Gap 1
Recovery Testing
Are table-top exercises or incident simulations run at least annually?
Score lost: 10
SERVICESIGNAL / FICTIONAL SAMPLE / METHOD 1.0
Invented answers and notes, not a customer record or an independently verified assessment. The score is not a probability of recovery.
Sample Incident Readiness Report
Example Manufacturing Ltd (fictional) · Sample output · 4 October 2026
The building blocks exist, but key parts are not yet dependable under pressure.
Based on reported answers, not a technical test or certification. Methodology 1.0
Gap 1
Are table-top exercises or incident simulations run at least annually?
Score lost: 10
Gap 2
Are privileged accounts protected with stronger controls than standard user accounts?
Score lost: 8
Gap 3
Can isolation, shutdown, or emergency spend be authorised out of hours without delay?
Score lost: 8
Gap 4
Do you have current contacts and incident support paths for those suppliers?
Score lost: 8
Gap 5
Can you isolate endpoints or disable accounts within minutes, not hours, during an incident?
Score lost: 5
These requests illustrate follow-up for this fictional result; the documents have not been reviewed.
Scenario: a privileged account is compromised and ransomware starts to spread. 1. a compromised account is able to pivot laterally before anyone can contain it 2. backups are unavailable or unusable when the business tries to recover 3. nobody is sure who has authority to act, so the incident keeps spreading
Focus area: Ransomware and privileged account compromise
Discussion prompt only, not the full facilitated exercise. Do not change live systems or send real stakeholder messages.
Agree an owner, target date, closure evidence and reviewer for each action. A status change alone is not proof of improvement.
Are critical systems centrally logged and monitored through a SIEM, EDR, or equivalent detection stack?
YesDo you have out-of-hours alert coverage or a clear escalation path for critical events?
PartialAre alert thresholds, use cases, and ownership documented for the most likely attack paths?
YesIs log retention long enough to support investigation and containment if an attack is discovered late?
PartialDo you have out-of-hours alert coverage or a clear escalation path for critical events?
Is log retention long enough to support investigation and containment if an attack is discovered late?
Fictional assessor note: Central monitoring is in place. Out-of-hours escalation and retention for some sources are incomplete.
Can you isolate endpoints or disable accounts within minutes, not hours, during an incident?
PartialAre privileged accounts protected with stronger controls than standard user accounts?
NoIs network segmentation in place for critical services and sensitive administrative paths?
PartialAre there playbooks for emergency access removal, device quarantine, and identity lockout?
NoCan you isolate endpoints or disable accounts within minutes, not hours, during an incident?
Are privileged accounts protected with stronger controls than standard user accounts?
Fictional assessor note: Isolation depends on provider approval. Privileged identities have no stronger controls than standard accounts; emergency playbooks are absent.
Are backups immutable or offline, with separate credentials from the main environment?
PartialAre recovery point and recovery time objectives defined for your critical systems?
PartialHave you tested restores from backup within the last 12 months?
NoAre backup administration privileges protected from the same compromise paths as production?
NoAre backups immutable or offline, with separate credentials from the main environment?
Are recovery point and recovery time objectives defined for your critical systems?
Fictional assessor note: Some backups are isolated. Recovery objectives cover only part of dispatch; no restore has been tested in the last 12 months.
Is there an incident communications plan with named owners and stakeholder groups?
YesAre pre-approved templates available for internal, customer, and executive updates?
PartialIs there a 24/7 contact tree or escalation matrix that works during a crisis?
PartialIs external comms ownership aligned between operations, legal, and leadership?
YesAre pre-approved templates available for internal, customer, and executive updates?
Is there a 24/7 contact tree or escalation matrix that works during a crisis?
Fictional assessor note: Message ownership is agreed. Templates and the contact tree need updating before an exercise.
Is an incident commander or equivalent decision-maker named in advance?
PartialCan isolation, shutdown, or emergency spend be authorised out of hours without delay?
NoAre decision thresholds documented for scenarios such as ransomware, account compromise, or data exfiltration?
PartialAre alternates defined if the usual incident lead is unavailable?
PartialIs an incident commander or equivalent decision-maker named in advance?
Can isolation, shutdown, or emergency spend be authorised out of hours without delay?
Fictional assessor note: The incident lead is named for working hours only. Emergency authority and alternates are incomplete.
Are breach notification obligations mapped by jurisdiction, contract, and regulator?
PartialIs legal or compliance engaged early in the incident response process?
YesAre evidence preservation and chain-of-custody requirements documented?
PartialAre notification windows and required approvals clear to the incident team?
YesAre breach notification obligations mapped by jurisdiction, contract, and regulator?
Are evidence preservation and chain-of-custody requirements documented?
Fictional assessor note: The privacy lead is engaged early. Contract mapping and the evidence-preservation procedure need review.
Have you identified critical third-party dependencies such as cloud, DNS, identity, backup, or MSP services?
PartialDo you have current contacts and incident support paths for those suppliers?
NoAre fallback or manual workarounds documented if a dependency is unavailable?
PartialDo supplier contracts include incident response support or escalation obligations where needed?
NoHave you identified critical third-party dependencies such as cloud, DNS, identity, backup, or MSP services?
Do you have current contacts and incident support paths for those suppliers?
Fictional assessor note: The dependency list is incomplete, provider support contacts are out of date and incident support scope is not contracted.
Are table-top exercises or incident simulations run at least annually?
NoHave restore, failover, or recovery drills been performed against real systems or data?
PartialAre lessons learned from exercises tracked to closure with owners and dates?
PartialAre recovery success criteria and service restoration thresholds defined in advance?
NoAre table-top exercises or incident simulations run at least annually?
Have restore, failover, or recovery drills been performed against real systems or data?
Fictional assessor note: No annual tabletop has been run. A limited component drill does not establish dispatch recovery; acceptance criteria remain undefined.
Continue from this result