Rehearsal Intelligence: Using Digital Twins for Crisis Readiness

MIT Sloan Management Review ·

Rehearsal Intelligence: Using Digital Twins for Crisis Readiness

Carolyn Geason-Beissel/MIT SMR | Getty Images In July 2024, the cybersecurity software company CrowdStrike pushed a routine but buggy software update to its platform. In the ensuing 78 minutes, before a patch was deployed, IT systems worldwide crashed. Microsoft estimated that 8.5 million Windows devices were affected. As blue screens of death cascaded across the […]

Carolyn Geason-Beissel/MIT SMR | Getty Images

In July 2024, the cybersecurity software company CrowdStrike pushed a routine but buggy software update to its platform. In the ensuing 78 minutes, before a patch was deployed, IT systems worldwide crashed . Microsoft estimated that 8.5 million Windows devices were affected. As blue screens of death cascaded across the globe, airlines grounded fleets, hospitals lost access to patient records, and banking platforms went dark. One analysis estimated that the collapse cost Fortune 500 companies $5.4 billion .

Six months earlier, a ransomware group had accessed Change Healthcare, the largest medical claims clearinghouse in the United States, through a single portal that lacked multifactor authentication . Within days, nearly every pharmacy, hospital, and physician practice in the U.S. was unable to process insurance claims. Surgeries were postponed, and the personal health data of as many as 1 in 3 Americans was exposed. Combined direct response costs and business disruption impacts incurred by parent company UnitedHealth Group exceeded $2 billion in the first half of 2024 alone, according to the company’s filings with the Securities and Exchange Commission.

Two incidents. Two different failure modes. Combined documented losses exceeding $7 billion. In both cases, crisis experts wondered, had anyone rehearsed this?

They could have. As far back as 2022, McKinsey was reporting that 70% of C-suite technology executives at large enterprises were exploring and investing in digital twins as a way to optimize operations, model supply chains , and accelerate decision-making. A digital twin is a dynamic virtual replica of an organization’s operations, supply chain, manufacturing lines, IT infrastructure, or distribution network, connected in real time to the data flows that govern its physical counterpart. Unlike a static model, a digital twin updates continuously as conditions change, and it can be queried, stressed, or reconfigured without touching the physical system.

Few companies are using this modeling capacity to rehearse crisis scenarios. They’re not using it to test what happens when a software provider’s routine update crashes their operating environment, or when their largest payment processor goes dark. But they could be. The gap between what digital twins are used for and what they could be used for is not a technology gap. It is a strategic gap that has cost organizations billions of dollars and is risking the loss of much more.

To test whether this gap was visible at the practitioner level, I conducted a structured poll during a session titled “Rehearsal Intelligence: AI Digital Twins for Crisis-Ready Organizations” at ASIS Europe 2026, a Tier 1 international conference drawing risk professionals from across sectors and geographies. Roughly 40 practitioners attended the session; between 19 and 23 responded to each poll question. While I cannot claim that this convenience sample is statistically representative, its composition — exclusively senior security and resilience practitioners with direct organizational visibility — offers a meaningful practitioner-level signal.

Of the 21 respondents who identified their role, 47% were corporate security directors or heads of security. The remainder were in risk management, security consulting, and C-suite functions.

Asked how often their organization conducts crisis simulations, 68% reported once a year, through a tabletop exercise — typically, a facilitated discussion in which a team walks through hypothetical scenarios and planned responses. A further 15% reported never testing the crisis plan at all. Only 5% reported conducting simulations continuously, using live data or digital tools.

The second question produced the starkest finding. Of 22 respondents, 20 (91%) reported that their organization was not using digital twins in any capacity. Two said that their organization used digital twins for operational monitoring. Not a single participant reported using digital twins for crisis simulation.

The third question identified future impediments. Asked what the primary obstacle was to adopting digital twins for crisis management — and, by extension, where challenges might lie in organizations yet to adopt general digital twin technology — 43% said “insufficient leadership awareness and buy-in.” This was the top answer, above budget constraints, technical complexity, and data integration challenges.

An executive might reasonably say, “We have crisis teams, we run tabletop exercises, and we have AI. Is the absence of digital-twin-based rehearsals truly a strategic risk?”

To be clear, tabletop exercises run by crisis teams have genuine value. They align work groups, expose assumptions, and create shared mental models. No serious resilience professional would argue against them. But they carry structural limitations that become more consequential as crisis complexity increases.

