Incident Management Training For Consulting Teams

incident management training for consulting teams

At 06:40 on a Tuesday, a building manager closes a consulting firm’s Manchester office. A burst water main has cut the power overnight. Forty consultants are due in, a client workshop is booked for 09:30, and the incident plan says the office incident lead decides what happens next.

The person named in that role moved to another practice in the spring. The deputy has never opened the plan. So the questions pile up: who tells the forty people already on trains, does the workshop move, who calls the client, and can a deputy close an office without asking a partner?

The plan answers every one of those questions. Nobody on duty that morning has ever been asked to give the answers against a clock, and that is the gap incident management training for consulting teams is meant to close.

The firm in this example has 600 staff across four UK offices, most of them at client sites on any given day. It can’t get twenty people into a room for an afternoon. This article is organised around what it can do instead: sessions of ten, fifteen and sixty minutes that fit around client work.

Incident Management Training For Consulting Teams Means Practice, Not A Course

Incident management training for consulting teams is the practice that prepares partners, engagement leads, office managers and consultants to carry out their part of the firm’s incident plan. It covers who holds each role, how alerts are sent and acknowledged, when a problem is escalated, and how the firm records what it learned afterwards.

A course tells people what the plan says. Practice shows whether they can follow it, and the consulting model makes practice hard to arrange. Consultants spend their weeks at client sites, engagement teams form and dissolve every few months, and utilisation targets make an unbilled afternoon hard to justify.

The plan drifts in the meantime. Three things go stale first:

  • Named role holders, as people change practice, get promoted or leave
  • Contact details, especially personal mobiles and out-of-hours numbers
  • Engagement lists, which decide who needs to hear about a problem at a given client site

The earlier article on incident coordination for consulting teams covered how hard it is to say who is where on a normal day. Short, regular practice shows whether that picture holds on a bad one.

Ten Minutes: Role Cards And Escalation Questions

Two kinds of practice take ten minutes each. A role card walkthrough is done once with each role holder, and an escalation question is put to a team at the end of a regular call.

Walk Each Role Holder Through One Page

A role card walkthrough takes ten minutes per person and answers the question the Manchester deputy couldn’t: what is this role allowed to decide? Role clarity means every person named in the plan knows they are named, knows what they can decide, and knows who covers for them.

The card is one page. For an office incident lead it might hold five things:

  • The decisions the role can take alone, such as closing an office for the day
  • The decisions that need a partner
  • The first three actions, and how long each should take
  • The named deputy, and who covers for the deputy
  • Where the plan and contact lists are kept when the office network is unavailable

The deputy’s problem at 06:40 isn’t ability. Nobody told them the role came with authority to close the building, so they wait for a partner who is asleep. Training should start with the role card, because a scenario only tests roles that people already recognise as theirs.

Put One Escalation Question On A Team Call

An escalation question practises the moment someone decides a problem is no longer theirs to handle alone. Plans describe escalation as a threshold. In practice it’s a judgement made by one person with partial information, often someone who doesn’t want to wake a partner.

Give an engagement lead a situation and ask: do you escalate, to whom, and what do you say? Prompts that suit a consulting firm include:

  • A consultant reports that the client’s building has been evacuated and nobody has told visitors where to go
  • A consultant travelling overseas has missed two agreed check-ins
  • A client calls to say its systems are down and asks whether the firm’s laptops on its network are affected
  • An office is closed and a client workshop is due to start there in three hours

The first two prompts draw on the firm’s duty of care at client sites and during travel. The third raises the question of keeping clients informed during an incident. One prompt a month, at the end of a team call, shows whether engagement leads share one view of when to escalate.

Fifteen Minutes: Send A Drill And Count The Replies

A communication drill tests one thing: whether a message reaches the people it should and whether they confirm it. It takes fifteen minutes, needs nobody in a room and can run while consultants are at client sites.

