How frequently is the IR plan tested (quarterly/semi-annually/annually)?
An untested plan is a document. The test is what converts it into shared knowledge about who does what.
What the carrier is actually asking
The carrier is asking for a testing cadence, usually offering quarterly, semi-annual, or annual. It means a deliberate exercise against a scenario, with the people who would actually respond, not a review of the document.
Why it is underwritten
Testing surfaces the gaps that only appear under simulated pressure: the contact list is stale, nobody knows who can approve isolating a production system, the forensics firm needs a purchase order, the out-of-band channel does not exist. Every one of those costs hours during a real event, and hours are the currency of business interruption.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Exercise records are the evidence, and they are attested. A dated record with findings is considerably more persuasive than a cadence claim.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Exercise records | Date, scenario, participants, and duration of the last exercise | A real exercise with the right people, recently. Attested |
| Exercise records | Findings and the actions taken afterwards | Gaps identified and closed, which is the output that makes the exercise worth running |
| Participation | Whether executives and communications participated, not only technical staff | Decision-makers involved, since the hardest decisions in a real event are not technical |
| Scenario | What was exercised | Ransomware and business email compromise at minimum, since those are what actually happens |
| Plan updates | Version history showing changes after exercises | The plan changes as a result, rather than being reaffirmed unchanged each year |
Carriers are not expecting a full technical simulation. A two-hour tabletop against a ransomware scenario, with the executive team present and a written record of what it found, satisfies this question and is genuinely useful. The bar is lower than most organisations assume, which makes a no here harder to justify.
What a defensible yes requires
- An exercise has taken place within the stated period, with a record.
- Executives and communications participated alongside technical staff.
- The scenario reflected a realistic threat rather than a generic outage.
- Findings were recorded and closed.
- The plan was updated as a result.
How this answer goes wrong
The stated cadence is annual and the last exercise was three years ago, or the exercise was a walkthrough of the document with two people from the IT team. Neither tests the decisions that matter, and a claims review that asks for the exercise record will find the gap.
Frequently asked
Does a real incident count as a test?
Yes, if you conducted a review afterwards and captured findings. A post-incident review is arguably the most valuable exercise available.
What cadence do carriers expect?
Annual is the baseline expectation, semi-annual reads well. What matters more is that the record shows the exercise happened and produced changes.
Who should attend?
The people who would actually respond, including an executive with authority to spend and to communicate publicly. Excluding them is the most common reason exercises miss the real bottlenecks.
Can our carrier help run one?
Many offer tabletop exercises as a risk service, sometimes free. It is worth asking, and it produces exactly the record this question wants.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture