
Construction
Safespy team members designed and delivered a board-level cyber exercise for the senior leadership of the world’s largest construction project. The exercise tested leadership decision-making, supply chain readiness, and the role of third-party security providers under cyber and insider threat scenarios.
The challenge
Operating at an unprecedented scale, the project involved huge international supply chains, complex data flows, and a tangled web of third-party dependencies.
Leadership wanted assurance that both internal teams and external providers could respond effectively to a cyber or insider incident, and that Board members understood the steps required to manage disruption.

The tabletop exercise
We facilitated a Board-level tabletop exercise tailored to the client’s environment and threat profile.
​
-
Senior leadership were immersed in escalating cyber and insider threat scenarios.
​
-
Responses from internal teams and third-party providers were stress-tested against realistic timelines and impacts.
​
-
An immediate Board debrief captured executive reflections while fresh.
​
-
A detailed After Action Report followed, including recommendations and scheduled calls to work through required improvements.

Lessons learned
The exercise provided leadership with:
​
-
Clear visibility of strengths and weaknesses across internal and third-party response.
​
-
A deeper understanding of how insider threats intersect with cyber risk.
​
-
Evidence that Boards need structured playbooks for decision-making under pressure.
​
-
A roadmap for enhancing contracts, communications, and escalation with external providers.
​
By confronting real-world scenarios in a safe environment, the Board left with greater confidence — and a clear agenda for strengthening resilience across one of the most complex construction programmes in the world.
