling in external help?
Incident response is a business issue, not (just) a tech team problem
A cyber incident response plan can sound like something for technical teams, but they cannot carry it alone. The simulation made that clear. While the technical room was trying to understand what was happening, the business room was dealing with press pressure, launch expectations, customer impact and internal concern.
A good plan helps bridge that gap. It should set out roles, responsibilities, escalation routes and decision points, so people know who does what, when to escalate and who has the authority to make bigger calls. It should also be tested, even if that just means gathering the right people, picking a scenario and talking through what you would do.
You may discover that nobody knows who owns a key account, your emergency contact is out of date, or your plan relies on a shared document that nobody can access if accounts are locked. Better to find that out over coffee than during an actual breach.
What happens if work has to stop?
An incident response plan asks what you do when something bad starts happening. A business continuity plan asks what you do if normal work is no longer possible.
What happens if your team cannot access email, your project management system is unavailable, client sites or hosting dashboards cannot be reached, or restoring service takes days rather than hours? In the simulation, the fictional business took weeks to get fully back up and running. The financial and operational impact was huge.
That is where cyber security stops feeling like a technical side quest and starts looking very much like business survival.
For agencies, charities, care providers, universities, ecommerce teams and membership organisations, digital systems often sit at the centre of day-to-day activity. The website is not just a brochure. The CRM is not just a database. The booking system, ecommerce platform, intranet, payment process or learning platform may be central to how the organisation functions.
How would you keep serving people if the systems you rely on were unavailable?
Backups and insurance are not magic buttons
Backups are reassuring until you start asking awkward questions. Do you know where they are, how often they run, who can restore them and whether they have actually been tested? In the simulation, the attackers had also damaged the backups, which meant “just restore everything” was not the simple escape route everyone hoped for.
Insurance can feel like another safety net, but it has its own conditions. If systems are wiped too quickly, useful evidence may disappear with them, which could affect investigations or claims. That does not mean doing nothing, it means knowing the process before panic sets in. Backups and insurance matter, but they are not a plan on their own, which is exactly why we test ours, rather than crossing our fingers and hoping past-us set them up properly.
The pressure is the point
The part that stayed with us was not the technical detail. It was the pressure around it. On paper, “shut things down quickly” sounds obvious. In the room, with a product launch happening, customers waiting and senior people asking for answers, it suddenly felt much less tidy.
Nobody wants to be the person who pulls the plug because of one suspicious email. Nobody wants to wait politely for more evidence and then realise the attackers have been having a lovely time in the background. That is why preparation matters. Not because it makes the decision easy, but because it gives people something steady to work from when the situation is anything but.
A good plan gives technical teams permission to escalate, helps leaders understand the risk, and gives client-facing teams a calmer way to communicate. With a bit of luck, it also means the first proper conversation about cyber incidents does not happen during an actual cyber incident.
A useful day at Milton Park
A big thank you to the Planet IT team for organising such a thoughtful event and for having us along.
The live simulation made the subject feel immediate in a way that a slide deck rarely can. It showed how quickly small signs can become serious, how easily pressure can cloud decisions, and how important it is to prepare before you need to.
We came away with a clearer sense that cyber security is not just about stopping bad things from happening. It is also about knowing how to respond when something does not feel right.
Because the question is not just, could this happen to us?
It is, if something strange happened tomorrow morning, would we know what to do first?
For the organisations whose sites we look after, we've done our best to make sure the answer is yes, ideally before tomorrow morning ever arrives."