Executive opening
Attendance may be high. The scenario may be completed. Participants may agree that the exercise went well. Yet those signals do not necessarily show whether people can make decisions with incomplete information, challenge a senior assumption, move intelligence between departments, or recover when the original plan no longer fits.
That distinction matters. Organisational risk is managed by building the capability to recognise disruption, decide, coordinate and learn.
This is the leadership value of organisational resilience analytics Australia needs: a structured way to examine behaviour under pressure and whether learning is sustained.
OEX and OCI can support that conversation. In this article, OEX refers to the six evidence dimensions surfaced through the organisational exercise intelligence view: Robustness, Exposure, Blind Spots, Trust, Adaptability and Recovery. OCI, the Organisational Confidence Index, expresses the level of confidence supported by available evidence—from assumed or developing confidence through to evidenced or demonstrated confidence, with insufficient evidence remaining visible.
Neither is a substitute for judgement, assurance or incident experience. Their value is in helping leaders ask better questions of the evidence produced by tabletop exercises.
Why a completed exercise is not the same as resilience
Traditional exercise reporting often concentrates on completion:
- Was the exercise delivered?
- Did the right people attend?
- Were the objectives marked complete?
- Was the plan or playbook followed?
- Were actions recorded afterwards?
These are useful controls. They are not useless. But they are weak proxies for durable resilience when treated as the whole assurance picture.
A point-in-time pass or fail can hide important variation. A team may follow a familiar script because the scenario is predictable, while a senior decision-maker resolves ambiguity personally and conceals an authority gap. Participants may notice a serious weakness but choose not to challenge the room.
The Australian Institute for Disaster Resilience’s Managing Exercises handbook treats evaluation and lessons management as core parts of exercise practice. The exercise is not the product; learning and corrective action are part of the product. A tabletop observation is not proof that the same behaviour will occur in a live event.
The more defensible question is therefore not, “Did we pass?” It is:
“What did this exercise reveal about our ability to resist, respond, recover and improve—and what evidence will show that we acted on it?”
That question moves the board from event assurance to organisational risk management.
The Australian context: resilience is an accountability issue
Australian organisations face different legal and regulatory obligations, but the direction of travel is clear: critical services, material risks, third parties, cyber threats and crisis decisions require active oversight.
For APRA-regulated entities, CPS 230 places accountability for operational risk management, business continuity and material service-provider arrangements with the board and accountable executives. A tabletop is one input into that assurance—not evidence, by itself, that tolerances can be met in reality.
ASIC’s 2026 Key issues outlook identifies cyber-attacks, data breaches, inadequate operational resilience and crisis management as risks that can undermine market confidence and harm consumers. The precise duties depend on the organisation and regulatory perimeter; this is not legal advice. It is a reminder that resilience cannot be delegated entirely to a specialist team.
The Australian Government Crisis Management Framework emphasises coordination mechanisms that bring stakeholders together and support expert-informed decisions. Leaders should see how information reached the decision-maker, which authority was used and whether dependencies were visible.
Longitudinal analytics can show patterns in authority, trust, communication, timeliness, governance and recovery. They cannot guarantee performance in a real crisis, but can make an anecdotal risk easier to examine, prioritise and retest.
What longitudinal tabletop analytics can reveal
Longitudinal analysis compares evidence across runs, scenarios, teams or time periods. The comparison must be disciplined: scenarios, participants and scoring conditions can change, and familiarity can improve performance without representing broader capability.
Used carefully, it can illuminate six leadership questions.
1. Robustness: what continues to work under pressure?
Robustness asks whether important capabilities remain usable when assumptions are disrupted. Exercise maturity, dimension results and retested actions can show which capabilities are dependable, individual-dependent or unsupported by evidence.
2. Exposure: where could a weakness become material?
The detailed exercise view can translate observations into governance risk, technical exposure, regulatory compliance, communications gap, legal readiness and response timeliness. This does not turn a simulation into a loss forecast; it creates a common prioritisation language.