First, tabletop exercises operate on pre-constructed scenarios. In other words, the exercise is designed around a crisis someone has imagined. CrowdStrike and Change Healthcare were not included in anyone’s tabletop scenarios. The crisis that will actually test your organization is, by definition, the one that was never in the playbook. Second, tabletop exercises are episodic. The muscle memory that organizations build inevitably decays between quarterly or annual sessions. And third, tabletop exercises test the team, not the system. The exercise reveals how particular crisis management team members think under pressure, but it does not reveal how the actual organizational systems, supply chain, IT infrastructure, customer-facing operations, or financial flows might behave under real crisis conditions. Stress-testing examines financial or technical resilience within defined parameters but is not designed for cross-system cascade failure. The gap between what a team decides and what the organization can execute is precisely where most crisis responses break down.

Artificial intelligence adds some value to planning, but less than leaders might expect. In a peer-reviewed study published in March 2026 in International Studies of Management & Organization , researchers Raphaël De Vittoris and Carole Bousquet analyzed 24 crisis simulations conducted between 2017 and 2024 that tested the predictive capacities of human and artificial intelligence across a range of scenarios.

Each simulation was built around nine critical developments that a crisis group should be able to anticipate. Those points were embedded in the scenarios in advance and validated by internal and external crisis professionals, and performance was measured as the share of critical developments that each group involved in the study actually surfaced.

On that measure, AI operating alone identified 41% of the critical points. (The AI models tested were the three most frequently cited by the crisis management team members themselves — the tools they would plausibly reach for under pressure.) Human teams without any support identified 48%. But the use of sophisticated AI platforms barely added value to crisis-anticipation performance: Human teams that used AI identified 49% of the critical points, a gain of a single percentage point. Human teams equipped with structured information access (that is, Google’s search engine) found 81%.

Those results carry a direct management implication. AI investments on their own won’t yield the best solutions. Instead, preparing teams before pressure arrives requires different options.

In their 2025 article “ How to Supercharge Your Crisis Training ,” MIT’s Sandra Galletti and Steven B. Goldman argue compellingly that organizations need to move beyond passive crisis planning toward active, experiential simulation, and that most organizations fall significantly short of what modern crisis complexity demands. They’re right.

Digital twins offer a way to inject systems with active simulation. Digital twins can stress-test systems against scenarios no one has imagined, run continuously rather than episodically, and be used to test not just team thinking but an organization’s actual capabilities to respond to disruption. Rehearsal intelligence is not a theoretical construct but the organizational capability that emerges when the digital twin is deliberately repurposed from an operational optimization tool into a permanent crisis-anticipation environment. The technology already exists in increasing numbers of large organizations. The gap between using digital twins for operations and digital twins for crisis rehearsal is an opportunity that requires a governance decision that data suggests is long overdue. What’s missing is the framework to deploy it for this purpose — and, as the poll data from the practitioners makes clear, the leadership attention that could make it systematic.

Repurposing an organization’s existing digital twinning tool for a new class of questions rests on a five-step framework of organizational design decisions.

1. Treat the digital twin as a permanent rehearsal environment, not an episodic exercise tool. Crisis simulation should not be an event but rather an ongoing organizational practice. The digital twin should be accessible for scenario stress-testing as routinely as it’s used for operational planning.

Some organizations are already moving in this direction, though without a shared language for what they are doing. BMW planned and validated the construction of a new plant in Debrecen, Hungary, in an entirely virtual environment more than two years before physical vehicle production began. Its digital twin simulates every production change before any physical modification is made, in part to avoid danger and damage. For instance, what BMW calls its “virtual factory” allowed faster insight into collision checks — simulating the movement of a new vehicle design through the production line to make sure it wouldn’t scrape up against anything. Using the digital twin reduced what would typically take almost four weeks to just three days. In June 2025, the company announced that it would be scaling the use of digital twins across 30 of its production facilities worldwide and projected that production planning costs will fall by up to 30%.

Similarly, Walmart has deployed digital twins across many of its stores and distribution centers. Brandon Ballard, group director for real estate at Walmart US, said last year that digital twins have helped the company detect and remediate potential equipment failures up to two weeks before they occur, reducing emergency alerts by 30% and cutting refrigeration maintenance costs by 19%, according to CNBC. In one implementation across 20 stores, a digital twin project proactively identified and addressed 842 potential failures in Walmart’s systems, such as refrigeration, in a six-month period, enabling the company to avoid an estimated $1.4 million in downtime costs.

2. Position AI as a structured sparring partner, not a decision maker. The De Vittoris and Bousquet study offers a warning here. Deploying AI casually added a single percentage point to team performance. The best results came from teams that used tools they had mastered, in a structured and deliberate way. Among the top-scoring crisis cells, those that used AI engaged with it through multiple contextualized prompts, in real conversations, explicitly asking for the anticipations that a team emotionally affected by the event might miss. The worst-scoring team to use AI submitted one short, uncontextualized question. The researchers’ conclusion is that organizations need a genuine prompt culture that includes a library of adaptable prompt templates built before a crisis arrives. That literacy comes from deliberate practice, not from buying an AI platform.

