Incident Response Testing — Proposal
Incident Response Testing · Confidential

Incident Response
Scenario Testing
Program.

Prepared for [Organization Name] — a structured program of tabletop exercises and scenario simulations that tests your team's real response capability before an actual incident forces the test.

Prepared for
[Contact Name]
[Title, Organization]
Prepared by
[Account Executive]
Lexcom Systems Group
Date
[Date]
Valid until
[30 days]
Introduction

An incident response plan that has never been tested is not a plan.

Most organizations that have incident response plans have never tested them. Plans are written, reviewed, filed — and then activated for the first time under the worst possible conditions: during a real incident, with real consequences, while everyone is already under pressure. The gaps surface at exactly the wrong moment.

Lexcom's incident response testing program addresses this by running structured scenario exercises before an incident occurs. Each exercise is built around a realistic threat scenario specific to your industry and environment, involves the actual people who would respond to a real incident, and produces a detailed after-action report with specific, actionable findings.

The goal is not to produce a passing grade. The goal is to find the gaps — in your plan, in your team's decision-making, in your communication procedures, and in your technical recovery capability — while there is still time to close them.

Find gaps
Identify weaknesses in your plan, team, and technology before an attacker does
Build muscle
Build the decision-making confidence that only comes from having done it before
Satisfy auditors
Produce documented evidence of IR testing for insurers, auditors, and regulators
Exercise structure

How every exercise is structured.

Each scenario exercise follows a consistent five-phase structure. Exercises are conducted in a controlled environment — no live systems are affected — but participants are expected to make real decisions and engage with the scenario as they would in an actual incident.

01
Briefing
Scenario context, rules of engagement, participant roles, and objectives
02
Scenario inject
Initial incident notification — teams respond as they would to a real alert
03
Decision rounds
Facilitator introduces escalating injects — teams make decisions, Lexcom observes
04
Hot debrief
Immediate team debrief — what worked, what didn't, first observations
05
After-action report
Detailed findings, gap analysis, and prioritized recommendations delivered within 5 business days
Format
Tabletop (discussion-based) or functional (limited live activities) — selected per scenario
Duration
2–4 hours per exercise depending on scenario complexity and participant count
Participants
IT team, leadership, legal/compliance, communications — scenario determines who is included
Scenario 01
Critical Severity · Ransomware

Ransomware Attack & Encryption Event

P1 — Critical Ransomware detected across multiple systems
Monday morning. Your IT monitoring platform fires alerts at 6:47 AM — ransomware is actively encrypting files across three servers and spreading laterally across the network. The attacker has been in the environment for [XX] days undetected. A ransom note is on every encrypted machine. Production systems, file shares, and your backup server may all be affected.
Duration: 3–4 hours
Participants: IT, leadership, legal, communications
Format: Tabletop + limited functional

What this exercise tests

Initial detection & escalationWho gets called first, in what order, and how quickly — and whether the right people are reachable

Containment decision-makingWhether to isolate systems immediately or investigate first — and who has authority to decide

Backup integrity assessmentWhether your backups are clean, how long recovery takes, and whether RTOs are realistic

Pay vs restore decision processWho makes the ransom payment decision, under what criteria, and what the insurer notification requirement is

External communicationCustomer, supplier, and regulator notification — who drafts it, who approves it, when it goes out

Business continuity activationWhether manual fallback procedures exist and are actually usable without primary systems

Key inject scenarios

Lexcom's facilitator introduces escalating developments during the exercise to test decision-making under uncertainty:

"The backup server was also encrypted — you cannot confirm whether your last clean backup is intact."
"The attacker has posted a sample of what appears to be customer data on a dark web leak site."
"A journalist has called asking about the outage. Your website is down and customers are asking on social media."
"72 hours have passed. Recovery is taking longer than estimated. A major customer is threatening to cancel their contract."
Scenario 02
High Severity · Email Compromise

Business Email Compromise (BEC)

P2 — High Executive email account compromised — fraudulent wire transfer initiated
Your CFO's email account was compromised [XX] days ago via a targeted phishing email. The attacker has been monitoring email traffic silently, intercepting a pending wire transfer negotiation, and has now sent modified banking instructions to your accounts payable team impersonating the CFO. A [XX] wire transfer has been sent to an attacker-controlled account. The fraud is discovered when the real CFO follows up on a payment.
Duration: 2–3 hours
Participants: IT, finance leadership, legal, executive team
Format: Tabletop

What this exercise tests

Email forensics capabilityCan your team determine how long the attacker had access and what was read or exfiltrated?