An exposure becomes more meaningful when it recurs, crosses functions or remains open after management has accepted an action. A repeated weakness across different exercises deserves escalation as a systemic risk signal.
3. Blind spots: what does the organisation fail to see?
Blind spots appear when a team excludes another function, fails to test an assumption, omits an external dependency or discounts a warning that does not fit the initial narrative.
The Attack Cascade Intelligence Framework view maps evidence across governance, behaviour, signal and culture, controls, and the phases of resist, respond and recover. Its purpose is to show where attention narrows under pressure, not to label individuals.
4. Trust: can people speak, challenge and act?
Trust is observable in whether concerns are raised, information is shared without status barriers, experts challenge a preferred course and commitments are clear.
Amy Edmondson’s foundational research links a team’s shared belief that interpersonal risk-taking is safe with learning behaviour. Reviews caution that psychological safety is shaped by leadership, team and organisational conditions; it is not created by a slogan. It does not remove accountability.
The useful longitudinal question is: “Are the same concerns becoming easier to raise and act on?” Observations should be aggregated responsibly and never used to punish or rank individuals.
5. Adaptability: can the organisation update its response?
A resilient organisation notices when a plan no longer fits and changes course without losing governance.
Exercise analytics can support review of decision reversals, response timeliness, evidence used and changing priorities. These are observations and correlations, not causal proof. A faster decision is not automatically a better decision.
Adaptability is visible when teams can explain what changed, why it changed and who authorised it.
6. Recovery: what happens after the immediate crisis?
Recovery includes trust, obligations, stakeholder communication and changed practice—not only technology restoration.
Completed-run history, maturity trends and improvement findings can distinguish an action that was recorded from one that was closed, tested and retained.
OEX and OCI as evidence frameworks—not magic scores
OEX is most useful when treated as a structured view of evidence across Robustness, Exposure, Blind Spots, Trust, Adaptability and Recovery. Each dimension should be read with its evidence coverage, context and limitations. Where the minimum evidence for an OEX view is not available, the dashboard retains an insufficient-evidence state rather than manufacturing certainty.
OCI provides a related confidence conversation. A “demonstrated” or “evidenced” confidence tier should mean that the organisation has more than an assumption to point to. It should not be presented as a guarantee of performance. “Developing”, “assumed”, “insufficient evidence” and “not captured” are important governance outcomes: they show where the board should resist a reassuring narrative.
The leadership benefit is the discipline of asking:
- What evidence supports this assessment, and is it repeated?
- Did the scenario test the relevant authority and dependency?
- What changed after the last finding, and what remains unknown?
That is a stronger conversation than presenting an attractive radar chart without context.
How exercise analytics change the conversation
Analytics change the conversation when they connect exercise observations to decisions that leaders already own.
Instead of “the exercise was completed”, ask, “Which material risk did it test, and what did we learn about our tolerance?”
Instead of “communications were good”, ask, “Where did information slow down, who had to interpret it twice, and which stakeholder was missing?”
Instead of “the action is closed”, ask, “What was changed, who retested it, and what evidence shows the change held in a later run?”
Instead of “our people are resilient”, ask, “Could a person raise a concern without fear, and did the system make it possible to act on that concern?”
These questions connect board oversight with practical organisational behaviour and protect against reducing a complex system to a single number.
Practical actions for Australian boards and executives
Set an evidence question before each exercise
Choose one or two material risk questions: can the organisation decide within tolerance when facts are incomplete, and can a cyber signal move from detection to executive action without avoidable delay?
Require a longitudinal view
Review the current result beside comparable runs, open findings, closed-and-retested actions and evidence coverage. Treat unexplained deterioration as a question, not automatically as failure.
Include the human system and retest
Observe authority, trust, challenge, handovers, intelligence flow and stakeholder communication—not only technology recovery. Aggregate behavioural evidence, protect confidentiality, assign accountable owners and retest material findings. Never infer trauma, diagnosis or personal vulnerability from exercise behaviour.
