Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Cyber Security

Incident Response Plan Services and Tabletop Exercises

A written plan your leaders have actually practiced, a facilitated tabletop that finds the gaps, and a responder on retainer for the day it is real.

Veteran-LedSDVOSB
NIST SP 800-61r3Aligned Plans
Chain of CustodyEvery Incident
AZ DPS PI LicenseNo. 1759795
NationwideRemote Delivery

When you need incident response plan services

Incident response plan services give your team a written plan, practice using it, and a responder ready when something goes wrong. Honeybadger Solutions provides this work as part of our managed cyber security services, and the same team handles live cyber incident response when a real incident hits.

The hardest hour of a ransomware attack or a wire fraud is the first one. People argue about who decides, whether to call the insurer, whether to shut systems down, and where the contact list is, often while that list sits on an encrypted server. A short plan that has been tested in a tabletop exercise turns that hour into a checklist.

Common reasons clients ask us for this work:

  • A cyber insurance application or renewal asks whether you have a tested incident response plan.
  • A client contract, a regulator or a framework such as CMMC, HIPAA or PCI DSS expects one.
  • You had a near miss, such as a phishing click or a fake invoice, and realized nobody knew the steps.
  • Your old plan was written years ago and names people who have left.

What changed with NIST SP 800-61 Revision 3?

In April 2025 NIST published SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management. It replaced Rev. 2 from 2012 and recasts incident response as a Community Profile of the NIST Cybersecurity Framework 2.0. In plain terms, incident response is no longer a separate binder; it touches all six CSF functions: Govern, Identify, Protect, Detect, Respond and Recover.

CSF 2.0 itself says incident response plans should be established, communicated, maintained and improved (ID.IM-04), and that improvements should come from security tests and exercises (ID.IM-02). A plan that has never been exercised does not meet that outcome.

What is a tabletop exercise?

A tabletop exercise is a guided discussion. Leaders and staff sit with a realistic scenario that unfolds in stages and talk through what they would do, who decides, and what they would need. Nobody touches live systems. CISA publishes more than 100 free Tabletop Exercise Packages with scenarios, discussion questions and an after-action report template, and FEMA’s Homeland Security Exercise and Evaluation Program (HSEEP, 2020 revision) sets out how to turn findings into specific, measurable corrective actions. We use those formats and tailor the scenario to your business.

Plan section The question it answers
Roles and decision authority Who declares an incident, who can approve shutting systems down, and who speaks for the company?
Contact sheet kept offline How do we reach the insurer, breach counsel, the bank, IT, key vendors and law enforcement if email is down?
Severity levels Is this a nuisance, a contained event or a full incident, and who is told at each level?
Evidence preservation What must not be wiped, rebooted or reimaged before it is copied?
Notification decisions Who decides, with counsel, whether a breach notice is required and by when?
Recovery criteria What has to be true before systems go back online?

For example, Arizona’s breach statute, A.R.S. 18-552, requires a prompt investigation once you become aware of a security incident and, if a breach is confirmed, notice to affected people within 45 days; a breach needing notice to more than 1,000 people also requires notice to the three largest consumer reporting agencies, the Attorney General and the director of the Arizona Department of Homeland Security. A good plan puts those clocks in front of the decision makers.

What we deliver

These services build on each other, and each can be bought separately.

Incident plan and tabletop

A fixed project with a capped number of consultant hours: a written plan sized for your organization, a response contact sheet, one facilitated tabletop scenario, and written findings with corrective actions.

IR readiness retainer

A yearly agreement with a block of prepaid incident response hours you can use any time of day. If the block runs out, more hours are billed at a stated rate. Unused hours expire each year.

Using unused retainer hours

Retainer hours that are not needed for incidents can fund readiness work during the year, such as a second tabletop, plan updates or a configuration review.

Emergency incident response

Billed hourly, with a short minimum, when something is happening now: incident command, containment, evidence preservation and root-cause work.

Security baseline assessment

A fixed project for one tenant or site and a set number of endpoints, with prioritized findings and a debrief. It shows which gaps would make an incident worse.

Framework gap assessment

A fixed project against one framework, such as NIST CSF 2.0 or CMMC, for a defined environment. You get a gap register and a roadmap. It does not include certification.

How incident response plan services run

  1. Request online. Tell us your size, your main systems, your insurer and any framework you answer to.
  2. Kickoff. We meet leadership and IT, review any existing plan and your cyber policy’s incident clauses, and choose a scenario such as ransomware, business email compromise, a lost laptop or an insider.
  3. Draft the plan. We write a short plan with roles, decision points, the contact sheet and evidence steps, then review it with you.
  4. Run the tabletop. A facilitated session, usually a few hours, walks leaders and staff through the scenario in stages with new developments at each step.
  5. Findings. After the session you receive an after-action report listing what worked, what broke and specific corrective actions with owners and dates.
  6. Update and repeat. We fold the findings into the plan. We suggest a new exercise at least once a year and after major changes such as a merger or a new core system.

