Skip to content
FioSec Consulting

3-minute readiness check

If an incident started right now, would your team know what to do?

Incident response is decided before the incident: the plan, the people, and the practical details that either exist at 2 a.m. or don't. Answer ten quick questions for an honest read on how ready you are. Nothing is sent anywhere: your answers are scored right here in your browser.

Incident response readiness questions

How it’s weighted: the exercise question counts double. A plan that has never been rehearsed is a document, not a capability, and it usually fails on first contact with a real incident.

The plan

01 · Written plan

Do you have a written incident response plan that says who does what in the first hours of an incident?

02 · Likely scenarios

Does the plan cover your most likely scenarios specifically (ransomware, a compromised email account, a lost laptop), not just “incidents” in general?

03 · Exercised counts double

Has the plan been tested in the past year, in a tabletop exercise or a real incident?

People & decisions

04 · Roles & authority

Is it clear who leads an incident, and who has the authority to take systems offline or approve emergency spending, at any hour?

05 · Contact list

Is there an up-to-date contact list for everyone the plan involves, kept somewhere reachable even if your systems are down?

06 · Outside help

Do you know exactly who you would call for outside help: incident response or forensics support, your cyber insurer’s hotline, legal counsel?

07 · Notification duties

Do you know who you would be obliged to notify (insurer, regulators, affected individuals, customers) and how quickly?

The practicalities

08 · Out-of-band comms

Could your response team communicate if email and chat were down, or couldn’t be trusted because the attacker may be reading them?

09 · Investigation visibility

Could you reconstruct what happened? Are logs from your key systems collected centrally and retained, with endpoint telemetry to draw on?

10 · Containment

Could you contain an incident within minutes: isolate an infected machine from the network and disable a compromised account?

Ten questions. Answer “Partly” when something exists but is incomplete or out of date; “Not sure” is a valid answer too. No email required; scored in your browser, never sent anywhere.