Executive opening
Australian organisations are making decisions in conditions of sustained uncertainty: cyber-enabled fraud, third-party outages, geopolitical tension, extreme weather and rapidly changing technology. The challenge is whether people can recognise a developing threat, share uncomfortable information, decide with incomplete evidence and recover without repeating the same failure.
That is why threat-informed leadership is a useful proposed management lens. It asks leaders to design around ambiguity, pressure, disrupted information, unequal power and hesitation to speak. It is not a clinical framework, diagnosis or claim that employees have experienced trauma, but a non-clinical proposition inspired by trauma-informed practice.
The Australian Human Rights Commission describes trauma-informed practice through safety, trustworthiness, choice, collaboration and empowerment, with cultural safety and respect for lived experience (Australian Human Rights Commission, 2021). SAMHSA similarly describes safety, transparency, collaboration, and voice and choice (SAMHSA, 2026). These principles prompt a better question:
What must leaders build into everyday organisational design so that people can think, communicate and act when threat makes normal coordination difficult?
Tabletop exercises provide a controlled way to explore that question. Longitudinal analytics help leaders see whether authority, trust, intelligence flow, adaptation, recovery and learning are changing. They do not prove real-incident performance; they provide structured observations and correlations that make improvement more visible and accountable.
Why threat-informed leadership matters in Australia
The risk environment is becoming more interconnected. A technology failure can become a customer, regulatory, reputational and people issue at the same time. A cyber incident can require decisions from technology, legal, operations, communications, finance, risk and the executive team before any one function has a complete picture.
The Australian Cyber Security Centre (ACSC) assessed in its Annual Cyber Threat Report 2024–25 that artificial intelligence (AI) almost certainly enables malicious actors to operate at greater scale and speed. It also reported phishing as an initial-access technique in 38 per cent of reported incidents. These figures describe reported incidents and an intelligence assessment; they do not mean every attack uses AI or establish a national rate of deepfake attacks (ACSC, 2025).
The leadership implication is practical. Organisations need to exercise verification, escalation, authority and communication—not only technical detection. When an urgent payment instruction arrives through a convincing channel, who can pause it? When facts are incomplete, who convenes the response, and how is dissent heard?
For APRA-regulated entities, Prudential Standard CPS 230 makes this expectation explicit. It requires effective operational-risk management, critical operations maintained within tolerance through severe disruption, credible business continuity planning and management of service-provider risk. The board is ultimately accountable for oversight, including approving tolerance levels and reviewing testing results (APRA, 2023; effective 1 July 2025). ASIC has likewise urged directors and financial-services licensees to test operational resilience and crisis responses and address third-party vulnerabilities (ASIC, 2026).
These requirements do not make a single tabletop proof of resilience. A recurring evidence base shows whether the organisation is learning to operate within its tolerances.
Trauma-informed principles, translated carefully
Trauma-informed practice recognises that experiences affect people differently and organisational responses can support safety or cause further harm. In the Australian Human Rights Commission’s guidance, safety includes physical, emotional and cultural safety; trustworthiness involves transparent decisions; choice avoids coercion; collaboration reduces power imbalances; and empowerment centres affected people.
Threat-informed leadership borrows the design logic—not the clinical terminology or scope. It can translate the principles as follows:
Safety becomes the ability to raise risk without retaliation
A safer design makes challenge an expected role. Facilitators can explicitly invite dissent, distinguish a person from an observation and record unresolved concerns without attaching blame to an individual. The aim is not comfort at the expense of accountability. It is a working environment where accurate information can surface early enough to matter.
Trust becomes transparency about decisions and evidence
Exercise analytics can support this conversation by examining evidence such as time to escalate, decision reversals, information cited, unresolved dependencies and communication coherence. These are observations, not a validated trust score or a prediction of incident performance. Repeated patterns can nevertheless show where teams lack a shared basis for action.
Choice becomes bounded discretion
In an incident, “choice” does not mean ignoring a critical control. It means understanding options, escalation paths and boundaries. Leaders should make authority explicit: who can stop a transaction, activate a plan, contact a regulator, make a public statement or request assistance?
The detailed exercise analytics described in the organisation’s current framework include governance questions about authority structures and legal responsibilities, alongside improvement questions about response thresholds and communication timeliness. That is the right level of inquiry: test the system of authority, not an individual’s personality.
Collaboration becomes designed interoperability
Trauma-informed guidance emphasises collaboration and reduced power imbalances. In organisational resilience, the equivalent is not a vague instruction to “work together”. It is designing the hand-offs between functions.
A tabletop can reveal whether a technical signal reaches risk, whether risk can reach the executive decision-maker, whether legal advice arrives before an external notification deadline and whether communications has enough verified information to protect stakeholders. Cross-functional collaboration is observable as a flow of information and decisions. It is not guaranteed by having representatives in the same meeting.
Empowerment becomes voice, agency and learning
People closest to a process often see weak signals first. Empowerment creates routes for that knowledge to influence decisions while preserving accountability. It also means choice about disclosure, protection of sensitive information and no punitive individual ranking.
This distinction matters especially when exercises involve distressing scenarios. A threat-informed approach should include an appropriate briefing, opt-out or support pathways where needed, culturally safe facilitation and careful handling of exercise data. It should never infer trauma, mental-health status or personal vulnerability from a person’s exercise behaviour.
How exercise analytics change the conversation
Traditional exercise reporting asks whether the organisation completed the scenario and closed actions. Useful, but not enough to show repeatable resilience.
Longitudinal analytics create a different conversation by looking for patterns across comparable runs:
- Authority: Do decision-makers know when they can act without another approval? Do escalation paths become clearer?
- Trust and voice: Do participants raise concerns earlier? Are dissent and uncertainty recorded and addressed?
