| 1 | Write the decision brief for Cyber Incident Simulation: define which accounts, devices, data and response capability the club will protect first, the starting evidence, people affected, local authority, resource limit, success signals and stop conditions. | Board sponsor and information owner | Week one | An approved decision and boundary brief |
| 2 | Identify users and non-users, map access and digital-confidence barriers, explain data use and permissions and retain an equivalent human or non-digital route where essential participation is involved. Apply this specifically to Cyber Incident Simulation and record which relevant experiences or users are still missing. | Board sponsor and information owner with the access and privacy contacts | Weeks one and two | A participant, access and information-handling plan |
| 3 | Build and test a bounded 90-day initiative with a clear outcome, participant choices, safeguards and decision date for Cyber Incident Simulation; complete the Cyber Incident Simulation Initiative Delivery Blueprint, rehearse the boundary wording and confirm who may decide, refer, pause, recover or close the work. | System lead, privacy contact and access tester | Before the trial | A tested initiative delivery blueprint and delivery pack |
| 4 | Use synthetic or minimised test data, least privilege, versioned configuration, accessible instructions, exception handling and a rollback; do not expose live credentials or private member information. Capture only the evidence needed to judge whether Cyber Incident Simulation advances practical cyber resilience. | System lead, privacy contact and access tester | Weeks three to eight | A controlled activity and evidence record |
| 5 | Compare the evidence with the starting point, validate meaning with affected participants or users, record gaps and unintended effects and prepare a completed delivery and evidence pack supporting a continue, adapt or stop decision without overstating what the trial proves. | System lead, privacy contact and access tester with an independent reviewer | Within seven days of the trial | A completed delivery and evidence pack supporting a continue, adapt or stop decision |
| 6 | Make and record the authorised continue, adapt, refer, scale or stop decision for Cyber Incident Simulation; explain the reason, complete every action, close unnecessary records and schedule the 90-day follow-up. | Service owner and independent reviewer | By day 90 | A published participant response, closed action register and next-step decision |