Incident response and claims history

How frequently is the IR plan tested (quarterly/semi-annually/annually)?

An untested plan is a document. The test is what converts it into shared knowledge about who does what.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking for a testing cadence, usually offering quarterly, semi-annual, or annual. It means a deliberate exercise against a scenario, with the people who would actually respond, not a review of the document.

Why it is underwritten

Testing surfaces the gaps that only appear under simulated pressure: the contact list is stale, nobody knows who can approve isolating a production system, the forensics firm needs a purchase order, the out-of-band channel does not exist. Every one of those costs hours during a real event, and hours are the currency of business interruption.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Exercise records are the evidence, and they are attested. A dated record with findings is considerably more persuasive than a cadence claim.

PlatformWhere the setting livesWhat has to be true
Exercise recordsDate, scenario, participants, and duration of the last exerciseA real exercise with the right people, recently. Attested
Exercise recordsFindings and the actions taken afterwardsGaps identified and closed, which is the output that makes the exercise worth running
ParticipationWhether executives and communications participated, not only technical staffDecision-makers involved, since the hardest decisions in a real event are not technical
ScenarioWhat was exercisedRansomware and business email compromise at minimum, since those are what actually happens
Plan updatesVersion history showing changes after exercisesThe plan changes as a result, rather than being reaffirmed unchanged each year
A tabletop counts

Carriers are not expecting a full technical simulation. A two-hour tabletop against a ransomware scenario, with the executive team present and a written record of what it found, satisfies this question and is genuinely useful. The bar is lower than most organisations assume, which makes a no here harder to justify.

What a defensible yes requires

  • An exercise has taken place within the stated period, with a record.
  • Executives and communications participated alongside technical staff.
  • The scenario reflected a realistic threat rather than a generic outage.
  • Findings were recorded and closed.
  • The plan was updated as a result.

How this answer goes wrong

The stated cadence is annual and the last exercise was three years ago, or the exercise was a walkthrough of the document with two people from the IT team. Neither tests the decisions that matter, and a claims review that asks for the exercise record will find the gap.

Frequently asked

Does a real incident count as a test?

Yes, if you conducted a review afterwards and captured findings. A post-incident review is arguably the most valuable exercise available.

What cadence do carriers expect?

Annual is the baseline expectation, semi-annual reads well. What matters more is that the record shows the exercise happened and produced changes.

Who should attend?

The people who would actually respond, including an executive with authority to spend and to communicate publicly. Excluding them is the most common reason exercises miss the real bottlenecks.

Can our carrier help run one?

Many offer tabletop exercises as a risk service, sometimes free. It is worth asking, and it produces exactly the record this question wants.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture