Prepared for [Organization Name] — a structured program of tabletop exercises and scenario simulations that tests your team's real response capability before an actual incident forces the test.
Most organizations that have incident response plans have never tested them. Plans are written, reviewed, filed — and then activated for the first time under the worst possible conditions: during a real incident, with real consequences, while everyone is already under pressure. The gaps surface at exactly the wrong moment.
Lexcom's incident response testing program addresses this by running structured scenario exercises before an incident occurs. Each exercise is built around a realistic threat scenario specific to your industry and environment, involves the actual people who would respond to a real incident, and produces a detailed after-action report with specific, actionable findings.
The goal is not to produce a passing grade. The goal is to find the gaps — in your plan, in your team's decision-making, in your communication procedures, and in your technical recovery capability — while there is still time to close them.
Each scenario exercise follows a consistent five-phase structure. Exercises are conducted in a controlled environment — no live systems are affected — but participants are expected to make real decisions and engage with the scenario as they would in an actual incident.
Initial detection & escalationWho gets called first, in what order, and how quickly — and whether the right people are reachable
Containment decision-makingWhether to isolate systems immediately or investigate first — and who has authority to decide
Backup integrity assessmentWhether your backups are clean, how long recovery takes, and whether RTOs are realistic
Pay vs restore decision processWho makes the ransom payment decision, under what criteria, and what the insurer notification requirement is
External communicationCustomer, supplier, and regulator notification — who drafts it, who approves it, when it goes out
Business continuity activationWhether manual fallback procedures exist and are actually usable without primary systems
Lexcom's facilitator introduces escalating developments during the exercise to test decision-making under uncertainty:
Email forensics capabilityCan your team determine how long the attacker had access and what was read or exfiltrated?
Wire transfer recall procedureWho contacts the bank, within what timeframe, and what the realistic recovery probability is
Scope assessmentHow to determine whether other accounts or systems were compromised beyond the initial account
Regulatory notificationWhether this constitutes a reportable data breach under PIPEDA and what the timeline obligation is
Insurance claim processWhat your cyber insurance covers for financial loss from BEC and what documentation is required
Control gap identificationWhat MFA, approval workflow, or vendor confirmation controls would have prevented the incident
Breach validation processHow to confirm whether the data is real, from your systems, and what the actual scope is
PIPEDA notification obligations72-hour OPC notification requirement — who files it, what must be included, what constitutes "real risk of significant harm"
Individual notification processWho are the affected individuals, how are they notified, in what timeframe, and by what channel
Media responseWhether to proactively disclose, how to respond to press inquiries, and who is the authorized spokesperson
Legal exposure assessmentClass action risk, regulatory investigation preparation, and evidence preservation requirements
Forensic investigationHow to determine the attack vector, dwell time, and full scope without destroying evidence
Evidence preservationHow to collect and preserve forensic evidence in a way that supports potential legal action
Legal response optionsCease and desist, injunctive relief, and civil/criminal options — and who makes the decision to pursue
Offboarding gap analysisWhat access the employee retained after departure that should have been revoked immediately
Data exposure assessmentWhether taken data constitutes a reportable breach or trade secret theft
Competitor notificationWhether to contact the competitor directly, and what the legal implications are
Control gap remediationWhat DLP, access review, and offboarding controls would have prevented or detected this earlier
Vendor access inventoryWhether you know what access the vendor has, to which systems, and how to revoke it immediately
Compromise indicatorsHow to determine whether your environment was accessed via the vendor's compromised credentials
Vendor relationship managementWhether to suspend vendor access while investigating, and the contractual and operational implications of doing so
Breach notification obligationsWhether a vendor compromise that may have exposed your data triggers your own notification obligations
Vendor risk program gapsWhat vendor security assessment, access controls, and contractual requirements would have reduced exposure
Alternative vendor readinessWhether you can operate without this vendor while the incident is investigated and resolved
Compromised account identificationHow to rapidly identify all potentially compromised accounts and their system access scope
Mass credential reset processSpeed and completeness of credential reset across all affected accounts without disrupting operations
MFA emergency enforcementWhether you can rapidly enable MFA for all accounts and what the operational impact is
Session revocationWhether active attacker sessions can be terminated and how to confirm the attacker no longer has access
Activity auditWhat the attacker accessed, read, or exfiltrated during the access window
Staff communicationHow to notify affected staff, what they need to do, and how to prevent panic or further phishing response
Restoration sequencingIn what order systems are restored — which dependencies exist and what the correct sequence is
Manual fallback activationWhether staff can function using manual procedures while systems are restored — and for how long
RTO reality checkWhether your documented recovery time objectives are achievable given actual restoration speed
Vendor coordinationHardware replacement, insurance assessment, and facility repair — who coordinates, who has authority
Staff managementWhether to send staff home, have them work manually, or implement a modified operation — and who decides
Customer & supplier communicationWho communicates the outage, what they say, and what commitments can be made about restoration time
Each scenario exercise produces a structured package of deliverables that documents what was tested, what was found, and what your organization needs to do to close identified gaps.
Pre-exercise briefing packageScenario overview, participant roles, objectives, and rules of engagement — distributed 48 hours in advance
Facilitated exercise sessionLexcom-led tabletop with structured inject timeline and real-time observation of team decisions
After-action reportDetailed findings document covering what was tested, gaps identified, and prioritized recommendations — delivered within 5 business days
Gap remediation planActionable list of plan updates, control improvements, and training needs with suggested owners and timelines
Insurance & audit evidence packageDocumentation confirming the exercise was conducted, who participated, and what was assessed — formatted for insurers and auditors
Updated IR plan sectionsSpecific plan updates recommended based on exercise findings, ready for your review and adoption
Industry-specific scenarios. Exercises are not generic templates — they are built around the threat landscape, regulatory obligations, and operational reality of your specific industry and environment.
Realistic, escalating injects. Lexcom's facilitators introduce unexpected developments that force decision-making under uncertainty — the actual condition of a real incident.
Findings that drive action. Our after-action reports are specific and actionable — not a list of generic observations. Every finding has a named recommendation and suggested owner.
Integration with your IR plan. For Lexcom IR planning clients, exercise findings feed directly into plan updates — the exercise and the plan evolve together.
Insurer and auditor ready. Exercise documentation is formatted to satisfy cyber insurance renewal requirements and regulatory audit inquiries without additional preparation.
30 years managing real incidents. Our facilitators have managed real security incidents across regulated industries — their observations during exercises reflect what actually happens, not textbook theory.
Exercises can be purchased individually or as an annual programme. We recommend starting with the scenario most relevant to your current risk profile — for most organizations, that is ransomware. A separate scope and investment summary for [Organization Name] outlines the proposed exercise schedule, participant requirements, and investment.
Note: If your organization does not yet have a documented incident response plan, Lexcom recommends completing IR plan development before the first tabletop exercise — so the exercise can actually test the plan. Contact your account executive to discuss the right sequence.