Guides or assessment tools have been developed for small- and medium-sized enterprises by national information system security agencies to help companies assess their needs and put in place the main measures to ensure the company's resilience. Given the potential consequences of cyber incidents or attacks, their sometimes systemic nature, and the speed with which it is necessary to be able to react, it is essential to prepare for the crisis. It is necessary to identify the key functions and key people, internally and externally, to prepare for this crisis management and to be able to set up the procedures for D-Day. The best crisis preparation is through crisis simulation. It makes it possible to become aware of the impacts of an attack, to prepare response plans, emergency measures and the formation of teams.