Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Incident Response Plan and Tabletop Exercise Guide (2026)

Leadership team reviewing an incident response plan during a tabletop exercise in an Arizona office

An incident response plan is the document your team reaches for when a ransomware note appears or a mailbox gets taken over. A good one says who is in charge, who decides what, who gets contacted, and what must be preserved. A plan nobody has practiced usually fails in the first hour.

This guide covers how to build an incident response plan on the current federal model, NIST SP 800-61 Rev. 3, and how to test it with a tabletop exercise using the publicly available CISA Tabletop Exercise Packages. It is written for owners, IT managers, and compliance leads at small and mid-sized organizations. If you want practitioners to build or test it with you, Honeybadger provides cyber incident response services on retainer and on demand.

This article focuses on planning and practice. If you are deciding how to buy outside help, see our comparison of an incident response retainer vs on-demand response.

Key takeaways

  • NIST SP 800-61 Rev. 3 (April 2025) replaced the old four-phase cycle with a model built on the six CSF 2.0 Functions.
  • A usable plan names roles and decision authority, a contact tree, severity levels, evidence rules, notification duties, and a communications plan.
  • Notice clocks differ: Arizona allows 45 days, the FTC Safeguards Rule 30 days, HIPAA 60 days, and SEC Form 8-K four business days after a materiality determination.
  • CISA publishes more than 100 Tabletop Exercise Packages with scenarios, handbooks, and an after-action report template.
  • CISA’s performance goals call for drilling the plan at least annually, and NIST SP 800-84 adds re-exercising after major changes.

Where this guidance comes from. This guide draws on NIST SP 800-61 Rev. 3 (April 2025), NIST SP 800-84 on test, training, and exercise programs (2006), CISA’s Tabletop Exercise Package materials, the CISA #StopRansomware Guide (September 2023), CISA’s Cross-Sector Cybersecurity Performance Goals, and the notification rules cited below. It also reflects what our veteran-led team sees when organizations open their plans during real incidents and find gaps a two-hour exercise would have caught.

What changed in NIST SP 800-61 Rev. 3

For more than a decade, most plans followed the four phases in NIST SP 800-61 Rev. 2 (2012): preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. In April 2025, NIST replaced it with Rev. 3, written as a Community Profile of the Cybersecurity Framework (CSF) 2.0. If you want help building or testing a plan, our incident response plan services include tabletop exercises, and you can request them online.

NIST explains why. When Rev. 2 was written, incidents were relatively rare and recovery usually finished within a day or two. Today, NIST notes, incidents are frequent and recovery often takes weeks or months. Rev. 3 organizes response around the six CSF 2.0 Functions:

  • Govern, Identify, Protect: preparation work such as policy, risk understanding, and safeguards.
  • Detect, Respond, Recover: the response itself, from analysis and containment to notification and restoration.
  • Improvement: lessons from every Function feed back in continuously, not only after recovery ends.

For a small organization, the takeaway is simple: connect the plan to your policies, backups, vendors, and business continuity plan, and update it whenever you learn something, including from an exercise.

Incident response plan components: the checklist

Rev. 3 lists the core policy elements: management commitment, purpose and scope, definitions, roles and authorities, severity and prioritization guidelines, and performance measures. This table turns those elements and the CISA guidance into a working checklist.

ComponentWhat it must answerBasis
Scope and definitionsWhat counts as an incident, and which systems, sites, and data are coveredNIST SP 800-61r3, Sec. 2.3
Roles and decision authorityWho leads, and who can disconnect, shut down, or rebuild systemsNIST SP 800-61r3, Sec. 2.2-2.3
Contact treeNames, backups, and off-network contacts for leadership, IT, counsel, insurer, vendorsCISA #StopRansomware Guide
Severity levelsHow incidents are categorized, prioritized, and escalatedNIST SP 800-61r3, RS.MA-03/04
Evidence preservationWhat to capture, how actions are logged, who controls recordsNIST SP 800-61r3, RS.AN-06/07
Legal, insurer, regulator noticeWho decides on notice, which laws and contracts apply, deadlinesNIST SP 800-61r3, RS.CO-02
CommunicationsWho speaks to staff, customers, and media, and through which channelsNIST SP 800-61r3, Sec. 2.2
Third partiesWhat your MSP, cloud, and software vendors will do, and their authority to actNIST SP 800-61r3, GV.SC-08
Recovery and closureWhen recovery starts, when the incident ends, who writes the after-action reportNIST SP 800-61r3, RC.RP-06
Approval and testingWho signs it, where offline copies live, when it is exercisedCISA guide; CPG 2.S

Roles and decision authority

NIST lists the people who typically take part: leadership, incident handlers, technology staff, legal, public affairs, HR, facilities, and the owners of affected systems. Rev. 3 also suggests naming an incident lead for each incident.

