Summary
The core value of “Under Pressure: Survive the Crisis” was to make cyber crisis response tangible by placing participants inside a simulated crisis management team rather than asking them to passively listen. Kelvin Rorive and Jelger Groenland of CCRC framed the workshop around the belief that organizations often invest heavily in prevention, while spending too little time training how to respond once a crisis hits. The audience was asked to become the crisis management team of Break X, a fictional 65-year-old family manufacturer of brake discs in the East of the Netherlands, and to make pressured decisions with incomplete information.
The scenario centered on a supply-chain and operational-quality incident. Break X depends on Auto Tech Industries, its largest customer and source of 40% of revenue, and on FactoSense, a critical sensor and cloud-platform supplier whose AI model interprets production processes. On September 28, FactoSense reports a vulnerability in its solution, with no evidence yet of exploitation, advises restricting network access to sensors and monitoring measurements closely, and says a patch is expected within 48 hours. Minutes later, Auto Tech reports brake discs with 20% lower hardness than expected, 230 vehicles already fitted, installation stopped, and a recall being planned. Internally, Break X’s quality manager finds insufficient hardness caused by temperature deviation, a mismatch between the FactoSense dashboard and actual furnace temperatures, and 1,200 to 1,500 possibly unsafe discs.
Round one forced participants to decide whether to disconnect FactoSense and stop production, identify their three most important actions, and determine whom to call in which order. One group chose to continue production with manual quality checks, preserve communication with the largest customer, investigate the sensor issue, involve legal and authorities, and disconnect the internet connection while ignoring suspect dashboard figures. Another group emphasized disconnecting or isolating the sensors from production decisions before moving to manual measurement and contacting affected customers and the NCSC.
The facilitators used the feedback to surface the real lesson: crisis teams must act before they fully understand whether events are connected, accidental, or malicious. They challenged participants to consider consequences such as losing supplier measurement support when disconnecting systems, and to avoid prematurely assuming a cyberattack just because the setting is a cyber drill. The most important reflection was that in a serious crisis, many things happen in parallel, information is incomplete, pressure is high, and the team must quickly align, communicate, and make defensible choices.
Key Topics
5 key topics from Kelvin Rorive and Jelger Groenland at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Train crisis response together before incidents occur.
- Separate confirmed facts from cyberattack assumptions.
- Prioritize customer, supplier, authority, and legal communications.
- Use manual controls when automated measurements become suspect.
- Assess operational consequences before disconnecting critical systems.
“when a crisis hits and you don't know that much, but you feel in your stomach that this is not right.”
Up Next


Next in agenda
3 Practical Leadership Strategies to Retain Cyber Talent



Also on incident response
Blended Threats, Blurred Lines


Also on incident response
