About this program
Is your IR plan more than a PDF? Test for tabletop exercises, RACI, comms templates, escalation paths and lessons-learned.
Risks addressed
- Critical Slow, ad-hoc IR extends breach impact
- High Wrong people contacted (or none) during a real incident
- High Regulators / customers notified late or inconsistently
- High Logs purged before forensics can run
Controls (7)
-
Documented IR plan
HighAn incident response (IR) plan is a documented, formally adopted procedure that defines roles, responsibilities, communication protocols, escalation paths, and technical steps to detect, contain, eradicate, recover from, and learn from cybersecurity incidents. The plan typically includes contact lists, decision…
How to test + evidence
Testing procedure: Confirm an IR plan exists, dated within 12 months, owned + approved.
Evidence to collect: IR plan PDF.
-
Roles + RACI defined
HighThis control requires the organization to document and assign clear roles, responsibilities, accountabilities, and consultation/information requirements (RACI) for cybersecurity functions and activities. The RACI matrix explicitly identifies who is Responsible for execution, who is Accountable for outcomes, who must be…
How to test + evidence
Testing procedure: Plan names IR Lead, Comms, Legal, Tech, with contact details.
Evidence to collect: RACI table in plan.
-
Tabletop exercise within last 12 months
HighA tabletop exercise is a facilitated discussion-based session where stakeholders walk through incident response, business continuity, or disaster recovery scenarios in a controlled, low-pressure environment. The exercise tests the organization's preparedness, validates response procedures, identifies gaps in plans or communication…
How to test + evidence
Testing procedure: Last tabletop date + attendees + scenario; lessons-learned actioned.
Evidence to collect: Tabletop after-action report.
-
Escalation paths to legal + insurer
MediumThis control ensures that incident response procedures include formally documented and tested escalation pathways to both legal counsel and cyber insurance carriers when security incidents meet predefined severity thresholds or involve regulated data. These pathways specify contact information, triggering criteria…
How to test + evidence
Testing procedure: Plan documents when/how to engage legal counsel and cyber insurance.
Evidence to collect: Plan extract.
-
Comms templates ready
MediumPre-approved communication templates are prepared, tested, and made readily accessible to incident response and business continuity teams for use during security incidents, data breaches, or operational disruptions. These templates cover internal notifications, external stakeholder communications, regulatory breach notifications, customer advisories,…
How to test + evidence
Testing procedure: Pre-approved templates for staff, customers, regulators, media.
Evidence to collect: Template library.
-
Forensic readiness — logs + tools
HighForensic readiness for logs and tools ensures that an organization maintains comprehensive, tamper-evident logs and has pre-deployed forensic analysis capabilities to support incident investigation. This control requires centralized log aggregation with adequate retention periods, synchronized time sources, write-once or immutable…
How to test + evidence
Testing procedure: Log sources retained >=90 days; forensic tooling on standby (in-house or retainer).
Evidence to collect: SIEM retention + retainer contract.
-
Lessons-learned loop
MediumA lessons-learned loop is a structured process for capturing, analyzing, and incorporating insights from security incidents, near-misses, penetration tests, tabletop exercises, and operational failures into the organization's security posture. It typically involves post-incident reviews, root-cause analysis sessions, and formal mechanisms…
How to test + evidence
Testing procedure: Closed incidents trigger a post-mortem; actions tracked to completion.
Evidence to collect: Post-mortem register.