Use threat-informed leadership carefully
Threat-informed leadership is a proposed management lens inspired by trauma-informed principles such as safety, trust, collaboration, empowerment and cultural awareness. It is not a validated clinical framework. It means designing exercises and leadership responses around the pressures people may face, giving participants appropriate agency, avoiding unnecessary harm and learning from threat conditions without pathologising employees.
That lens should never justify surveillance, forced disclosure or punitive individual scoring; it should improve organisational learning.
Conclusion: resilience is what remains learnable
The real benefit of a tabletop exercise is credible evidence about how an organisation makes sense of uncertainty, distributes authority, moves intelligence, protects trust, adapts and recovers.
Longitudinal organisational resilience analytics make these questions visible over time. OEX and OCI can structure evidence, but leadership judgement remains essential. Use them as a basis for inquiry, action and retesting—not prediction.
For Australian boards operating in a volatile threat environment, confidence should be earned through repeated evidence—not assumed because an exercise ended on schedule.
Key takeaways
- A completed tabletop is an input to assurance, not proof of durable resilience.
- Longitudinal evidence can reveal recurring exposure, blind spots, trust barriers, adaptation patterns and recovery weaknesses.
- OEX and OCI are supporting evidence frameworks; neither guarantees real-incident performance.
- Psychological safety supports learning and speaking up, but does not remove accountability.
- Exercise analytics should connect observations to material risk, accountable owners and retesting.
- Threat-informed leadership is a proposed, ethically bounded management lens—not a clinical or validated scoring model.
Frequently asked questions
What is organisational resilience analytics?
Organisational resilience analytics is the structured analysis of exercise, risk, behavioural and improvement evidence to understand how an organisation resists, responds, recovers and learns over time. It supports judgement; it does not predict outcomes.
What does OEX measure?
In this framework, Organisational Exercise Intelligence (OEX) presents six evidence dimensions: Robustness, Exposure, Blind Spots, Trust, Adaptability and Recovery. Dimensions should be interpreted with their evidence coverage and exercise context.
What is the difference between OEX and OCI?
OEX organises evidence across six resilience dimensions. OCI, the Organisational Confidence Index, expresses the level of confidence supported by the available evidence, including insufficient-evidence and not-captured states. Neither is a guarantee of operational performance.
Can tabletop analytics prove that an organisation is resilient?
No. Exercise analytics provide observations, trends and correlations. They can show whether findings recur and actions are retested, but cannot prove causation or guarantee live performance.
Suggested internal links
- Psychological safety and the organisational conditions for speaking up
- How intelligence flow becomes an organisational resilience capability
- Threat-informed leadership: learning from trauma-informed principles
- AI-era threats and the case for adaptive tabletop exercises
References
- Australian Prudential Regulation Authority, Prudential Standard CPS 230 Operational Risk Management (2023)
- Australian Securities and Investments Commission, Key issues outlook 2026 (2026)
- Australian Institute for Disaster Resilience, Australian Disaster Resilience Handbook 3: Managing Exercises (2012)
- Australian Government, Crisis Management Framework: Decision-making and coordination mechanisms (current)
- Edmondson, “Psychological Safety and Learning Behavior in Work Teams” (1999)
- Frazier et al., “Psychological Safety: A Meta-Analytic Review and Extension” (2017)
- O’Donovan and McAuliffe, “A systematic review exploring interventions to improve psychological safety, speaking up and voice behaviour” (2020)
- Safe Work Australia, Psychological health and safety in the workplace (2024)
- Australian Signals Directorate, Annual Cyber Threat Report 2024–25 (2025)
- Australian Human Rights Commission, Guidelines for Working With a Trauma-informed Approach (2021)
A leadership question to take forward: What evidence would your board need to see, across the next two or three exercises, before it could responsibly say that resilience is improving?
