Untested Incident Response Capability
No incident response plan, or a plan that has never been exercised.
- Remediation SLA
- 30 days
- Tier
- 2 · Regulatory
- Domain
- Processing
- Escalation
- Security manager review at 14 days
What this finding is
There is no documented incident response plan, or the plan exists but has not been tested within the required period. Also covers plans that are documented but unusable in practice — missing current contact details, no defined severity thresholds, or no regulatory notification timelines.
Why it is Tier 2
Incident response planning and annual testing are explicitly required by PCI DSS, ISO 27001, HIPAA, and SOC 2, and assessors ask for the test record rather than the plan. The operational stake is high: breach-notification regimes impose short deadlines — 72 hours under GDPR — and an organisation discovering its plan's gaps during a live incident will miss them. It is Tier 2 because the capability matters at the moment of compromise rather than preventing it.
Most common misclassification
How to detect it
- 1Ask for the plan and its last test record; either being absent is the finding.
- 2Check that the plan names regulatory notification timelines for every applicable regime and jurisdiction.
- 3Verify contact details, escalation paths, and third-party retainers are current — these decay fastest.
- 4Confirm the plan covers cloud and SaaS incidents, not only on-premises scenarios.
How to remediate it
Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.
- 1Document the plan with severity definitions, roles, escalation paths, and notification obligations with their statutory deadlines.
- 2Run a tabletop exercise against a realistic scenario — ransomware and cloud account compromise are the highest-value starting points.
- 3Record lessons learned and update the plan; the update record is the evidence assessors want.
- 4Establish retainers for forensics and legal counsel in advance, since procurement during an incident consumes the notification window.
- 5Test at least annually and after any material change to the estate.
How to verify the fix
A current plan exists with defined severities and notification deadlines, a test conducted within the required period is documented with participants and findings, and resulting plan updates are recorded.
Mappings
Attacker techniques
- T1486Data Encrypted for Impact
Compliance mappings
- PCI DSS v4.012.10.1 / 12.10.2 — incident response plan and annual testing
- ISO/IEC 27001:2022A.5.24 — incident management planning
- GDPRArt. 33 — notification within 72 hours
- SOC 2CC7.4 — incident response