Policies & Planning 7 min read

Test Your Incident Response Plan Before You Need It

A plan nobody has practiced is not a plan. It is wishful thinking. Here is how to run a 90-minute tabletop exercise that will reveal every gap in your incident response — before the attackers do.

The $50,000 Typo

A small marketing agency had an incident response plan. It was a nice document. Six pages. Clear steps. Contact numbers. They had paid a consultant $3,000 to write it two years ago.

When ransomware hit on a Friday afternoon, they pulled out the plan. The first person on the contact list had left the company 18 months ago. The second number was a desk phone that nobody answered on a Friday. The third contact was their MSP — whose email was part of the same system that was down. Nobody had their direct phone number. It took four hours to reach someone who could start the response.

Four hours. In ransomware response, four hours is the difference between one infected computer and every computer on the network. That four-hour delay turned a manageable incident into a six-figure recovery. All because nobody had tested the plan.

What Is a Tabletop Exercise?

A tabletop exercise is the simplest form of incident response testing. You get the key people in a room. You present them with a scenario. They talk through what they would do, step by step. You discover what works and what does not. Nobody actually has to respond to a real incident. Nothing gets shut down. It is a conversation, not a drill.

The goal is not to test whether people can memorize a procedure. The goal is to find out: do the phone numbers work? Does everyone know who to call? Are there decision points where people hesitate because authority is unclear? Does the plan assume systems will be available that might not be?

How to Run One (90 Minutes Total)

Preparation (15 minutes before the meeting)

Pick a scenario relevant to your business. Write it down in 2-3 sentences. Do not over-prepare — the point is to see how people react, not to test your creative writing. Have a printed copy of the current incident response plan in the room. Make sure the key people are there: the owner or decision-maker, whoever handles IT, whoever handles communications, and whoever would deal with legal/insurance.

Minute 0-5: Present the scenario

Read it aloud. Keep it simple. Example: "It is 3 PM on a Tuesday. Susan in accounting receives an email that looks like an invoice from a vendor. She opens the attachment. Her screen changes — files are being renamed. A message appears demanding $50,000 in Bitcoin within 72 hours. Susan calls you. What do you do?"

Minute 5-30: Walk through the first 30 minutes

Who gets called first? What is their actual phone number — look it up right now, do not assume. Who makes the decision about whether to disconnect systems? Who contacts the insurance company? Does anyone know the insurance company's breach hotline number? Write down every phone number that someone says they would need. Then verify each one. Last time I did this with a client, 3 of 7 phone numbers were wrong.

Minute 30-60: The hard decisions

Now introduce complications. "The MSP says it will take 48 hours to restore from backup. Your biggest client has a deliverable due tomorrow. Do you pay the ransom to speed things up?" "The forensic firm says customer data may have been accessed. Do you notify customers now with incomplete information, or wait until you know more?" "A reporter from a local news outlet has heard about the breach and is calling. Who talks to them? What do you say?" The value of the exercise is in these uncomfortable moments — where the plan says "notify legal counsel" but nobody knows who legal counsel is on a Friday at 4 PM.

Minute 60-75: Review and fix

Go through what worked and what did not. Update the plan immediately — do not put it on a to-do list. Wrong phone numbers get corrected right now. Missing contacts get added. Decision-making gaps get documented. The goal is to walk out of the room with an updated plan that is better than the one you walked in with.

Minute 75-90: Schedule the next one

Put a recurring calendar invite for 6 months from now. Pick a different scenario next time — website defacement, phishing attack that exposed credentials, lost laptop with customer data, vendor breach. Different scenarios reveal different gaps.

Three Scenarios to Start With

Scenario 1: Ransomware

An employee opens a malicious attachment. Files across the network are encrypted. A ransom note demands $75K in Bitcoin within 72 hours. Your main file server and backup NAS are both encrypted. The off-site backup is a week old. What do you do?

Scenario 2: Lost Laptop

Your sales director's laptop is stolen from their car. It contains customer contracts, pricing spreadsheets, and cached email with 3 years of client communications. The laptop has full-disk encryption but was logged in when stolen. What do you do?

Scenario 3: Phishing + Wire Transfer

Your finance person receives an email that appears to be from you (the owner) asking for an urgent wire transfer to close a deal. The email uses your actual signature block and references real projects. They send $42,000. Then they mention it to you in passing and you realize it was fraud. What do you do?

The Most Common Gaps (What You Will Probably Find)

After running dozens of these with small businesses, the same gaps come up every time:

  1. Phone numbers are wrong. People leave, desk phones change, nobody updates the plan.
  2. The plan assumes email is available. In a ransomware incident, it probably is not. You need phone numbers and a backup communication method (Signal, WhatsApp group, personal emails).
  3. Nobody knows who has authority to make decisions. Can the IT person authorize a $50K ransom payment? Probably not. But waiting for the owner to get back from vacation is not a plan either. Document decision-making authority for financial commitments during an incident.
  4. The insurance contact information is wrong or missing. Cyber insurance policies have a specific breach notification number. It is different from your regular claims number. Find it. Put it in the plan.
  5. Nobody knows the backup restoration timeline. "Restore from backup" sounds quick. It is not. Ask your MSP: "If we had to do a full restore of our file server today, how long would it take?" Write that number down.

The Bottom Line

An untested plan is a document that makes you feel prepared without actually preparing you. A 90-minute tabletop exercise costs nothing, requires no consultants, and will reveal more about your readiness than any checklist. Run one this quarter. Update the phone numbers. You will sleep better knowing the plan actually works — or at least knowing exactly what does not.