Skip to main content

SERVICESIGNAL / FICTIONAL SAMPLE / METHOD 1.0

Invented answers and notes, not a customer record or an independently verified assessment. The score is not a probability of recovery.

Sample Incident Readiness Report

Manufacturing and dispatch

Example Manufacturing Ltd (fictional) · Sample output · 4 October 2026

47/ 100
ExposedRemediate before go-live

The building blocks exist, but key parts are not yet dependable under pressure.

Based on reported answers, not a technical test or certification. Methodology 1.0

Top five gaps

Gap 1

Recovery Testing

No

Are table-top exercises or incident simulations run at least annually?

Score lost: 10

Gap 2

Containment

No

Are privileged accounts protected with stronger controls than standard user accounts?

Score lost: 8

Gap 3

Decision Authority

No

Can isolation, shutdown, or emergency spend be authorised out of hours without delay?

Score lost: 8

Gap 4

Third-party Dependencies

No

Do you have current contacts and incident support paths for those suppliers?

Score lost: 8

Gap 5

Containment

Partial

Can you isolate endpoints or disable accounts within minutes, not hours, during an incident?

Score lost: 5

Evidence to request

These requests illustrate follow-up for this fictional result; the documents have not been reviewed.

  • Current isolation authority, including out-of-hours approval and alternates.
  • A scoped restore result with clean-environment checks and business acceptance criteria.
  • Current supplier support contacts, contracted incident scope and a dispatch fallback record.

Tabletop scenario

Scenario: a privileged account is compromised and ransomware starts to spread. 1. a compromised account is able to pivot laterally before anyone can contain it 2. backups are unavailable or unusable when the business tries to recover 3. nobody is sure who has authority to act, so the incident keeps spreading

Focus area: Ransomware and privileged account compromise

Discussion prompt only, not the full facilitated exercise. Do not change live systems or send real stakeholder messages.

Executive action plan

  1. Define isolation steps, emergency revocation authority, and tested containment playbooks.
  2. Harden backup isolation, define recovery targets, and prove restores before an incident forces the test.
  3. Set incident authority, alternates, and escalation thresholds so containment is not blocked by governance.
  4. Document critical dependencies, confirm contacts, and plan fallbacks for supplier-driven outages.
  5. Schedule realistic recovery tests, close the loop on lessons learned, and prove the runbooks work.

Agree an owner, target date, closure evidence and reviewer for each action. A status change alone is not proof of improvement.

Dimension breakdown

01Detection

19/25

Are critical systems centrally logged and monitored through a SIEM, EDR, or equivalent detection stack?

Yes

Do you have out-of-hours alert coverage or a clear escalation path for critical events?

Partial

Are alert thresholds, use cases, and ownership documented for the most likely attack paths?

Yes

Is log retention long enough to support investigation and containment if an attack is discovered late?

Partial

Do you have out-of-hours alert coverage or a clear escalation path for critical events?

Is log retention long enough to support investigation and containment if an attack is discovered late?

Fictional assessor note: Central monitoring is in place. Out-of-hours escalation and retention for some sources are incomplete.

02Containment

7/25

Can you isolate endpoints or disable accounts within minutes, not hours, during an incident?

Partial

Are privileged accounts protected with stronger controls than standard user accounts?

No

Is network segmentation in place for critical services and sensitive administrative paths?

Partial

Are there playbooks for emergency access removal, device quarantine, and identity lockout?

No

Can you isolate endpoints or disable accounts within minutes, not hours, during an incident?

Are privileged accounts protected with stronger controls than standard user accounts?

Fictional assessor note: Isolation depends on provider approval. Privileged identities have no stronger controls than standard accounts; emergency playbooks are absent.

03Backups

9/25

Are backups immutable or offline, with separate credentials from the main environment?

Partial

Are recovery point and recovery time objectives defined for your critical systems?

Partial

Have you tested restores from backup within the last 12 months?

No

Are backup administration privileges protected from the same compromise paths as production?

No

Are backups immutable or offline, with separate credentials from the main environment?

Are recovery point and recovery time objectives defined for your critical systems?

Fictional assessor note: Some backups are isolated. Recovery objectives cover only part of dispatch; no restore has been tested in the last 12 months.

04Communications

19/25

Is there an incident communications plan with named owners and stakeholder groups?

Yes

Are pre-approved templates available for internal, customer, and executive updates?

Partial

Is there a 24/7 contact tree or escalation matrix that works during a crisis?

Partial

Is external comms ownership aligned between operations, legal, and leadership?

Yes

Are pre-approved templates available for internal, customer, and executive updates?

Is there a 24/7 contact tree or escalation matrix that works during a crisis?

Fictional assessor note: Message ownership is agreed. Templates and the contact tree need updating before an exercise.

05Decision Authority

8/25

Is an incident commander or equivalent decision-maker named in advance?

Partial

Can isolation, shutdown, or emergency spend be authorised out of hours without delay?

No

Are decision thresholds documented for scenarios such as ransomware, account compromise, or data exfiltration?

Partial

Are alternates defined if the usual incident lead is unavailable?

Partial

Is an incident commander or equivalent decision-maker named in advance?

Can isolation, shutdown, or emergency spend be authorised out of hours without delay?

Fictional assessor note: The incident lead is named for working hours only. Emergency authority and alternates are incomplete.

06Legal / Compliance

18/25

Are breach notification obligations mapped by jurisdiction, contract, and regulator?

Partial

Is legal or compliance engaged early in the incident response process?

Yes

Are evidence preservation and chain-of-custody requirements documented?

Partial

Are notification windows and required approvals clear to the incident team?

Yes

Are breach notification obligations mapped by jurisdiction, contract, and regulator?

Are evidence preservation and chain-of-custody requirements documented?

Fictional assessor note: The privacy lead is engaged early. Contract mapping and the evidence-preservation procedure need review.

07Third-party Dependencies

7/25

Have you identified critical third-party dependencies such as cloud, DNS, identity, backup, or MSP services?

Partial

Do you have current contacts and incident support paths for those suppliers?

No

Are fallback or manual workarounds documented if a dependency is unavailable?

Partial

Do supplier contracts include incident response support or escalation obligations where needed?

No

Have you identified critical third-party dependencies such as cloud, DNS, identity, backup, or MSP services?

Do you have current contacts and incident support paths for those suppliers?

Fictional assessor note: The dependency list is incomplete, provider support contacts are out of date and incident support scope is not contracted.

08Recovery Testing

6/25

Are table-top exercises or incident simulations run at least annually?

No

Have restore, failover, or recovery drills been performed against real systems or data?

Partial

Are lessons learned from exercises tracked to closure with owners and dates?

Partial

Are recovery success criteria and service restoration thresholds defined in advance?

No

Are table-top exercises or incident simulations run at least annually?

Have restore, failover, or recovery drills been performed against real systems or data?

Fictional assessor note: No annual tabletop has been run. A limited component drill does not establish dispatch recovery; acceptance criteria remain undefined.