What counts as evidence that an incident-response plan has been tested?
Glassbreak Team · Published 2026-07-24
"Do you test your incident-response plan at least annually?" looks like a yes/no question. It isn't. On a claim — or in an audit — the follow-up is always the same: show us. When was it tested, against what scenario, who was in the room, what decisions were made, what gaps surfaced, and what changed afterward. This page defines what qualifies as a test, what evidence actually survives that follow-up, and gives you a log template so your next exercise documents itself.
What qualifies as a test
Three formats are broadly accepted, in ascending order of strength:
- Structured walkthrough. The responders step through the plan against a scenario, section by section. Weakest form that still counts — acceptable as a first-ever test, not as a steady state.
- Tabletop exercise. A facilitator injects a developing scenario ("your EDR console is down", "the attacker emails the CFO"); responders make real decisions in real time; a scribe records everything with timestamps. This is the sweet spot for 20–200-person organizations: a half-day investment producing evidence that satisfies the annual-testing question and maps to ISO 27001's incident-management controls (A.5.24–A.5.27).
- Functional / live drill. Actually failing over, actually invoking break-glass access, actually sending the emergency broadcast. Strongest evidence; run one once the tabletop stops surfacing new gaps.
What does not qualify: emailing the plan "for review", a lunch-and-learn about incident response, or any exercise that produced no written record. For evidence purposes, an undocumented test is indistinguishable from no test.
The evidence bar
An artifact that survives underwriter or auditor scrutiny has six elements:
| Element | What to capture |
|---|---|
| Date & duration | When the exercise ran, start to finish |
| Scenario | What was simulated, specifically — "ransomware detonation with IdP compromise", not "a cyber incident" |
| Participants & roles | Named responders and their exercise roles: incident lead, scribe, facilitator, observers |
| Timestamped decision log | Each inject, the decision made, who made it, and when — the core of the artifact |
| Findings | Gaps discovered: stale contacts, unreachable credentials, unclear authority, missing runbook steps |
| Remediation | Each finding assigned an owner and a date; evidence the previous exercise's findings were closed |
The decision log is what separates real evidence from theater. "We discussed the ransomware scenario" proves a meeting occurred. "14:22 — decided to invoke break-glass for the hypervisor admin account; quorum approval from J.M. and A.K. at 14:26" proves the plan operates.
Test the scenario the questionnaire cares about
If you run one exercise this year, make it identity-plane loss: ransomware with your IdP or SSO compromised. It forces answers to the questions the rest of the application asks:
- Where are the break-glass credentials, and can the responders actually release them when the password manager behind SSO is locked too?
- How do you coordinate when email, Slack, and ticketing are compromised or unavailable — what is the out-of-band channel, and does everyone know it?
- Who has authority to disconnect systems, and is that decision path written down?
Organizations running this scenario for the first time almost always find at least one blocking gap — a sole keyholder on leave, a recovery code in the very vault that's locked, an emergency contact list two hires out of date. Finding it in a tabletop costs an afternoon. Finding it during the real thing costs the incident.
How Glassbreak fits (and honest limits)
Glassbreak's guided tabletop exercises ship the scenario library (ransomware + IdP compromise, key person unavailable, cloud provider outage, data-breach disclosure), record every inject, decision, and action with occurred_at timestamps in sequence, and export a printable report per exercise — the artifact this page describes, generated as a by-product of running the drill. The evidence pack maps completed exercises to the insurance-questionnaire and ISO/DORA/NIS2 themes. Honest limits: Glassbreak is not an insurer and doesn't certify your plan; the report evidences that you tested it. For the wider renewal-form context see the questionnaire prep guide; for the emergency-access procedure the same audits sample, the ISO 27001 break-glass template.
Frequently asked questions
- Does a tabletop exercise count as "testing" the IR plan?
- For most questionnaires and SMB audits, yes — provided it produces evidence. A tabletop that walks a realistic scenario with the actual responders, records decisions with timestamps, and ends with written findings and owners is a recognized test of the plan. What doesn't count: circulating the plan for review, a slide-deck briefing with no decisions, or an exercise nobody wrote down.
- How often should the plan be tested?
- Annually is the floor the questionnaire asks about; the defensible pattern is one full exercise per year plus a re-test after material change — new critical vendor, leadership change among responders, or a real incident that exposed gaps. Some EU regimes in scope for DORA expect more structured and more frequent testing for critical functions, so check your regulatory floor before settling on a cadence.
- Who has to participate for the test to be credible?
- The people who would actually respond — not a delegate who takes notes for them. An exercise where the incident lead, the person with break-glass release authority, and the comms owner all participated (with names in the log) is credible. External parties like a vCISO or IR retainer firm strengthen it further; they can be recorded as facilitator or observer.
- Can Glassbreak run the exercise for us?
- Glassbreak provides guided tabletop scenarios (including ransomware + IdP compromise), records every inject, decision, and action with timestamps, and exports the report — so the evidence produces itself as you run the exercise. Facilitation is yours or your consultant's; the product is the harness and the record, not a consulting service.