Cybersecurity

What Is an Incident Response Drill? A Small-Business Guide

An incident response drill is a planned exercise where your team practices detecting, containing, and recovering from a simulated security incident, ransomware, a phishing-driven account compromise, a stolen laptop, before a real one happens. The point isn't to see if your written incident response plan looks good on paper. It's to find out whether the people who'd actually have to execute it, IT, leadership, legal, HR, know what to do in the first hour, who to call, and what not to do that would make things worse. A drill is cheap. Finding these gaps for the first time during a real breach is not.

The Four Types of Incident Response Drills

Not every drill looks the same, and the right type depends on how mature your program already is.

Drill type What happens Best for
Tabletop exercise A facilitator walks the team through a scenario verbally, everyone describes what they'd do at each step. No systems are touched. First drill for any team; leadership and cross-department participants
Walkthrough The team physically follows the incident response plan step by step, checking that runbooks, contact lists, and access actually work, without triggering real containment actions. Validating that the written plan matches reality
Simulation A realistic but controlled event is triggered, a simulated phishing click, a test alert in your EDR or SIEM, and the team responds as if it were real. Teams that have run tabletop exercises and want to test actual tooling and detection
Full-scale exercise A live, largely unannounced test involving IT, leadership, and sometimes outside partners (legal, insurance, a forensics firm), run close to how a real incident would unfold. Mature programs with an established plan that want to test it under real time pressure

Most 20 to 200-person businesses should start with a tabletop exercise. It's the lowest-cost, lowest-disruption way to find the gaps, missing contacts, unclear authority to shut down a system, no one who knows the cyber insurance policy's notification deadline, before investing in anything more elaborate.

A 6-Step How-To for a 20 to 200-Person Business

  1. Pick one realistic scenario. Don't try to cover every threat at once. Choose the incident type most likely to hit your business: ransomware on a file server, a business email compromise, or a lost or stolen laptop with access to customer data.
  2. Identify who's in the room. IT or your MSP, an owner or executive who can approve a decision (like paying a ransom or shutting down operations), and anyone who'd need to notify customers, insurers, or regulators. A drill without a decision-maker in the room just tests IT's knowledge, not the business's.
  3. Write a short scenario brief. A page is enough: what was detected, when, and by what (an alert, an employee report, a customer complaint). Don't hand out the "correct" answers in advance.
  4. Run the exercise and take notes on gaps, not blame. As the scenario unfolds, a facilitator asks "what do you do now?" at each stage and records what the team actually knows versus what they assume. The goal is finding gaps, not scoring individuals.
  5. Time the critical decisions. How long until someone identified who has authority to isolate a system? How long until someone knew whether the cyber insurance policy required notification within a specific window? These timestamps are what you'll compare drill over drill.
  6. Document findings and fix the plan. Every drill should produce a short list of specific fixes, an outdated contact number, a missing step in the runbook, a person who didn't know they had authority to act, with an owner and a deadline. A drill that doesn't change anything wasn't worth running.

A Sample Scenario

Here's a workable tabletop scenario for a 40-person professional services firm: "At 7:40 AM, your MSP's monitoring flags unusual after-hours login activity on your file server from an unfamiliar IP address. By 8:15 AM, an employee reports several shared folders show files renamed with an unfamiliar extension. It is now 8:20 AM." Walk the room through it: Who gets the first call? Who decides whether to disconnect the server from the network, and does that person know they have the authority to make that call before the owner is reachable? Who checks the cyber insurance policy for required notification timelines? Who drafts a holding statement if a client asks what's happening? Most first-time drills discover that at least one of those questions has no clear answer.

What to Measure

A drill that doesn't produce a number is hard to compare next time. Track time-to-detect (how long between the simulated event and someone noticing), time-to-contain (how long until a decision-maker approved isolating the affected system), and time-to-notify (how long until the right internal and external parties, including any regulatory or contractual deadline, were identified and briefed). Track these across drills, not just within one, since the real value is watching the numbers improve, or catching that they didn't.

