Is Your incident Response Plan Actually Going to Work? | LDD Consulting

Is Your Incident Plan Actually Going to Work?

Here’s How You Find Out

By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published August 6, 2026 | 6 min read

Is Your Incident Plan Actually Going to Work

THE SHORT ANSWER

The only way to know if your incident response plan will actually work is to test it before a real attack forces you to find out. A tabletop exercise — a structured walkthrough where your team responds to a simulated cyberattack scenario — exposes the gaps, unclear roles, and outdated contact info that live inside every untested plan. Businesses that skip this step often discover their plan fails at the exact moment they need it most.

Why Having a Plan Isn’t the Same as Having a Working Plan

A lot of Albuquerque business owners check the “incident response plan” box, file it away in a shared drive, and never look at it again. That’s understandable — writing the plan felt like the hard part. But a plan that’s never been tested is really just a document with good intentions.

We’ve seen it happen: a client had a solid, well-written plan on paper. When a real ransomware incident hit, the plan named an IT contact who’d left the company eight months earlier. The escalation chain broke down in the first ten minutes — the exact moment speed mattered most.

Organizations with a tested incident response plan consistently contain breaches faster and at lower cost than those without one. The plan itself isn’t what saves you. The rehearsal is.

Pro tip: If your plan hasn’t been reviewed or tested in the last 12 months, treat it as outdated — even if nothing on paper has technically changed.

What a Tabletop Exercise Actually Is

A tabletop exercise is a low-stakes, low-cost simulation. No systems get shut down, nothing goes offline — your team simply talks through how they’d respond to a realistic scenario, step by step, out loud, in a room or on a call.

Who Should Be in the Room

Not just IT. Include whoever would actually be involved in a real incident: leadership, your IT support contact, HR, and anyone who’d need to communicate with customers or vendors.

What a Scenario Looks Like

A facilitator — often your MSP — presents a realistic situation, such as a ransom note appearing on a workstation Monday morning, and the team responds in real time, discussing what they’d actually do next.

What You’re Testing

You’re not testing technology. You’re testing decision-making, communication speed, and whether people actually know their role once the pressure is on.

How to Run Your First Tabletop Exercise

Step 1 — Pick a Realistic Scenario

Start with the threat most likely to hit your business — ransomware, a business email compromise, or a vendor breach are common starting points for SMBs.

Step 2 — Walk Through It Live

Set aside 60–90 minutes. Present the scenario in stages and let the team respond to each stage before revealing what happens next. Resist the urge to solve it for them.

Step 3 — Document the Gaps

Every exercise reveals something — an outdated contact, a missing backup verification step, confusion over who’s authorized to make the call to shut systems down. Write it all down.

Step 4 — Update the Plan and Repeat

Fix what you found, then run the exercise again in 6–12 months. Treat this like a fire drill, not a one-time event.

Pro tip: Your cyber insurance policy may require documented proof of incident response testing to pay out on a claim. Ask your provider directly — this is increasingly common, and it overlaps with broader compliance requirements many businesses are already tracking. 

Common Mistakes Businesses Make

Mistake 1 — Writing the Plan and Never Opening It Again

We see this constantly with new clients. The plan exists, it looks thorough, and nobody in the building has read it in over a year.

Mistake 2 — Only Involving IT

A real incident touches leadership, HR, and communications — not just the technical team. If those people aren’t part of the test, they won’t know what to do during the real thing.

Mistake 3 — Treating the Plan as Static

Staff turnover, new software, and new vendors all make an untested plan go stale fast. A plan from two years ago rarely reflects who’s actually on your team today.

Mistake 4 — Forgetting Recovery, Not Just Response

Responding to the incident is only half the plan. If your team doesn’t also know how data and systems actually get restored, you’re missing the second half of the exercise — this is where data recovery planning comes in.

Frequently Asked Questions

How often should we run a tabletop exercise?

Once a year at minimum, or sooner after any major staffing or vendor change.

Do we need special software to run one?

No — a facilitator, a realistic scenario, and a room or video call is enough to get real value.

Can our MSP run this for us?

Yes — this is a service LDD provides directly as part of our managed IT services, since we can bring an outside perspective and realistic scenarios your team hasn’t already anticipated.

What if the exercise reveals big problems?

That’s the point. Better to find them in a 90-minute exercise than during a real breach. If you’re not confident in your current plan, contact us and we’ll help you find the gaps before an attacker does.

Is tabletop testing part of a broader cybersecurity strategy, or a standalone task?

It should be part of a broader strategy. Incident response testing works best alongside ongoing cybersecurity monitoring and prevention — the plan is your safety net, not your only line of defense.

David Luft

CEO, LDD Consulting

David founded LDD Consulting in 2003 with a straightforward mission: help small and mid-sized businesses in Albuquerque and across New Mexico get reliable, enterprise-quality IT support without the enterprise price tag. He holds an MBA with a concentration in Information Systems from the University of New Mexico, along with Microsoft Certified Systems Engineer (MCSE) and Microsoft Certified Trainer (MCT) credentials. He’s been solving business technology problems for more than 25 years. 

Linkedin |  Learn More About David