{"id":17717,"date":"2026-06-10T11:54:06","date_gmt":"2026-06-10T11:54:06","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17717"},"modified":"2026-06-15T08:16:36","modified_gmt":"2026-06-15T08:16:36","slug":"the-emergency-plan-that-nobody-practiced","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/the-emergency-plan-that-nobody-practiced\/","title":{"rendered":"The emergency plan that nobody practiced."},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">7 min read<\/p>\n<p><strong>Many companies have an incident response plan. Few have ever tested it under pressure. That difference is decisive in an emergency: organizations that regularly test their plan and have a well-rehearsed team incur significantly lower damage costs, according to IBM, than those whose plan sits untouched in a folder. The plan is the theory-tabletop exercises are the dress rehearsal.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">An untested plan is just an assumption.<\/strong> A document that\u2019s never been put through its paces under time pressure describes a best-case scenario. Without practice, the first gap only appears during a real incident.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Tabletop exercises expose costly gaps.<\/strong> Unclear decision-making authority, missing escalation paths, and uncertainty over who speaks to authorities or the press can waste hours in a crisis. In a drill, they take minutes to resolve.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Practice reduces damage costs.<\/strong> IBM reports that organizations with a tested plan and a well-coordinated team face significantly lower breach costs. The exercise is one of the most cost-effective security investments available.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/security-awareness-the-click-rate-measures-the-wrong-thing\/\" style=\"color:#333;text-decoration:underline;\">Security Awareness: Why Click Rates Measure the Wrong Thing<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/\" style=\"color:#333;text-decoration:underline;\">Backup Against Ransomware: 3-2-1-1-0 Over 3-2-1<\/a><\/p>\n<p><strong>What is a tabletop exercise?<\/strong> A tabletop exercise is a moderated dry run where the crisis team walks through a realistic attack scenario-without touching live systems. Participants make decisions under time pressure, uncover gaps in the incident response plan, and practice collaboration before a real crisis forces their hand.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The Plan in the Folder Meets 3:40 AM<\/h2>\n<p>An incident response plan looks flawless on paper. Roles are assigned, steps are numbered, contact lists are up to date. Then the phone rings at 3:40 AM-half the contact list is on vacation, and no one knows whether the on-call staffer or the CISO has the authority to shut down production. That\u2019s when you find out if the plan is a tool or just a security blanket.<\/p>\n<p>The gap rarely lies in the document itself, but in the assumptions about how people act under stress. A plan assumes clear heads, available contacts, and unambiguous responsibilities. A real crisis delivers the opposite. An exercise bridges that gap by creating the friction the document ignores.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the Exercise Really Reveals<\/h2>\n<p>The most valuable insights from a tabletop exercise aren\u2019t found in any plan. Who can halt production without waiting through three escalation levels? Who speaks to the regulator, who addresses the press-and who keeps the two apart? At what point does an IT incident become a board-level issue? These questions are resolved in minutes during a drill, but in a real incident, they cost hours-hours during which the damage continues to spread.<\/p>\n<p>A well-run exercise also brings the right people together-people who would otherwise never meet: IT security, legal, communications, HR, and senior management. In a real crisis, these functions must collaborate within minutes. If they coordinate for the first time during the exercise, that\u2019s a major win-long before an attacker ever breaches the network.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\" class=\"evm-stat-highlight\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">24 hrs.<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">Under NIS2, affected organizations have just 24 hours after becoming aware of a significant incident to submit their initial report to the BSI. Those who spend this window clarifying roles and reporting procedures usually miss the deadline.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: NIS2 Implementation, BSI Reporting Requirements<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The Gaps That Keep Appearing<\/h2>\n<p>Across countless exercises, the same weaknesses resurface. First, decision-making authority: no one dares to make the costly call alone, so it gets passed up the chain-wasting time. Second, external communications, which under NIS2 are bound by strict deadlines yet often remain unresolved. Third, reliance on key individuals whose knowledge no one else possesses.<\/p>\n<p>Then there\u2019s the recovery interface. A crisis team can communicate flawlessly and still fail if the <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/\">backup was never tested for an actual restore<\/a>. That\u2019s why tabletop exercises and restore tests go hand in hand: one tests decisions, the other tests whether the technology can even support them. <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/security-awareness-the-click-rate-measures-the-wrong-thing\/\">Internal reporting channels<\/a> should also be part of the same playbook.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The DACH Factor: NIS2 Tightens the Clock<\/h2>\n<p>In Germany, crisis communication is governed by a hard deadline. NIS2 requires affected organizations to submit an initial report to the BSI within 24 hours of becoming aware of a significant incident, followed by a detailed report within 72 hours. Those who spend this window figuring out who\u2019s authorized to report-and what information to include-usually miss the deadline. A tabletop exercise with a built-in reporting clock makes these 24 hours tangible.