The hard part is authority. Write down who can take a revenue system offline, who approves outside responders, and who signs off on ransom-related decisions. Name a backup for every role.

Contact tree and out-of-band communications

The CISA #StopRansomware Guide (September 2023) says to keep a hard copy and an offline version of the plan. If email and file servers are encrypted or watched by an attacker, a plan stored there does not help.

List personal mobile contacts for key staff, outside counsel, your insurer’s claim reporting channel, your IT provider, and your response firm. Agree on a fallback channel for when company systems cannot be trusted.

Severity levels

Rev. 3 recommends categorizing incidents by type (data breach, ransomware, account takeover, denial of service) and prioritizing by scope, likely impact, time sensitivity, and available resources.

For example, a three-level scheme might use Low for a single contained event handled by IT, High for a confirmed account or system compromise with leadership briefed the same day, and Critical when operations stop or regulated data is likely exposed. Tie each level to who gets notified and how fast.

Evidence preservation

NIST notes that formal chain of custody may not happen for every incident, but collected data is still evidence, and actions taken should be recorded with their integrity protected. Write the first-hour rules plainly: isolate rather than wipe, capture before reimaging, save logs before they roll over, and keep a timestamped log. Our guide to the first 24 hours after ransomware walks through that sequence.

Legal, insurer, and regulator notification

Rev. 3 says notifications should follow the laws for your sector and locations, and that law enforcement and regulators should be notified based on criteria in the plan with management approval. As of October 2026, common clocks include:

  • Arizona (A.R.S. 18-552): notify affected individuals within 45 days after determining a breach. Above 1,000 individuals, also notify the three largest consumer reporting agencies, the attorney general, and the director of the Arizona Department of Homeland Security.
  • FTC Safeguards Rule: covered non-banking financial institutions notify the FTC within 30 days of discovering an event involving at least 500 consumers (effective May 13, 2024).
  • HIPAA: notify individuals no later than 60 days after discovery; breaches of 500 or more also go to HHS and, by state, to prominent media.
  • SEC registrants: Form 8-K Item 1.05 is generally due four business days after an incident is determined material.

Also check your cyber policy’s notice terms and any approved-vendor rule, plus customer contracts. Our data breach response guide for small business covers the notice process. This is general information, not legal advice; confirm specifics with counsel.

Communications plan

NIST notes that the media sometimes learns of an incident before your spokesperson does. Decide who may speak, who approves statements, and what staff tell customers. CISA recommends the CEO or equivalent approve the plan and communications plan in writing.

Need a plan built or checked against your environment? We can review what you have, fill the gaps, and test it with your leadership. Submit a service request online with your industry, headcount, and whether a plan exists today.

How to build an incident response plan in six steps

  1. Get an executive owner and set scope. Without a named sponsor, decisions stall mid-incident.
  2. Inventory what matters. Critical systems, regulated data, key vendors, and backups. NIST recommends syncing with your business continuity plan.
  3. Assign roles and authority. Names, backups, and who approves shutdowns, outside help, and notice.
  4. Write short playbooks. Start with ransomware, business email compromise, and lost devices.
  5. Approve, print, and store offline. Get written sign-off and keep copies reachable when the network is down.
  6. Exercise and revise. Run a tabletop, write the after-action report, and update the plan.

What a tabletop exercise is

NIST SP 800-84 defines tabletop exercises as discussion-based events where people with roles in a plan talk through a scenario, led by a facilitator. Nobody touches production systems. The goal is to confirm that documented roles, decisions, and dependencies hold up.

Per SP 800-84, tabletops typically run two to eight hours; senior-level sessions usually take two to four. NIST suggests exercising senior and operational teams separately first, then together.

CISA Tabletop Exercise Packages (CTEPs)

CISA publishes more than 100 customizable Tabletop Exercise Packages, or CTEPs, with template objectives, scenarios, and discussion questions. Cyber scenarios include ransomware, insider threats, phishing, and industrial control system compromise, plus sector-specific versions.

Per CISA’s CTEP fact sheet (November 2021 version), a package includes a planner handbook, a facilitator and evaluator handbook, a situation manual, slide and invitation templates, feedback forms, and an HSEEP-aligned after-action report/improvement plan template. CTEPs are generic, so the value comes from tailoring the scenario to your systems, vendors, and notice duties.

How to run a tabletop exercise, step by step

  1. Set three or four objectives. SP 800-84 says they should validate the plan’s content, roles, and dependencies.
  2. Keep the scenario short. NIST notes long scenarios lead people to debate the story instead of the plan.
  3. Write injects. New facts released mid-session to force a decision, each tied to an objective.
  4. Assign a facilitator and a note taker. CISA’s handbook asks evaluators to record who made each decision and what triggered it.
  5. Plan ahead. NIST suggests at least one month for simple exercises and three for large ones.
  6. Hold a hot wash. Right after, ask what worked, where training is needed, and what in the plan should change.
  7. Write the after-action report. Assign owners and due dates, then update the plan.