- Intelligence flow: Does relevant information move between technology, operations, legal, risk, communications and leadership, or does it remain in functional silos?
- Adaptation: When a scenario changes, can the organisation update its plan rather than defend an outdated assumption?
- Recovery: Does the response include restoration, stakeholder care and a return to normal operations within appropriate tolerances?
- Learning: Are after-action findings assigned, closed, retested and reflected in the next exercise?
The current analytics model supports this inquiry through a resilience causal chain—Identity and Trust; Structure and Roles; Decisions and Action; Output and Results; and Continual Improvement. It also surfaces maturity trends, per-run scores, dimension deep-dives, response-impact and crisis-flexibility measures, and evidence-gated OEX results.
OEX, or Organisational Experience, is best understood here as a supporting evidence framework. Its six dimensions—Robustness, Exposure, Blind Spots, Trust, Adaptability and Recovery—organise questions that a tabletop can expose. OCI, the Organisational Confidence Index, indicates the level of evidence available, from insufficient evidence through developing and evidenced confidence to demonstrated confidence. It should not be presented as a certificate, a clinical assessment or causal proof.
The evidence gate is important. The current framework requires at least three captured after-action review dimensions plus an overall result before OEX can be calculated. Where evidence is insufficient, the appropriate output is “not captured”, not a manufactured score.
Practical actions for boards and executives
1. Test a defined capability
Before approving a scenario, identify whether it tests authority, critical-operation tolerance, third-party dependency, communication, recovery or learning. AIDR describes exercises as objective-driven activities that should contribute to continuous improvement (AIDR, 2012).
2. Require a longitudinal view
Ask for the current result alongside the previous comparable run, the action register and evidence that material findings were retested. A trend with context is more informative than a single score, although it remains exercise evidence rather than proof about future incidents.
3. Review information flow and safety
Ask when each function received needed information, what was delayed, what assumptions changed and which dependencies remained unresolved. Set ground rules for respectful challenge, culturally appropriate participation and strengths-based language.
4. Make analytics accountable and non-punitive
Use aggregated, role-based and purpose-limited evidence. Explain access and retention, focus on system conditions rather than individuals, and give every material finding an owner, target state, time frame and retest condition.
Boundaries for responsible use
This proposed lens is not clinical trauma support, occupational health advice, industrial consultation, incident doctrine or legal advice. It does not assume staff are traumatised, justify surveillance or force disclosure. Nor does it turn OEX, OCI or another output into a definitive measure of a person or organisation. Scenario familiarity, facilitation, participant changes, evidence quality and exercise design affect scores, so interpret trends alongside qualitative observations and run context.
Conclusion: resilience is what the organisation learns to do repeatedly
Threat-informed leadership starts with a realistic premise: under pressure, people operate through relationships, authority, trust, information and habits developed before the event.
Trauma-informed principles offer a useful ethical prompt for designing those conditions: safety, transparency, choice, collaboration and empowerment. Australian governance expectations add a firm accountability requirement: critical operations, dependencies, controls and recovery arrangements must be tested and improved.
Longitudinal tabletop analytics connect the two. They help leaders ask whether the organisation is becoming more capable of raising concerns, sharing intelligence, making bounded decisions, adapting to new information and recovering without repeating known weaknesses. That is the leadership value—not the score itself, but the quality of the conversation and the action that follows it.
The question for your next board or executive meeting is simple: what evidence would show that your organisation has learned since its last exercise, and how will you know whether that learning is shared, safe and durable?
Key takeaways
- Threat-informed leadership is a proposed, non-clinical management lens—not a validated clinical framework.
- Trauma-informed principles can inform safer organisational design when translated carefully and without pathologising employees.
- Resilience depends on authority, trust, intelligence flow, adaptation, recovery and learning—not attendance at a single exercise.
- OEX and OCI can organise evidence from tabletop findings, but they do not prove causation or predict real-incident performance.
- Use longitudinal, aggregated and privacy-aware analytics to improve systems rather than punish individuals.
- Australian boards should connect exercise findings to tolerances, owners, remediation and retesting.
Frequently asked questions
What is threat-informed leadership in Australia?
Threat-informed leadership is a proposed non-clinical management lens for designing decisions, communication and support around realistic threat conditions. It is not a validated clinical or regulatory framework.
How is threat-informed leadership related to trauma-informed leadership?
It adapts principles associated with trauma-informed practice—safety, trust, transparency, choice, collaboration and empowerment—to high-threat business environments. It must not diagnose trauma or infer personal vulnerability.
Can tabletop exercise analytics prove that an organisation is resilient?
No. Analytics show observations, patterns, trends and evidence coverage across exercises; they cannot establish causation or guarantee real-incident performance.
How should executives use OEX and OCI?
Use them as supporting evidence for questions about robustness, exposure, blind spots, trust, adaptability, recovery and evidence quality. Treat insufficient evidence as a finding, not a reason to invent certainty.
Suggested internal links
- Why tabletop exercises need longitudinal analytics
- Psychological safety as an organisational resilience capability
- How intelligence flow determines crisis decision quality
- Preparing for AI-era operational resilience in Australia
References
- Australian Cyber Security Centre, Annual Cyber Threat Report 2024–25 (2025).
- Australian Human Rights Commission, Guidelines for Working With a Trauma-informed Approach (2021).
- Australian Institute for Disaster Resilience, Australian Disaster Resilience Handbook 3: Managing Exercises (2012).
- Australian Prudential Regulation Authority, Prudential Standard CPS 230: Operational Risk Management (2023; effective 2025).
- Australian Securities and Investments Commission, Key Issues Outlook 2026 (2026).
- Substance Abuse and Mental Health Services Administration, Trauma-Informed Approaches and Programs (2026).
