Taking the Cyber Drill to the World Stage: My Session at The World CIO 200 Summit Grand Finale, Sri Lanka
Most incident response plans fail on paper before they fail in production. Nobody reads them until the breach is already happening, and by then it’s too late to discover the plan assumed a team that no longer exists, or a vendor contact who left the company two years ago.
That’s the problem a cyber drill is meant to solve, and it’s why I’m honoured to say I’ll be delivering the Cyber Drill Workshop at the Grand Finale of The World CIO 200 Summit, hosted by Global CIO Forum and Global Enterprise Connect, taking place 22 to 24 September 2026 in Sri Lanka.
This isn’t a small room. The Grand Finale brings together CIOs and CISOs from more than 59 countries, closing out a year of regional summits with the people who actually carry the risk decisions back to their boards. Being asked to run the cyber drill session in that room, as CISO of Morgan State University and NATO Cybersecurity Advisor, is one I don’t take lightly.
What the workshop actually covers
I’m not walking in with slides and a lecture. A cyber drill only earns its name if it puts people under the same pressure a real incident does: incomplete information, conflicting priorities, and a clock that doesn’t stop for a coffee break. The session will work through:
- A live-fire simulation built around a realistic multi-stage attack, not a sanitised case study
- The decision points where CIOs and CISOs typically stall: communication breakdowns, unclear escalation ownership, and the gap between the written plan and what actually happens in the room
- How to translate a tabletop exercise into board-level assurance, because a drill that never reaches the board is a drill that never gets funded again
- Lessons from running this exact format at Morgan State University, across 53 buildings and roughly 11,000 students, where the constraints are different from a Fortune 500 but the failure modes are the same
Why this matters beyond the room
Cybersecurity leadership from 59 countries means 59 different regulatory environments, threat landscapes, and boardroom cultures, but the core failure I see everywhere is the same: organisations plan for the incident they can imagine, not the one that actually shows up. A good drill exposes that gap while it’s still cheap to fix.
I’ll be publishing a full recap of the sessions, key takeaways, and what I heard from other CIOs in the room, so if you’re not able to attend in person, check back here after the Summit.
If you’re attending #CIO200GrandFinale, come find me, I’d rather compare notes in person than on LinkedIn.
Regards,
Dr Erdal Ozkaya
