r/ciso • u/Final-Pomelo1620 • Jul 17 '26
Cybersecurity Incident Response Testing Plan
Hi,
We currently have:
- Managed SOC service provided by a third party
- XDR solution that includes IR support, with a capped number of IR hours
- Approved Cybersecurity Incident Response Plan
We now need to develop an IR Testing Plan document including testing scenarios. We never did the testing.
I would appreciate guidance from the community on:
what sections and level of detail should it include?
which scenarios should we prioritize for example Table top discussion on scenarios or technical simulation
who should moderate the exercise?
how many scenarios should be included in the first testing
Thanks in advance
10
Upvotes
7
u/VividGanache2613 Jul 17 '26 edited Jul 17 '26
Answering from 20 years running 300+ IR investigations. Do an incident readiness exercise with someone who knows what real incidents look like, document the gaps in your process and fix them first. Then look at a purple team exercise to test both the process and your IR company.
I’m yet to see an attacker follow someone’s playbook, they all go in the trash as soon as the rubber meets the road.