How Often to Run One

A tabletop exercise once or twice a year is a reasonable baseline for a small or mid-size business, more often if your team, vendors, or systems change significantly, or after any near-miss that revealed a gap. Annual is a floor, not a target: a business in a regulated industry, or one that has grown quickly, benefits from running one every time the incident response plan itself changes, not just on a fixed calendar.

Common Mistakes

  • Running it as an IT-only exercise. If leadership, legal, or HR aren't in the room, the drill never tests who actually has authority to make the hard calls under pressure.
  • Treating it as a pass/fail test. A drill exists to find gaps. If people are afraid of "failing," they stop surfacing the real problems.
  • Never writing down the findings. A drill with no documented follow-up items is a meeting, not a drill.
  • Only ever running the same scenario. Ransomware, business email compromise, and a stolen device each expose different gaps. Rotate scenarios over time.
  • Skipping it because "we have a plan." A written incident response plan that has never been exercised is untested by definition. The drill is what proves the plan works outside the document.

How a Managed IT and Security Provider Runs This

A managed IT and security provider brings two things a business usually can't build in-house on its own: an outside facilitator who isn't part of the internal blame dynamic, and the technical detail to make the scenario realistic, what your EDR platform actually shows, how your backup and recovery process actually performs under time pressure, and what a real detection alert from your monitoring stack looks like. If you already have a managed cybersecurity relationship, ask whether an incident response tabletop is part of it. If you're not sure your plan would survive a real test, an IT assessment is a reasonable place to start before scheduling a drill, since it surfaces the gaps a drill would otherwise have to find live.

Further Reading

For a deeper technical reference on the incident handling lifecycle, see NIST SP 800-61: Computer Security Incident Handling Guide. CISA also publishes free, ready-to-use scenario materials through its Tabletop Exercise Packages, a practical starting point if you're building your first scenario from scratch. For the broader audit this drill should sit inside, see our IT security audit checklist, and for the full picture of managed protection, our cybersecurity services overview.

Frequently Asked Questions

What is an incident response drill?

An incident response drill is a planned exercise where a team practices detecting, containing, and recovering from a simulated security incident, such as ransomware or a compromised account, before a real one occurs. It tests whether the people responsible for responding know what to do, who to call, and what decisions they have authority to make, rather than just testing whether a written plan looks complete.

What is the difference between a tabletop exercise and a full incident response drill?

A tabletop exercise is a discussion-based walkthrough where the team describes what they'd do at each stage of a scenario, without touching any systems. A full-scale drill is a live, largely unannounced exercise that involves IT, leadership, and sometimes outside partners like legal or a forensics firm, run close to how a real incident would actually unfold. Most small businesses should start with a tabletop before attempting anything more involved.

How often should a small business run an incident response drill?

Once or twice a year is a reasonable baseline for most 20 to 200-person businesses, with an additional drill after any significant change to your team, vendors, or systems, or after a near-miss that exposed a gap. Annual should be treated as a minimum, not a target, especially for regulated industries or fast-growing companies.

Who should be involved in an incident response drill?

At minimum: IT or your managed service provider, and a leadership decision-maker who can approve actions like isolating a system or engaging outside help. Depending on the scenario, legal, HR, and whoever would handle customer or regulatory notification should also participate. A drill limited to IT alone never tests who actually has authority to make the hard calls under pressure.

Not Sure Your Incident Response Plan Would Hold Up?

An IT assessment surfaces the gaps a drill would otherwise have to find during a live incident.

Request a Cybersecurity Consultation
Ryan Gyure

Ryan Gyure

Co-Founder and Managing Partner

Ryan Gyure is the Co-Founder and Managing Partner at Unio Digital. With over 15 years of experience in IT, project management, and web development, he helps businesses build secure, efficient technology environments.

Unió Digital is an Arizona ROC-licensed contractor (ROC 327245, ROC 333580) and licensed alarm business (25254-0), serving Southern Arizona since 2016.

Connect on LinkedIn