top of page

Your Incident Response Plan Is a Hypothesis Until You Test It

3 hours ago
4 min read

Every IT leader we talk to during Cybersecurity Awareness Month can point to a document. It has a title page, a revision date, a distribution list, and a set of steps to follow if ransomware hits. What most of them can't point to is the last time anyone ran through it.

That gap is the difference between a plan and a defense.


A plan is a claim until someone tests it

An incident response (IR) plan describes what your organization believes it will do during a ransomware event: who gets called, in what order; which systems get isolated first; how backups get validated before restoration; what gets communicated to leadership, customers, and regulators, and when. Every one of those steps is an assumption until it has been exercised against something resembling a real scenario.


Ransomware's share of breaches keeps climbing: it now accounts for 48 percent of all data breaches, up from 44 percent the year before, according to Verizon's 2026 Data Breach Investigations Report — and smaller organizations take the brunt of it, Of the Ransomware

cases where we have information on the organization size, we found that about 96% of Ransomware victims were SMBs. Sophos puts the average cost to recover from a ransomware incident — not counting any ransom paid — at $1.7 million, up 11 percent year over year.


Those figures assume an organization responds the way its plan says it will. Most plans have never been tested to find out.


Why the plan sits untested

This isn't a story about negligence, and it isn't just a government problem. More than 80 percent of state, local, tribal, and territorial organizations report fewer than five staff dedicated to cybersecurity — but the same resource squeeze shows up everywhere else in our client base. Sophos's 2026 research found that smaller organizations, in the 100–250 employee range, succeed at preventing encryption only 34 percent of the time, well behind larger enterprises. A plan gets written — often during onboarding, an audit finding, or a compliance deadline — and then the same lean team that wrote it, whether that's a county IT department, a hospital security office, or a manufacturer's small corporate IT group, moves on to the next fire.


The demands ransomware places on an organization are rarely the ones the plan anticipated, and the research bears that out across every sector we serve. Higher education ransomware attacks rose more than 8 percent in the first half of 2026, while median ransom demands across the education sector rose 53 percent to $420,620 (Comparitech).


Healthcare attacks rose nearly 14 percent over the same period, with median demands around $310,000 for direct care providers (Comparitech). And governments that do get hit pay more often than anyone else — 72 percent of state and local government victims paid, the highest rate Sophos measured across any sector. Attackers are not slowing down to let response plans catch up.


What a real test looks like

Testing an IR plan does not mean simulating an outage by taking production systems offline. It means a structured tabletop exercise: walking a cross-functional group — IT, security, legal, communications, and leadership — through a realistic ransomware scenario in a conference room and watching where the plan holds up (and doesn't).


A properly scoped ransomware readiness assessment goes further than a single tabletop session. It should cover: disaster recovery and IR plan review; the tabletop exercise itself; backup and quarantine capability review (can you restore clean data, and how do you know a backup isn't already compromised); network and endpoint monitoring; EDR evaluation; and an assessment of security awareness training, since most ransomware attacks start with a person, not a firewall.


Findings from that process should map to established frameworks — MITRE ATT&CK, so you can see exactly where and how an attacker would gain a foothold, escalate privileges, and spread; and the NIST Cybersecurity Framework (NIST CSF), so the same findings translate cleanly into a board-level risk conversation.


What this surfaces

In practice, tabletop exercises rarely fail on the technical steps. They fail on the coordination steps: nobody is sure who has the authority to take a system offline at 2 a.m.; the call tree references someone who left the organization eight months ago; the cyber insurance carrier's required notification window is shorter than anyone realized; the “clean” backup turns out to share a network segment with the systems that got encrypted.


These are the gaps a document review will never find, because they only show up when people try to execute the plan under pressure. Our new white paper walks through a real incident in which this played out — and our companion case studies cover what it looks like to find those same gaps proactively, through a readiness assessment or an executive tabletop exercise.


Where Securance stands

Securance's ransomware readiness engagement is built around this gap: senior consultants with 15 or more years of experience run a hands-on tabletop exercise and full assessment of your IR plan, backup and recovery capability, and monitoring posture — then translate the findings into plain-language, board-ready risks mapped to MITRE ATT&CK and NIST CSF.


If your IR plan hasn't been pressure-tested in the last 12 months, Cybersecurity Awareness Month is a good time to change that before a real incident does it for you.


 
 
 

Comments


bottom of page