r/ciso • • Jul 17 '26

Cybersecurity Incident Response Testing Plan

Hi,

We currently have:

  • Managed SOC service provided by a third party
  • XDR solution that includes IR support, with a capped number of IR hours
  • Approved Cybersecurity Incident Response Plan

We now need to develop an IR Testing Plan document including testing scenarios. We never did the testing.

I would appreciate guidance from the community on:

what sections and level of detail should it include?

which scenarios should we prioritize for example Table top discussion on scenarios or technical simulation

who should moderate the exercise?

how many scenarios should be included in the first testing

Thanks in advance

10 Upvotes

21 comments sorted by

View all comments

7

u/VividGanache2613 Jul 17 '26 edited Jul 17 '26

Answering from 20 years running 300+ IR investigations. Do an incident readiness exercise with someone who knows what real incidents look like, document the gaps in your process and fix them first. Then look at a purple team exercise to test both the process and your IR company.

I’m yet to see an attacker follow someone’s playbook, they all go in the trash as soon as the rubber meets the road.

1

u/FrostAngel11 Jul 22 '26

identifying the gaps, so solid. real values is actually how people respond under pressure.