Here’s a suggestion: Build one structured anticipation session into your next crisis team meeting. Give the team a specific disruption scenario and ask them to regard your AI environment as a structured challenger to generate three alternative scenarios, identify second-order consequences of each, and test the assumptions your current crisis plan rests on. This is precisely the structured engagement that separated the best-performing teams in the study from the rest. It’s available to your team today.

3. Embed structured anticipation into organizational culture rather than delegating it to a crisis unit. The performance differential in the De Vittoris and Bousquet study came from anticipation mechanisms that were formalized and actually used when the crisis hit, not from titles or org charts. It’s a matter of organizational design, not staffing.

At Walmart, the digital twin infrastructure that monitors refrigeration temperatures could be queried against disruption scenarios: What happens across 200 stores if the monitoring systems fail simultaneously? What is the cascade if three distribution centers lose connectivity during peak demand? These are questions that general managers, not just risk managers, can ask.

The first step toward building this culture is to run one crisis rehearsal scenario in your digital twin environment. You don’t need a comprehensive program or a multiyear transformation. You just need one scenario, representing a realistic disruption event relevant to your sector, with a structured debrief within 72 hours. The goal is not a perfect simulation. It’s to harness the organizational learning that comes from running one.

4. Build scenario templates and structured question sets that enable crisis teams to engage the digital twin environment rapidly when a scenario emerges. In financial services, digital twins that model trading infrastructure and liquidity flows can be queried against settlement failures, counterparty cascades, or regulatory intervention scenarios. In pharmaceutical manufacturing, production-line twins can be stress-tested against supply disruptions or batch-failure events before they reach patients or regulators.

In energy and utilities, grid topology and distribution twins can simulate cascade failures before they reach physical infrastructure. FedEx has built a digital twin of its global logistics network, which it uses to forecast, identify, and minimize disruption.

The point is, the technology footprint and focus will vary by sector. Repurposing digital twins will call for a new class of questions.

5. Adopt a three-stage maturity model — reactive to structured to anticipatory — that gives leadership a clear diagnostic and a direction of travel. The majority of organizations in my ASIS Europe poll were in the first stage, reactive , with crisis plans and occasional tabletop exercises, while digital twins were either absent or siloed in operational functions. The second stage is structured , where the organization has conducted at least one deliberate crisis-rehearsal scenario using a digital twin environment, with assigned ownership of the rehearsal function, a defined debrief process, and documented findings. The third stage is anticipatory , where crisis rehearsal is continuous and embedded.

Stage 3 has an underlying prerequisite that no governance decision alone can shortcut: the need for quality data feeding the digital twin. Organizations that reach Stage 3 have made the accuracy, accessibility, and maintenance of their live data environment a leadership priority, not just a technology department responsibility.

For most organizations, moving from the first to the second stage will mean finding out whether currently deployed digital twins within specific functional domains can be accessed, combined, and stress-tested by a crisis anticipation team. This does not require a technology project. It requires that you assign one person to audit which digital twin environments your organization currently operates and then have a two-hour conversation with your technology leadership.

The organizational capability that CrowdStrike and Change Healthcare revealed to be absent in 2024 has a name: rehearsal intelligence. Although it is urgently needed and the technology to build it is being adopted by more and more large enterprises, most organizations don’t have it in any systematic form.

Organizations can realistically aim to get to Stage 3, where they are in a continual state of anticipation, and crisis rehearsal is ongoing and entrenched. The return extends beyond crisis avoidance. Organizations operating at Stage 3 report faster decision-making (because the decision architecture has been tested against disruption before a real crisis arrives) and more precise capital allocation (because leadership understands which system vulnerabilities carry the greatest operational risk). They have stronger AI utilization because teams engage with AI as a structured reasoning partner rather than a retrieval tool, and because they have a measurable recovery-speed advantage over competitors encountering the same disruption for the first time.

As Jürgen Wittmann, head of innovation, virtual factory, and virtual commissioning in BMW’s production department, told CIO magazine last year, “Thanks to the digital twin, we know exactly the current situation and can immediately see the impact of changes.” Why shouldn’t all companies use that same tool for a wider look at the horizon?

The distance between where most organizations are today and where rehearsal intelligence can take them is not measured in technology investment or budget cycles. It’s measured in the decisions made, or deferred, right now. The CrowdStrike and Change Healthcare outages didn’t announce themselves in advance. The next disruption won’t either.

Источник: MIT Sloan Management Review