Skip to content
Buy an exerciseBuy

Free, no signup

Check your incident response plan.

The questions below are the ones vendors get sent and auditors ask out loud. Answer them honestly and you get a plain list of what to fix. Nothing is sent anywhere: this runs in your browser, and there is nothing to sign up for.

This is not an assessment and it does not score you. It counts what you could not answer. Your auditor decides what your evidence is worth.

Section

Do you have a plan at all

The opening questions on almost every security questionnaire.

  • Do you have a formal incident response plan?

    HECVAT 4.1.6, HFIH-01

    What good looks like. A written document someone owns, with a revision date inside the last twelve months.

    What to do if the answer is not yes

    What usually gets written. A wiki page last edited two years ago by someone who has since left.

    Name an owner, and put a version number and a review date on the first page. Length is not the point: six pages someone can follow at 3am beat forty nobody opens. If you are starting from nothing, write four things first, in this order: who declares an incident, how severity is graded, who to call, and what notification deadlines you are on. Everything else can follow later.

  • Do you either have an internal incident response team or retain an external team?

    HECVAT 4.1.6, HFIH-02

    What good looks like. Named people, or a signed retainer. A distribution list is not a team.

    What to do if the answer is not yes

    What usually gets written. "Engineering handles it", or a security@ alias with nobody on the other end.

    Write down three people and a deputy for each: who declares, who runs the technical response, who talks to customers. If you retain a firm, put the contract reference and the hotline in the plan itself, not in a procurement folder. If you have neither, answer no on the questionnaire. A claimed team that cannot be produced on request is worse than an honest gap.

  • Do you have the capability to respond to incidents on a 24 x 7 x 365 basis?

    HECVAT 4.1.6, HFIH-03

    What good looks like. A real rota with escalation, or an honest no.

    What to do if the answer is not yes

    What usually gets written. "Someone always has their phone", which is a habit rather than a capability.

    If you page, name the tool and the escalation policy, including what happens when the first person does not acknowledge. If you do not, answer no and state your actual coverage instead. Buyers accept “business hours, with an out-of-hours page for Sev 1” far more readily than a yes that falls apart on the follow-up call, and the follow-up call always comes.

Section

Can someone act on it at 3am

A plan that reads well and cannot be executed is the common failure.

  • Does the plan name who declares an incident, who runs it, and who tells customers?

    Practice, not a questionnaire item

    What good looks like. Names or named roles with deputies. "The security team" tells nobody what to do.

    What to do if the answer is not yes

    What usually gets written. A RACI chart that lists departments rather than people.

    Three lines is enough: X declares, Y runs the response, Z owns customer and regulator communications. Give each one a deputy. The failure mode is rarely that the role is undefined; it is that the single person holding it is on a plane, and nobody knows who is allowed to decide in their absence.

  • Are severity levels defined with triggers two people would apply the same way?

    Practice, not a questionnaire item

    What good looks like. Written thresholds, not adjectives.

    What to do if the answer is not yes

    What usually gets written. "Sev 1 = critical business impact", which just moves the judgement call one word along.

    Pin each level to something countable: customer data confirmed exposed, production unavailable to all customers, a regulatory clock started, recovery expected to exceed the RTO. Then test the wording. Ask two people to grade last quarter’s worst incident separately, without discussing it. If they disagree, your thresholds are still adjectives, and they will be argued about while the clock runs.

  • Does the plan state your notification deadlines and where they come from?

    Practice, not a questionnaire item

    What good looks like. The contractual and regulatory clocks written down, with their source.

    What to do if the answer is not yes

    What usually gets written. "We will notify affected parties as required", which defers the question to the worst possible moment.

    Build one table: deadline, who it is owed to, and where it comes from. Populate it from your largest customer contracts (notification windows are usually in the security addendum or DPA, commonly 24 to 72 hours), any regulator you answer to, and your cyber insurance policy, which typically requires notification within a set window and where a late call can affect cover. Do this now, because nobody reads an MSA at 3am.

  • Are out-of-hours contacts and vendor escalation paths in the plan?

    Practice, not a questionnaire item

    What good looks like. Reachable numbers, including the vendors you would need, verified this year.

    What to do if the answer is not yes

    What usually gets written. An internal email alias, and a vendor name with no account number.

    Phone numbers, not aliases: email is the first thing you lose in an identity or ransomware incident, and it may be the thing the attacker is reading. Include how to raise a Sev 1 with your cloud provider (which depends on your support tier, so check what you actually pay for), your EDR vendor, outside counsel, and the insurer hotline. Then ring two of them this quarter and write the date next to the number.

Section

Can you show it works

This is the section that decides whether the plan counts as evidence.

  • Are these processes and procedures reviewed, updated, and tested at least annually?

    Cloud Security Alliance Consensus Assessments Initiative Questionnaire Version 4.1.0, SEF-07.2

    What good looks like. A dated exercise with participants and findings. This is the one most plans fail.

    What to do if the answer is not yes

    What usually gets written. "Reviewed annually" with no artifact, which answers half the question and skips the half being asked.

    Two different obligations are hiding in one sentence. Reviewing the document is a diff and an approval date. Testing the response is people making decisions against a scenario, with a record of what they decided. You owe both, and the test is the half that usually does not exist. Put a date in the calendar before you need it; an exercise run the week the auditor asks is visible as one.

  • If asked today, could you produce a record of the last test?

    Practice, not a questionnaire item

    What good looks like. Date, who took part, what was decided, what it surfaced. A calendar invite is not a record.

    What to do if the answer is not yes

    What usually gets written. A slide deck summarising the discussion, written the following week.

    A usable record has four parts: when it ran and for how long, who was in the room and in what role, what was decided and at what time, and what it surfaced. Write it during the exercise rather than afterwards. In a reconstruction, timings and attribution are the first things to disappear, and those two are precisely what separate evidence from an assertion. There is a free template on this site that lays the four parts out for you.

  • Did the last test produce findings with owners, and were they closed?

    Practice, not a questionnaire item

    What good looks like. Findings that name what was expected, what happened instead, an owner and a date.

    What to do if the answer is not yes

    What usually gets written. Findings phrased as sentiment: "communication could be improved".

    Write each finding as what the plan says against what the room actually did, then attach a named owner and a due date, and put it in the tracker you already use rather than leaving it in the exercise document where it will not be looked at again. The question after “did you test it” is always “what did you find and what did you do about it”. An exercise that found nothing reads as an exercise nobody took seriously, and an open finding with an owner and a date is stronger than a closed one nobody can evidence.

The usual answer

Most plans fail the same question.

Not "do you have a plan". Almost everyone does. It is "are these processes reviewed, updated, and tested at least annually", because that one needs a dated record with people in it, and a plan nobody has exercised cannot produce one.

ControlDrill runs that test as a live tabletop on your own systems and plan, and hands back the record. Running one is not by itself the control, and your auditor decides what it is worth.