Sample tabletop exercise agenda

For example, a three-hour leadership tabletop on a hypothetical ransomware scenario might run like this:

TimeSegmentWhat happens
0:00-0:15Welcome and ground rulesObjectives, no-fault rules, facilitator and note taker roles
0:15-0:25Scenario briefingMonday morning: the help desk reports locked files
0:25-1:05Module 1: Detect and escalateInjects: file shares encrypted; ransom note found. Who declares the incident, and at what severity?
1:05-1:45Module 2: Contain and decideInjects: backups may be affected; attacker claims data theft. Who approves shutdowns, responders, counsel, insurer?
1:45-1:55BreakFacilitator and note taker compare notes
1:55-2:35Module 3: Notify and recoverInjects: a reporter emails; a customer asks about its data. Which notice clocks apply?
2:35-2:55Hot washWhat worked, what was unclear, what the plan is missing
2:55-3:00Next stepsOwner and due date for the after-action report

Writing injects that test real decisions

Good injects create tension. Consider a hypothetical: IT wants to wipe and restore now, but counsel wants evidence preserved first. NIST names this trade-off between investigating thoroughly and returning to operations quickly. Make the room decide, and record who decided. Also ask the team to reach the insurer using only what is printed in the plan.

How often should you test an incident response plan?

CISA’s Cross-Sector Cybersecurity Performance Goals (CPG 2.S) say plans should be drilled at least annually and updated after each exercise’s lessons learned. NIST SP 800-84 notes that NIST SP 800-53 requires federal agencies to test incident response capabilities at least annually.

Treat annual as the floor. SP 800-84 also recommends exercising after organizational changes or plan updates, such as a new IT provider, a cloud migration, a merger, or a near miss. Rotating scenarios each year keeps the exercise honest.

Not sure where your gaps are? The free Ransomware Readiness Scorecard gives a quick baseline before your first exercise.

Do it yourself or bring in a facilitator?

A motivated team can run a useful tabletop with a CTEP. Outside facilitation pays off when leadership needs to be challenged without office politics, when insurers, auditors, or customers expect independent evidence of testing, or when nobody internally has handled a real incident.

How Honeybadger helps with incident response plans and tabletop exercises

Honeybadger Solutions is a veteran-owned SDVOSB based in Casa Grande, Arizona, delivering cyber services nationwide. Our incident response retainer starts by learning your environment, and when an incident happens our responders handle triage, containment, eradication, recovery, and court-ready forensics and reporting.

  • Our vCISO services include an annual incident response tabletop exercise with your leadership team, along with policy review and refresh.
  • Our security workshops and seminars include executive briefings with tabletop discussion, on-site in Arizona or live virtual.
  • Our ransomware recovery service offers readiness assessments, backup reviews, and tabletop facilitation for the payment, notification, and communications decisions leaders face.

Tell us whether you need a plan written, a plan reviewed, or a tabletop run, and roughly how many people should take part. Request incident response planning online, or book a consultation online to talk through scope first.

Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.

Frequently asked questions

What should an incident response plan include?

Scope and definitions, roles and decision authority, an offline contact tree, severity levels, evidence rules, notification duties, a communications plan, third-party responsibilities, recovery and closure criteria, and how the plan is approved and tested.

What is the difference between NIST SP 800-61 Rev. 2 and Rev. 3?

Rev. 2 (2012) used a four-phase life cycle. Rev. 3 (April 2025) is a CSF 2.0 Community Profile organized around Govern, Identify, Protect, Detect, Respond, and Recover, with continuous improvement throughout.

How long does a tabletop exercise take?

NIST SP 800-84 says tabletop exercises typically run two to eight hours, with senior-level sessions usually two to four hours.

Are CISA Tabletop Exercise Packages free?

CISA publishes its Tabletop Exercise Packages on CISA.gov for organizations to use in their own exercises, including scenarios, handbooks, templates, and an after-action report template.

How often should we run a tabletop exercise?

CISA’s performance goals call for drilling incident response plans at least annually. NIST SP 800-84 also recommends exercising after organizational changes or plan updates.

Who should attend a tabletop exercise?

Everyone with a role in the plan: leadership, IT and security, legal, communications, HR, and key system owners, plus your IT provider if it handles response.

Sources and further reading

Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.

Browse by topic

Security guard services  ·  Private investigations  ·  Cybersecurity  ·  Digital forensics  ·  Financial fraud investigation  ·  Executive protection  ·  All articles