<\/p>\n<p>Then there\u2019s the crisis team as a formal body. In many DACH organizations, it exists on paper but has never actually convened. Works councils come into play as soon as personal data or employment law implications arise. Bringing these stakeholders together for the first time during a real incident wastes time the reporting deadline won\u2019t allow.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">How to Run Your First Exercise Within the Next 90 Days<\/h2>\n<p>Getting started doesn\u2019t require an expensive simulation environment. A realistic scenario-like a ransomware infection with encrypted production systems-a facilitator, and two hours with the right functions in the room are enough: IT security, legal, communications, HR, and a member of senior management. The scenario is escalated step by step, every decision is made aloud and documented. The outcome isn\u2019t a grade but a list of gaps the plan didn\u2019t cover. That list is the real result. Address it, refine it in two to three exercises per year, and the plan in the binder becomes a capability that holds up in a real crisis.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>How often should an incident response plan be tested?<\/h3>\n<p>A good rule of thumb is two to three times per year, with additional sessions after major changes to systems, organization, or regulations. More important than frequency is ensuring each exercise ends with a list of gaps-and that this list is addressed before the next one. That turns testing into a cycle of improvement rather than a box-ticking exercise.<\/p>\n<h3>How Does a Tabletop Exercise Differ from a Real Penetration Test?<\/h3>\n<p>A tabletop exercise tests decisions, roles, and communication at the table-without touching any systems. A penetration test, on the other hand, examines the technical vulnerabilities of the systems themselves. The two complement each other: the pentest reveals how an attacker gains access, while the tabletop exercise shows whether the organization can manage the incident afterward.<\/p>\n<h3>Who Should Participate in a Tabletop Exercise?<\/h3>\n<p>More than just IT. Alongside IT security, legal, corporate communications, HR, and a member of senior management should be at the table. These are precisely the interfaces where costly delays occur in an emergency-and this collaboration can only be practiced together.<\/p>\n<h3>What Role Does NIS2 Play in Incident Response Exercises?<\/h3>\n<p>NIS2 requires affected organizations to report a significant incident to the BSI within 24 hours of becoming aware of it. An exercise with a built-in reporting clock ensures that, in a real crisis, it\u2019s clear who reports, what is reported, and when the clock starts ticking.<\/p>\n<h3>What Is the Most Important Outcome of an Exercise?<\/h3>\n<p>The list of uncovered gaps. A good feeling isn\u2019t preparation. An exercise that finds no weaknesses was likely too easy. The real value emerges only when those gaps are closed afterward-and the next exercise tackles a tougher scenario.<\/p>\n<p style=\"margin:40px 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#004a59;\">Editor\u2019s Picks<\/p>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/10\/security-awareness-the-click-rate-measures-the-wrong-thing\/\">Security Awareness: Why Click Rates Measure the Wrong Thing<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/\">Backups Against Ransomware: 3-2-1-1-0 Instead of 3-2-1<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/\">Zero Trust for Energy Providers: What NIS2 Audits Demand Now<\/a><\/li>\n<\/ul>\n<p style=\"margin:40px 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/06\/10\/cloud-repatriation-wann-rueckholen-rechnet\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Cloud Repatriation: When Bringing Workloads Back Pays Off<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/build-buy-partner-entscheidung-framework\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Build, Buy, or Partner: The Calculation Behind the Decision<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/lieferkettenangriff-software-mittelstand-nis2\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">When the Update Itself Becomes the Entry Point<\/a>\n<\/div>\n<p style=\"font-size:.8em;color:#888;margin-top:1.5em;\">Cover image: AI-generated (June 2026)<\/p>\n<p style=\"text-align:right;color:#868e96;font-size:0.85em;margin-top:48px;font-style:italic;\"><em>Image source: AI-generated (June 2026), C2PA certificate embedded in image<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Almost everyone has an incident response plan, but hardly anyone practices it. According to IBM, tested plans reduce breach costs by 58%.","protected":false},"author":10,"featured_media":17726,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Incident-Response-Plan (English) can be translated as \"Incident Response Plan.\" This term refers to a strategic approach to identifying, classifying, and responding to security incidents. It includes procedures for handling events like cyber attacks, data breaches, and other threats to an organization's information security.","_yoast_wpseo_title":"The emergency plan that nobody practiced.","_yoast_wpseo_metadesc":"\"Almost everyone has an incident response plan, but few practice them. Tested plans can reduce breach costs by 58%, says IBM.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3],"tags":[],"class_list":["post-17717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":16552,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17717"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17717\/revisions"}],"predecessor-version":[{"id":17718,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17717\/revisions\/17718"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17726"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}