Wire transfer recall procedureWho contacts the bank, within what timeframe, and what the realistic recovery probability is

Scope assessmentHow to determine whether other accounts or systems were compromised beyond the initial account

Regulatory notificationWhether this constitutes a reportable data breach under PIPEDA and what the timeline obligation is

Insurance claim processWhat your cyber insurance covers for financial loss from BEC and what documentation is required

Control gap identificationWhat MFA, approval workflow, or vendor confirmation controls would have prevented the incident

Key inject scenarios

"The attacker also accessed the CFO's calendar — they knew exactly who to impersonate and when the payment was expected."
"Email logs show the attacker set up a forwarding rule — all emails matching 'invoice' or 'payment' have been forwarded to an external address for the past 3 weeks."
"The bank confirms the funds have already been transferred internationally. Recall is unlikely but not impossible."
Scenario 03
Critical Severity · Data Breach

Customer / Patient Data Breach

P1 — Critical Sensitive customer data exfiltrated and posted publicly
A security researcher contacts your organization with evidence that a database containing [XX,XXX] customer records — including names, contact information, and [sensitive data type] — is available for sale on a dark web forum. The data appears to have been exfiltrated [XX] weeks ago through a compromised web application. You have had no indication of a breach until this notification.
Duration: 3–4 hours
Participants: IT, legal, executive, communications, customer service
Format: Tabletop

What this exercise tests

Breach validation processHow to confirm whether the data is real, from your systems, and what the actual scope is

PIPEDA notification obligations72-hour OPC notification requirement — who files it, what must be included, what constitutes "real risk of significant harm"

Individual notification processWho are the affected individuals, how are they notified, in what timeframe, and by what channel

Media responseWhether to proactively disclose, how to respond to press inquiries, and who is the authorized spokesperson

Legal exposure assessmentClass action risk, regulatory investigation preparation, and evidence preservation requirements

Forensic investigationHow to determine the attack vector, dwell time, and full scope without destroying evidence

Key inject scenarios

"A local news outlet has published a story citing the dark web forum post. Your phone is ringing."
"Forensic analysis suggests the attacker had access for 6 weeks. You cannot confirm what other data may have been accessed."
"A class action law firm has announced an investigation on behalf of affected customers."
Scenario 04
High Severity · Insider Threat

Malicious Insider / Departing Employee

P2 — High Departing employee exfiltrates sensitive data before resignation
A senior employee submitted their resignation two weeks ago and worked out their notice period. One week after their departure, a DLP alert surfaces showing that in the 48 hours before their last day, they copied [XX]GB of data to a personal USB drive and emailed themselves a customer list, pricing models, and internal project files. They are now employed by your largest competitor.
Duration: 2–3 hours
Participants: IT, HR, legal, executive leadership
Format: Tabletop

What this exercise tests

Evidence preservationHow to collect and preserve forensic evidence in a way that supports potential legal action

Legal response optionsCease and desist, injunctive relief, and civil/criminal options — and who makes the decision to pursue

Offboarding gap analysisWhat access the employee retained after departure that should have been revoked immediately

Data exposure assessmentWhether taken data constitutes a reportable breach or trade secret theft

Competitor notificationWhether to contact the competitor directly, and what the legal implications are

Control gap remediationWhat DLP, access review, and offboarding controls would have prevented or detected this earlier

Scenario 05
High Severity · Third Party

Third-Party / Supply Chain Compromise

P2 — High Key vendor suffers breach — your systems may be affected via trusted connection
One of your key technology vendors — a managed service provider with privileged access to your environment — announces a major cybersecurity incident affecting their systems. They cannot confirm whether their access to your environment was used as part of the attack. You have a Business Associate Agreement (or vendor access agreement) in place but have never tested what happens if that vendor becomes a threat vector.
Duration: 2–3 hours
Participants: IT, legal, procurement, executive leadership
Format: Tabletop

What this exercise tests

Vendor access inventoryWhether you know what access the vendor has, to which systems, and how to revoke it immediately

Compromise indicatorsHow to determine whether your environment was accessed via the vendor's compromised credentials

Vendor relationship managementWhether to suspend vendor access while investigating, and the contractual and operational implications of doing so

Breach notification obligationsWhether a vendor compromise that may have exposed your data triggers your own notification obligations

Vendor risk program gapsWhat vendor security assessment, access controls, and contractual requirements would have reduced exposure

Alternative vendor readinessWhether you can operate without this vendor while the incident is investigated and resolved

Scenario 06
High Severity · Credential Compromise

Credential Theft & Account Takeover

P2 — High Multiple staff credentials compromised via phishing — attacker has active access
A sophisticated phishing campaign targeted [XX] staff members over the past week using a convincing Microsoft 365 login page. [X] employees clicked the link and entered their credentials. Your monitoring platform detects an anomalous login from an unusual geography for one of the compromised accounts at 2:17 AM. MFA was not enabled on [XX]% of accounts.
Duration: 2–3 hours
Participants: IT, HR, affected department managers
Format: Tabletop + functional (credential reset simulation)