A drill message should say plainly what it is. For example:

“DRILL. This is a test of the Manchester office incident group. There is no incident. Please acknowledge this message within 15 minutes. No other action is needed.”

What comes back matters more than what went out. A delivered message isn’t a confirmed one, so the numbers to record are these:

  • How many people acknowledged within the 15 minutes
  • Who never acknowledged, and whether their details were wrong or the message was ignored
  • How long the sender took to find the right group and send
  • Whether anyone who has left the office or the engagement was still on the list

Emergency communication software can send the drill and count the acknowledgements, but the test is just as valid on whatever channel the firm would use for real. Run quarterly, a drill keeps contact data honest and makes the alert familiar before the first real one arrives.

Sixty Minutes: Run A Virtual Tabletop

A tabletop exercise puts the role holders on one call and walks them through a single scenario as it unfolds. The UK Resilience Academy’s Exercising Best Practice Guidance defines an exercise as “a process to train for, assess, practice and improve performance in an organisation”. It describes the tabletop as “a structured, collaborative discussion”, and it can be run virtually.

An hour is enough if the scenario is one the firm could really face. The Manchester closure would do. The facilitator reads out what is known at 06:40, 07:15 and 08:30, and at each point asks the role holders what they decide and who they tell. The useful moments are the ones where two people describe the same decision differently.

Twice a year suits most firms. Those that want a cyber scenario without writing one can use the National Cyber Security Centre’s free Exercise in a Box, which offers ready-made tabletop and micro exercises. A live exercise, which tests the full response in real time, is worth the extra cost once the shorter sessions stop producing surprises.

After Every Session: Who Owns The Fix?

Lessons learned are the changes a firm makes after an exercise, and they only count once each change has an owner and a date. A debrief that ends with a list of observations and no names will produce the same list at the next exercise.

The National Cyber Security Centre’s guidance on building and maintaining incident response capability says exercises “can help you to identify gaps that may have appeared, as well as provide your team with experience and practice”. A short debrief straight after each session catches what people noticed while it’s fresh. Three questions are enough:

  • What did the plan say would happen, and what happened instead?
  • Which decision took longest, and why?
  • What needs to change, who owns the change, and by when?

The Manchester firm’s first drill would probably have surfaced the departed incident lead within fifteen minutes. That finding becomes a lesson learned once the role card is reissued and the new lead has walked through the first three actions.

A Signed-Off Plan Is Not A Trained Team

A signed-off plan shows that someone wrote down what should happen. It doesn’t show that the people named in it can do it. The UK Resilience Academy guidance says so directly: “Planning and preparation for risks cannot be considered reliable until they have been exercised and shown to be workable.”

The figures on cyber security show how common the gap is. In the government’s Cyber Security Breaches Survey, 23% of UK businesses have a formal incident response plan (DSIT 2025). Only 19% provided any staff training or awareness raising on cyber security in the previous 12 months (DSIT 2025). A general awareness session is also a long way short of rehearsing a named role in a specific plan.

Where safety is concerned, training is a legal expectation. In Great Britain, regulation 13 of the Management of Health and Safety at Work Regulations 1999 requires employers to provide adequate health and safety training when employees are recruited, and again when a change of responsibilities exposes them to new or increased risks. A deputy who inherits an incident role has had a change of responsibilities, and the firm should ask whether its training kept pace.

A Year Of Practice On One Page

Put together, the sessions make a programme that asks each role holder for roughly four hours a year. The table below is a starting point, and the timings are typical rather than fixed.

When

What to run

Time per person

January, and whenever a role holder changes

Confirm who holds each role, issue role cards, walk through each one

10 to 20 minutes

Once a month

One escalation question at the end of a team call

10 minutes

Once a quarter

A labelled drill message to one office or engagement group

15 minutes

Spring and autumn

A virtual tabletop on one realistic scenario

60 to 90 minutes

After every session

A debrief with an owner and a date for each change

10 minutes

Once a year

A full review of the plan against what the sessions found

A morning for the plan owner

Start with the first row. A firm that only confirms its role holders and walks each of them through one page has already removed the failure in the Manchester example.

