Question: Has the organization conducted incident-response drills or tabletop exercises to validate readiness?
Why This Matters
Practice reveals gaps that policies hide. Drills build confidence, reduce panic, and shorten response time when real crises occur.
Maturity
0 — Unaware
No testing performed.
No testing performed.
1 — Ad Hoc
Unstructured discussion after major events.
Unstructured discussion after major events.
2 — Defined
Annual tabletop exercise scheduled.
Annual tabletop exercise scheduled.
3 — Managed
Realistic scenarios; lessons logged and tracked.
Realistic scenarios; lessons logged and tracked.
4 — Integrated
Joint exercises with partners and vendors.
Joint exercises with partners and vendors.
5 — Optimized
Continuous simulation and red-team validation.
Continuous simulation and red-team validation.
How to Level Up
| From → To | Actions |
|---|---|
| 0 → 1 | Discuss past incidents informally. |
| 1 → 2 | Plan and run basic tabletop with core team. |
| 2 → 3 | Record findings and assign CAPAs. |
| 3 → 4 | Invite vendors/clients to joint exercise. |
| 4 → 5 | Adopt continuous red-/purple-team program. |
Enablers
- People: IR Manager, Risk Officer, Comms Lead.
- Process: Annual exercise plan, CAPA tracking.
- Technology: Drill simulation platform / checklist app.
Evidence
- Drill agenda & attendance.
- Lessons learned register.
- Closed CAPA log.
KPIs
- Number of drills per year.
- Findings closed within 90 days.
- Average response time improvement per cycle.
Low-Cost / Open-Source Options (MSME)
| Purpose | Tool | Notes |
|---|---|---|
| Simulation | Tabletop Toolkit / custom scripts | Offline drills. |
| CAPA tracking | Airtable / Odoo Community | Follow-ups. |
| Recording | Obsidian / Markdown | Evidence journal. |
Common Pitfalls
- Drills become checkbox activities.
- No follow-up on findings.
- Scenarios unrealistic.
Compliance Mapping
| Standard | Clauses / Notes |
|---|---|
| ISO/IEC 27001:2022 | A.5.24 / A.10 (Improvement) |
| CERT-In 2022 | Section 30 (Exercise and Testing) |
| DPDP Act 2023 | Sec 10 (Accountability) |
| NIST CSF 2.0 | RS.IM / RC.MI |
| NIRMATA Mapping | IR-Q04 validates incident readiness testing. |