• Overview
  • FAQ

Join us for the members only 2025 CAPS Insurance cyber attack incident response exercise

Build a stronger incident response team

The CAPS virtual tabletop exercise challenges your incident response team to evaluate a fictional organization’s response to overcome a simulated attack against operations and processes. Participants practice mobilizing quickly, working under pressure, critically appraising information as it becomes available, and connecting the cyber dots to defend against an attack. One individual registers and leads your internal team through a virtual exercise. The exercise follows a realistic, timely scenario. 

Participating in the exercise helps your team

  • Strengthen team relationships and cross-functional knowledge
  • Develop a clearer understanding of system vulnerabilities
  • Explore improvements in processes and build stronger response plans

Gain maximum benefit with minimal resources

  • Take part virtually using our materials in a confidential tabletop exercise
  • The exercise requires only a few hours for each part
  • Participate in the CAPS survey to privately assess your internal processes and gain unattributed peer data for comparison

Take advantage of this exclusive membership benefit. CAPS 2025 is a members-only benefit and is included in FS-ISAC membership at no additional cost.

Register now for the CAPS Insurance Exercise through the FS-ISAC Intelligence Exchange Members Services app or click here: Insurance. Registration closes on 17 October. 

CAPS exercise registrants who coordinate the exercise team will need current VIDEO and CONNECT access to participate.

CAPS is for FS-ISAC members only. If your organization is not yet a member of FS-ISAC, join today. 

FAQ

Why participate?

Event Toggle Arrow

Pervasive vulnerabilities and cyber attacks are a serious source of risk for today’s enterprise. Security breaches, system compromises, and other cybersecurity issues are common and can be severe. FS-ISAC CAPS enables you to put into practice your processes, plans, and resources in response to a cyberbreach. You assess your exercise experience and preparedness while receiving insights on best practices and readiness at your organization and across the financial services industry. Regulators recommend participating in cyber threat exercises like CAPS to support an organization’s resilience, testing, and training.

Who should participate?

Event Toggle Arrow

All FS-ISAC members in the insurance industry.

Who should be involved in my company?

Event Toggle Arrow

You designate one person as the primary contact to register your company and coordinate the exercise internally. Your primary contact receives all communications about the exercise, including the FS-ISAC CAPS Pre-Exercise Guide, to help prepare for the exercise by accessing a private Channel in FS-ISAC CONNECT. Prior to the exercise, your Coordinator, who registered for the exercise, accesses instructions, materials, and links to lead the exercise. From your own premises, and on your own schedule, your team reviews and discusses the information available and confidentially answers a set of self-assessment survey questions; you submit the single compiled survey to an Alchemer link.

Where does the exercise take place?

Event Toggle Arrow

At your premises, virtually, with our materials, your staff, and your timing. 

How long does the exercise take?

Event Toggle Arrow

On average, teams work together for a few hours for each part of the exercise.

What time is the exercise?

Event Toggle Arrow

Your team may undertake the exercise during CAPS season on any day(s) and time(s) on your own schedule between 2 September and 17 October. You retrieve the instructions and materials prior to the exercise and set your schedule to best fit the participants and organization. You plan your own schedule.

How can a standard exercise work for my organization?

Event Toggle Arrow

The exercise applies to all types and sizes of financial services firms, with each team adapting it as necessary, “as they go,” to suit the specific organization participating. 

How will the results be meaningful to my organization?

Event Toggle Arrow

Survey results are anonymous; however, general demographic questions such as asset size, country code, and industry help us to compile a useful benchmark-type report that most participants find helpful. These results, combined with your extensive team discussions during the exercise, are qualitatively valuable as well. 

Who creates the exercise?

Event Toggle Arrow

FS-ISAC member volunteers work together with FS-ISAC staff to develop scenarios based on current trends and emerging threats; develop questions for discussion and response in the daily feedback survey, to help participating teams assess their preparedness; and script and record roles as members of the incident response team meetings presented in the exercise. 

What is the after-action?

Event Toggle Arrow

In the month following the exercise, we collate and tabulate the survey results. You will receive a copy of the results and an invitation to a presentation of the findings, hosted and facilitated by FS-ISAC.