AnalysisConsulting3 min read
91% of firms skip digital twins for crisis drills
Ninety-one percent of 22 security professionals surveyed at ASIS Europe 2026 reported their organizations do not use digital twins for crisis simulation, according to MIT Sloan Management Review on 5 October 2026.

91% of firms skip digital twins for crisis drills
Ninety-one percent of 22 security professionals surveyed at ASIS Europe 2026 reported that their organizations do not use digital twins for crisis simulation, according to an article published in MIT Sloan Management Review on 5 October 2026. The finding points to a gap between available technology and current practice, particularly after two incidents in 2024 that cost organizations billions of dollars.
Survey context and current practice
The ASIS Europe 2026 survey, reported in MIT Sloan Management Review, asked 22 respondents about digital twin use and 21 about simulation frequency. Sixty-eight percent of the 21 respondents said their organizations conduct crisis simulations once a year through tabletop exercises. Forty-three percent cited insufficient leadership awareness and support as the main barrier to adopting digital twins for crisis management. The sample size is small, and the article does not specify which industries or organization types the respondents represent.
CrowdStrike: 78 minutes, 8.5 million devices
In July 2024, a faulty software update from cybersecurity firm CrowdStrike caused global IT system failures within 78 minutes, according to the MIT Sloan Review article. Microsoft estimated that 8.5 million Windows devices were affected. One analysis estimated the outage cost Fortune 500 companies 5.4 billion dollars. The incident demonstrates the scale of impact a single software update can have when systems fail.
Change Healthcare: no multi-factor authentication
In January 2024, a ransomware group gained access to Change Healthcare, the largest medical billing clearinghouse in the United States, through a portal without multi-factor authentication, according to the MIT Sloan Review article. Nearly all pharmacies, hospitals, and physician practices in the United States were unable to process insurance claims after the attack. Personal health data of up to one in three Americans were exposed. UnitedHealth Group reported combined direct response costs and business interruption impacts exceeding 2 billion dollars in the first half of 2024.
What digital twins might offer
A study published in March 2026 in the journal International Studies of Management & Organization by Raphaël De Vittoris and Carole Bousquet showed that AI systems alone identified 41% of critical developments in crisis simulations, while human teams without support identified 48%, according to the MIT Sloan Review article. The study does not answer whether digital twin simulations would have surfaced the specific vulnerabilities exploited in the CrowdStrike or Change Healthcare incidents.
What this means for consultants
The survey data and the 2024 incidents raise a question about rehearsal frequency and complexity. Organizations that conduct annual tabletop exercises may not encounter the scenarios that matter most until they occur in production. Whether digital twin simulations would have identified the lack of multi-factor authentication at Change Healthcare or the software update vulnerability at CrowdStrike remains an open question. The evidence does not establish what operational requirements digital twin crisis simulation involves, what systems and expertise it requires, or how its effectiveness compares to tabletop exercises in identifying vulnerabilities before they are exploited.
The short version
Ninety-one percent of 22 security professionals surveyed at ASIS Europe 2026 reported their organizations do not use digital twins for crisis simulation, with 43% citing lack of leadership awareness as the primary barrier. Two incidents in 2024—CrowdStrike's 78-minute outage affecting 8.5 million devices and costing an estimated 5.4 billion dollars, and Change Healthcare's breach through a portal without multi-factor authentication costing UnitedHealth over 2 billion dollars—demonstrate the cost of inadequate rehearsal. Whether more frequent or complex simulation using digital twins would surface such vulnerabilities before they are exploited remains an open question.