What Crises Control Adds To Drills And Exercises

Exercises often show that the tools used on the day were the everyday ones. Crises Control’s own description of that gap is that communication tools send notifications but don’t coordinate ongoing updates, acknowledgements or response activities, and that email, spreadsheets and manual processes make it difficult to maintain an accurate incident record.

Crises Control is an Operational Incident Coordination Platform, and a firm can run its practice sessions on the same platform it would use in a real incident. The fifteen-minute drill is a job for Ping. A labelled drill message goes to one office or engagement group by SMS, voice call, email, push notification or Microsoft Teams, recipients acknowledge with one tap, and every delivery and acknowledgement is recorded. The list of who never replied is there when the fifteen minutes are up.

A tabletop can go a step further with Incident Manager. Authorised users launch the predefined response plan for the scenario, with its message templates and recipient groups, so role holders practise on the plan they would really use. Task Manager then tests whether the actions get done. Tasks are assigned to a named owner or team when the plan is activated, owners accept them and update their status from any device, and escalation rules pick up any task left overdue or unclaimed.

Every communication, acknowledgement, update and decision is timestamped and kept as an exportable record, which gives the debrief something firmer than memory. For the people who will run those sessions, the Crises Control Academy provides on-demand, self-paced video training on operating the platform, included with a subscription. The page on incident management for legal services describes the same approach in a professional services firm working across offices, practice areas and time zones.

The platform doesn’t design a firm’s exercises, decide who should hold which role or judge whether an escalation was right. Those remain the firm’s decisions.

The Same Morning, With Practice

A Manchester firm that had run one drill and one walkthrough would have had a different 06:40. The deputy closes the office, forty consultants get one message and acknowledge it, and the engagement lead calls the client about the workshop before 07:30.

Most consulting firms can already alert their people. Coordination is the next step up: named people making the decisions the plan gives them, in order, with others able to see what has been decided. That morning doesn’t need a better plan. It needs one that people have used before.

Request a free demo today!

Frequently Asked Questions

Incident management training for consulting teams is the practice that prepares partners, engagement leads, office managers and consultants to carry out their part of the firm’s incident plan. It combines role card walkthroughs, communication drills, scenario exercises and a debrief after each one.

A consulting firm should run a short communication drill every quarter and a tabletop exercise about twice a year. The National Cyber Security Centre recommends a full review of incident response plans and playbooks at least yearly.

A communication drill tests whether a message reaches the right people and whether they acknowledge it, and it takes about fifteen minutes. A tabletop exercise is a structured discussion in which role holders work through one unfolding scenario and explain the decisions they would take.

Emergency response training should include everyone named in the incident plan, which usually means partners, engagement leads, office managers and their deputies. Consultants who hold no named role still need to know how an alert will arrive and how to acknowledge it.

No, software does not replace exercises. It gives a firm a structured way to launch plans, send messages and keep a record, but people still have to practise the decisions their roles carry. Incident management training for consulting teams covers both parts: how to use the tool and how to perform the role.

This article was drafted with AI assistance and reviewed by the Crises Control team. Featured image: AI-generated.

Shalen Sehgal

CEO & Co-Founder

Since co-founding Crises Control, Shalen has focused on helping organisations strengthen operational resilience through coordinated incident management, emergency communication and business continuity. His work is centred on enabling organisations to respond to critical events with greater visibility, accountability and confidence.

← Blogs

How Crises Control Helps

From first alert to final report. One connected platform.

Crises Control combines incident alerting, response coordination, task management and automatic audit trail creation so organisations can manage every emergency while staying fully compliant.

Stop reacting. Start coordinating.

See how Crises Control gives your organisation control during every incident and defensible proof after it.

No commitment required. See the platform in action with your own use cases.