What this exercise tests

Compromised account identificationHow to rapidly identify all potentially compromised accounts and their system access scope

Mass credential reset processSpeed and completeness of credential reset across all affected accounts without disrupting operations

MFA emergency enforcementWhether you can rapidly enable MFA for all accounts and what the operational impact is

Session revocationWhether active attacker sessions can be terminated and how to confirm the attacker no longer has access

Activity auditWhat the attacker accessed, read, or exfiltrated during the access window

Staff communicationHow to notify affected staff, what they need to do, and how to prevent panic or further phishing response

Scenario 07
Critical Severity · Infrastructure

Critical Infrastructure Failure

P1 — Critical Primary server room failure — extended outage across all systems
A power surge at your primary facility has caused catastrophic failure of your server room cooling system. Multiple servers have overheated and shut down. Your primary file server, email system, ERP, and VoIP phone system are all offline. The hardware damage assessment is not yet complete. Your cloud backup is accessible but full restoration time is unknown. Staff are arriving for the morning shift with no working systems.
Duration: 3–4 hours
Participants: IT, operations, executive team, HR
Format: Tabletop + functional (restoration simulation)

What this exercise tests

Restoration sequencingIn what order systems are restored — which dependencies exist and what the correct sequence is

Manual fallback activationWhether staff can function using manual procedures while systems are restored — and for how long

RTO reality checkWhether your documented recovery time objectives are achievable given actual restoration speed

Vendor coordinationHardware replacement, insurance assessment, and facility repair — who coordinates, who has authority

Staff managementWhether to send staff home, have them work manually, or implement a modified operation — and who decides

Customer & supplier communicationWho communicates the outage, what they say, and what commitments can be made about restoration time

Frameworks:
NIST SP 800-61
ISO 22301
NIST SP 800-34
SANS IR Framework
Programme & deliverables

What you receive from every exercise.

Each scenario exercise produces a structured package of deliverables that documents what was tested, what was found, and what your organization needs to do to close identified gaps.

Pre-exercise briefing packageScenario overview, participant roles, objectives, and rules of engagement — distributed 48 hours in advance

Facilitated exercise sessionLexcom-led tabletop with structured inject timeline and real-time observation of team decisions

After-action reportDetailed findings document covering what was tested, gaps identified, and prioritized recommendations — delivered within 5 business days

Gap remediation planActionable list of plan updates, control improvements, and training needs with suggested owners and timelines

Insurance & audit evidence packageDocumentation confirming the exercise was conducted, who participated, and what was assessed — formatted for insurers and auditors

Updated IR plan sectionsSpecific plan updates recommended based on exercise findings, ready for your review and adoption

Recommended annual programme
Q1
Ransomware scenario — typically the highest-probability critical threat
Q2
Business email compromise or data breach — the two most common P2 scenarios
Q3
Industry-specific scenario — chosen based on your sector's current threat landscape
Q4
Infrastructure failure or insider threat — tests the non-cyber response capability
Why Lexcom

What makes our scenario exercises different.

Industry-specific scenarios. Exercises are not generic templates — they are built around the threat landscape, regulatory obligations, and operational reality of your specific industry and environment.

Realistic, escalating injects. Lexcom's facilitators introduce unexpected developments that force decision-making under uncertainty — the actual condition of a real incident.

Findings that drive action. Our after-action reports are specific and actionable — not a list of generic observations. Every finding has a named recommendation and suggested owner.

Integration with your IR plan. For Lexcom IR planning clients, exercise findings feed directly into plan updates — the exercise and the plan evolve together.

Insurer and auditor ready. Exercise documentation is formatted to satisfy cyber insurance renewal requirements and regulatory audit inquiries without additional preparation.

30 years managing real incidents. Our facilitators have managed real security incidents across regulated industries — their observations during exercises reflect what actually happens, not textbook theory.

Next Steps

How to get started.

Exercises can be purchased individually or as an annual programme. We recommend starting with the scenario most relevant to your current risk profile — for most organizations, that is ransomware. A separate scope and investment summary for [Organization Name] outlines the proposed exercise schedule, participant requirements, and investment.

Note: If your organization does not yet have a documented incident response plan, Lexcom recommends completing IR plan development before the first tabletop exercise — so the exercise can actually test the plan. Contact your account executive to discuss the right sequence.

Your account executive
[Name]
[Title] · Lexcom Systems Group
[Email]
Lexcom Systems Group
877‑539‑2663
lexcom.com  ·  lexcom.ca