Most organisations have an incident response plan.
It's been written, approved, and filed away. What's less common is knowing whether it actually works.
When a cyber incident hits, many organisations are using their plan properly for the first time. That's when the gaps appear.
When plans meet reality
Cyberattacks rarely happen at convenient times. They hit during shift changes, outside working hours, or when key people are unavailable.
Even well-documented plans can break down under pressure. Teams are working with incomplete information, systems may be unavailable, and communication channels become fragmented.
In those moments, common issues emerge:
· Unclear ownership of the response
· Delays in decision-making and escalation
· Confusion over reporting and regulatory obligations
· Gaps between technical, legal, and operational priorities
These are typical issues in organisations that haven’t tested their response.
For businesses in the security sector, the stakes are higher. Your clients rely on you to protect their sites, their people, and their operations. When a cyber incident affects your ability to deliver that service, or worse, compromises client data you hold, it creates a chain reaction that can affect multiple businesses at once.
Testing your decision making
Tabletop exercises simulate a cyber incident in a controlled environment, allowing organisations to walk through their response step by step. The focus is on how you make decisions, not just what the plan says.
These sessions bring together the people who would be involved in a real incident including leadership, IT, operations, legal, finance, HR, and communications. For security businesses, this might also include operations managers coordinating with client sites, account managers who need to communicate with affected clients, or shift supervisors dealing with compromised access control systems.
A typical scenario unfolds in stages.
An initial alert flags suspicious activity. The organisation must decide how to assess the threat and who to involve.
As the situation develops, systems may become unavailable and there may be signs of data compromise. At this point, questions around regulatory notification, external support, and internal communication become more urgent.
If the scenario escalates to ransomware, leadership teams must decide how to respond to operational disruption, potential data loss, and ransom demands, often with limited time and incomplete information.
This is where you can properly test your plans.
What organisations uncover in tabletop exercises
Tabletop exercises tend to reveal similar issues.
Key contact details are missing or out of date. Decision-making authority is unclear. Teams interpret reporting thresholds differently. External partners haven’t been engaged in advance. Backups exist but have not been tested in realistic conditions. Client notification procedures are unclear. If an attack affects data you hold on behalf of clients, who contacts them, what gets said, and when?
None of these issues are unusual. Most are fixable.
The risk comes from discovering them during a live incident. Government data shows that while most organisations report incidents to senior management, only around a third have clear guidance on when to report externally. These gaps get discovered under pressure, when the cost of confusion is highest.
From plans to practical capability
Running through these scenarios builds clarity. Teams understand their roles, decision-making becomes more structured, and communication improves across departments.
It also helps you align legal, technical, and commercial considerations when they’re addressed in advance of an incident.
Organisations leave with clear actions:
· Updates to incident response plans
· Defined ownership of decisions
· Improved communication processes
· Identified gaps in external support
This turns a static document into something usable, which is exactly what your incident response plan should be.
Why this matters now
Major cyber incidents are increasing in frequency and impact. Expectations from regulators, clients, and partners are also rising.
For organisations in the security sector, resilience is part of the service you provide. A cyber incident can affect your clients, your contracts, and your reputation. Preparation reduces that risk.
Citation Cyber – here to help
Citation Cyber work with organisations across the security sector to strengthen their cyber resilience and incident response capability. We understand the unique pressures you're under, and we're here to help you prepare before pressure becomes crisis.
Testing your response in a controlled environment gives you a clear view of how your organisation would perform in practice. And where it needs to improve.
As a BSIA member, you're entitled to exclusive discounts on our cyber security services. To learn more about incident response planning and tabletop exercises, get in touch using the code BSIAMEMBER or call us on 0345 241 3100.