Most organizations have an incident response plan. Most have never run it — not in a tabletop, not in a simulation, not under any condition resembling real adversarial pressure.
A plan that has never been tested is not a capability. It is a document. And when IBM's 2026 Cost of a Data Breach Report puts the global average at 247 days to identify and contain a breach — a record $4.99 million per incident, the organizations inside that window are not organizations without plans. They are organizations whose plans did not work.
NIST SP 800-61 provides the framework. What follows is what each phase requires in practice, where most plans quietly fail, and what a tested IR capability looks like.
Two NIST documents answer that question, and each does different work. NIST SP 800-61 is the foundational reference for IR program structure. NIST CSF 2.0 added the "Govern" function on top of it, making IR a board-level accountability issue rather than an IT-only one. Together, both are tool-agnostic: they define phases and outcomes, not a technology stack. That combination — structural reference plus board-level accountability — is why NIST anchors this plan rather than a vendor framework.
Good preparation means a documented plan with real role ownership, pre-authorized tools, a current asset inventory, and defined escalation thresholds. The gaps are almost always the same two things. First, asset inventories that were accurate at the last audit and stale by the next incident — a server decommissioned in March, a new SaaS integration added in June, neither one reflected in what the response team is working from. Second, role ownership that stops at job titles. Naming a CISO as accountable isn't ownership. Knowing which analyst calls which executive at 2 a.m. is. In healthcare environments, where clinical device networks often have limited logging visibility and asset inventories change with every equipment procurement cycle, both gaps compound before the first attacker arrives.
Preparation also means running the plan before an incident forces you to. Tabletop exercises, structured simulations under realistic scenario conditions, test whether the right people make the right decisions under pressure. Plans get written and filed. Very few are ever run.
One compliance note: the SEC now requires material incident disclosure within four business days of determining materiality. That clock runs regardless of whether your IR plan is ready. See New SEC Regulations Regarding Data Breaches.
This is the most underappreciated failure point in IR planning. Most plans are written as if the security information and event management (SIEM) system will alert, the analyst will triage, and escalation will follow. What most plans do not address is the scenario where detection never fires — where a threat actor moves through the environment for weeks without triggering a meaningful alert. In that scenario, the cyber security controls your IR plan depends on are irrelevant. The plan never gets invoked.
The CrowdStrike 2026 Global Threat Report puts this in sharp relief: the average eCrime breakout time fell to 29 minutes in 2025 — a 65% year-over-year increase in speed. Critically, 82% of 2025 detections were malware-free. Adversaries moved through valid credentials, trusted identity flows, and approved SaaS integrations. There was nothing for the tools to flag. Lateral movement is the primary mechanism: threat actors pivot from system to system while remaining under the detection threshold.
NIST treats these as sequential phases, each with a distinct failure mode. Containment has two modes organizations routinely conflate: short-term isolation (stop the spread now) and long-term containment while full remediation is prepared. Underspecifying the latter means teams isolate and then improvise.
Eradication and remediation are not the same thing. Eradication removes the attacker's foothold — the compromised account, the implanted tool, the lateral access path. Remediation patches the vulnerability they used to enter. Skipping eradication leaves the attacker's access intact. It sets up exactly the post-inoculation attack vectors that turn a contained incident into a second breach.
Recovery requires validation before systems return to production, not just that they are back online, but that the threat is gone and the conditions that enabled the incident have been closed.
Post-incident review is the phase most organizations skip — and the one that determines whether the next incident goes the same way. It produces a documented gap analysis between how the plan was designed to perform and how it actually performed. That gap list feeds the next security program cycle and gives a CISO the financial case to justify budget changes upward. Mean time to respond (MTTR) is the board-level metric that connects IR plan quality to financial outcomes.
Two validation mechanisms exist. They test different things.
Tabletop exercises test whether the right people make the right decisions under scenario pressure. They validate coordination and communication. They do not test whether detection would fire.
Penetration testing tests the detection layer itself: whether the attack paths your IR plan is designed to catch would actually surface in your environment, or whether a threat actor could move through undetected without the IR process ever engaging.
This is the specific gap The Global Ghost Team™ surfaces. The team maintains a 100% successful track record in penetrating the security of every system it has been engaged to test. A consistent finding in those engagements is that the IR plan existed but never fired. Initial access, lateral movement, and data exfiltration occurred without generating a meaningful alert from the client's cybersecurity stack. Adversarial testing is what reveals that gap before an actual attacker does. It is also what a red team engagement is specifically designed to surface.
A plan that has been through both a tabletop exercise and an adversarial penetration test has a fundamentally different status than one that has only been written. It has been run. It has produced gaps. Those gaps have been addressed. That is the standard.
Not sure where your IR program stands? Take the Pentesting Readiness Quiz to assess your current posture. When you're ready to pressure-test what you find, request a consultation — the right engagement depends on where your environment and your IR plan actually stand.