Authority, consent and legal limits

The plan belongs to you, and so do the decisions in it. Whether a breach notice is legally required, and how communications stay privileged, are questions for your counsel; we build the plan so counsel is called early. Many cyber policies require you to notify the insurer quickly and to use approved vendors, so check your policy before an incident and put the claim contact on the first page.

During a real incident we act only on systems you own or administer, with written authorization from someone who can give it. We do not hack back, we do not access attacker infrastructure, and decisions about ransom payment rest with you, your counsel and your insurer. We preserve evidence so law enforcement can be involved; we suggest reporting cyber crime to the FBI’s IC3. This is general information, not legal advice.

How it is priced

Our incident response plan services are priced in words here and in numbers on your written quote. The plan and tabletop is a fixed package per project with a stated block of consultant hours and one scenario; extra scenarios or sessions are added by written change order. The IR readiness retainer is a yearly fee that prepays a block of incident hours at a lower hourly rate, with a stated rate after the block is used. Emergency response without a retainer is billed hourly with a short minimum. The baseline and framework assessments are fixed projects with stated hours and a defined environment.

The main cost drivers are the size of the group in the exercise, how many locations and systems the plan covers, and whether you want more than one scenario a year.

Included Quoted separately
Written plan, contact sheet and one facilitated scenario Additional scenarios, sessions or locations
After-action findings with corrective actions Carrying out the technical fixes
Prepaid incident hours under a retainer Hours beyond the retainer block
Gap register and roadmap for one framework Certification audits or assessor fees

Mistakes to avoid before you contact us

  • A plan nobody has read. If leaders see it for the first time during an incident, it will not be used.
  • Contacts stored only on the network. Ransomware can lock the very server that holds the call list. Keep a copy offline.
  • No backup way to talk. If email and chat are compromised, attackers may be reading them. Decide on an alternate channel in advance.
  • Hiring help before calling the insurer. Some policies limit coverage when you skip their process.
  • Wiping machines too fast. Rebuilding before evidence is copied can destroy the record you need for the claim, the root cause and any notice decision.
  • Exercising only IT. The hardest decisions in an incident are business decisions. Executives, finance and HR belong at the table.

Who this is for

  • Small and mid-sized businesses
  • Medical and dental practices
  • Law and accounting firms
  • Defense contractors and suppliers
  • Nonprofits, schools and local governments
  • Boards and owners asked about cyber readiness

Why the online request is faster

Choose incident planning on the online request form and it goes straight to the cyber and forensics lead who runs these engagements. You share your size, systems and insurer once, and there is no phone tag.

Frequently asked questions

How often should we run a tabletop exercise?

We suggest at least once a year and after big changes such as a new core system, a merger or turnover in leadership. NIST CSF 2.0 expects plans to be maintained and improved using lessons from exercises.

What is the difference between an incident response plan and an IR retainer?

The plan is your playbook. The retainer is a contract that prepays responder hours so help starts quickly, without negotiating terms in the middle of a crisis. Most organizations benefit from both.

Who should attend the tabletop?

Decision makers: the owner or executive team, finance, HR, IT, communications and, where possible, counsel. Technical staff alone cannot answer the business questions a real incident raises.

Will a tabletop satisfy our cyber insurance requirement?

It depends on your policy wording. Many applications ask whether you have a plan and whether it has been tested. We give you a dated after-action report you can show your broker.

Are CISA’s free tabletop packages enough on their own?

They are a good starting point and we use their formats. Most organizations get more from a facilitator who tailors the scenario, keeps the discussion moving and writes up corrective actions.

Is NIST SP 800-61 Rev. 3 mandatory for private businesses?

No. It is federal guidance, published in April 2025, that many insurers, auditors and frameworks treat as the reference point. We use it to structure your plan.

What happens if we have an incident before the plan is finished?

Use our urgent intake form. We switch to emergency incident response, and the work feeds back into your plan afterward.

Related guides

We act on systems only with written authorization from someone who can give it. Notification and privilege decisions belong to your counsel.

Sources: NIST SP 800-61 Rev. 3, NIST CSF 2.0, CISA Tabletop Exercise Packages, FEMA HSEEP, A.R.S. 18-552.

Practice the hard hour before it happens

Request this service online and our cyber lead will scope your plan and exercise. Picking the service on the form routes it straight to the right specialist, so there is no phone tag. If an incident is happening now, use our urgent intake form.