📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
SIRI Incident Readiness | Playbooks & Tabletop Exercises — SIRI Law LLP
Cyber Resilience › Incident Readiness

Incident Readiness — the plan tested before you need it, not written the day you do.

An incident response plan that's never been rehearsed behaves differently than expected the first time it's needed for real. SIRI Incident Readiness builds and tabletop-tests your playbooks before an incident — satisfying RBI's half-yearly drill requirement along the way.

Half-yearlyRBI's DR drill requirement
0Cost of finding a gap in a drill vs. in a real incident
DocumentedEvery exercise outcome, board-ready
Why readiness is now a named requirement
Live tracking · scroll to see every relevant change
Effective
31 JUL 2026
RBI's Resilience & Assurance Framework requires half-yearly disaster recovery drills with documented Recovery Time and Recovery Point Objectives.
Baseline
6 HR WINDOW
CERT-In's notification requirement — realistically achievable only with a rehearsed response plan already in place.
Standard
NIST IR LIFECYCLE
Preparation is the first phase of the standard incident response lifecycle — readiness work is what happens in that phase, before detection ever occurs.
Notified
14 NOV 2025
DPDP Rules 2025 — breach-response procedures are part of a complete readiness programme.
Recurring
SEBI CSCRF
SEBI's framework similarly expects demonstrated incident-response capability, not just a written policy, inside its recurring audit cycle.

The gap between written and rehearsed

A plan nobody has run through is a document, not a capability.

Most organisations that have an incident response plan wrote it once — often years ago, often by someone no longer at the company — and have never actually rehearsed it. The people who would execute it during a real incident have never seen it in practice, the escalation contacts may be outdated, and the assumptions baked into it about system architecture may no longer hold.

RBI's 2026 Resilience & Assurance Framework converts this from a best practice into a specific, recurring requirement: half-yearly disaster recovery drills with documented outcomes. CERT-In's incident response expectations similarly assume an organisation has thought through its response before an incident, not during one. A tabletop exercise — walking a response team through a simulated incident scenario — is the standard way to find out whether a plan actually works before finding out the hard way.

Tabletop exercises find the gaps a document review can't
Outdated escalation contacts, unclear decision authority during a crisis, and assumptions about system dependencies that no longer hold — these consistently surface during a rehearsed simulation, not during a read-through of the plan on paper.

SIRI Incident Readiness builds the plan, then tests it under realistic conditions, then documents the outcome — producing both an improved capability and the drill documentation that RBI's framework specifically requires.

What organisations get wrong

Four assumptions readiness testing routinely exposes

These show up almost every time a plan meets an actual simulation.

01 — CONTACTS

“Our escalation list is in the plan document”

Escalation contacts change with staff turnover far more often than incident response plans get updated — a plan reviewed only during drafting frequently has stale contact information by the time it's needed.

02 — AUTHORITY

“Someone will make the call when it happens”

Without a pre-defined decision authority — who can authorise isolating a system, who can approve a public statement — real incidents lose critical time to internal debate about who's actually in charge.

03 — ASSUMPTIONS

“The plan covers our systems”

Infrastructure changes — new cloud services, new vendors, architecture changes — routinely outpace plan updates. A tabletop exercise against current systems, not the systems that existed when the plan was written, is what actually validates coverage.

04 — FREQUENCY

“We tested this once, we're covered”

RBI's framework specifically requires half-yearly drills, not a one-time exercise — systems, staff, and threats all change enough in six months to justify the recurring cadence.

What Incident Readiness covers

From written plan to tested, drilled capability

Built once, then exercised on a recurring cadence — not a one-time deliverable.

ASSESSMENT

Current-State Review

Assessing your existing plan, playbooks, and escalation procedures against current systems and staff.

  • Plan & playbook review
  • Escalation-contact validation
  • Gap identification
See the Resilience Audit →
BUILD

Playbook Development

Building or updating incident-specific playbooks — ransomware, data breach, BEC, and others.

  • Scenario-specific playbooks
  • Decision-authority mapping
  • Communication templates
See SIRI Cyber Legal Response →
EXERCISE

Tabletop Exercises

Running realistic simulated incidents with your actual response team to test the plan under pressure.

  • Scenario design
  • Facilitated exercise execution
  • Real-time gap capture
See SIRI Response →
DOCUMENTATION

Drill Documentation

Producing the documented outcomes RBI's framework requires — not just running the exercise, but recording it properly.

  • RTO/RPO validation record
  • Findings & remediation log
  • Board-ready summary
See Cyber Recovery & Assurance →
TRAINING

Response Team Training

Building familiarity and confidence in the response team before a real incident tests it.

  • Role-specific training
  • Escalation-procedure walkthroughs
  • New-hire onboarding to the plan
See SOC & SIEM →
CADENCE

Recurring Drill Programme

Establishing the half-yearly (or more frequent) testing cadence as an ongoing programme, not a one-off project.

  • Scheduled recurring exercises
  • Plan updates between drills
  • Continuous improvement tracking
See Cyber Resilience →

Evidence, not guesswork

Written plan vs. tested plan — what actually differs when it matters

Both look similar in a folder. Only one has actually been run through.

ApproachWritten plan, never testedOne-time tabletop exerciseSIRI Readiness Programme
Plan exists on paperYesYesYes
Escalation contacts validated as currentNoAt time of testValidated each cycle
Decision authority clearly assignedAssumed, untestedTested onceTested recurringly
Satisfies RBI's half-yearly drill requirementNoNo — one-time onlyYes — ongoing cadence
Documented, board-ready drill outcomesNoSometimesYes, every cycle

Sources: RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, effective 31 July 2026 — half-yearly DR drill requirement; CERT-In Directions 2022. Summarised for comparison; confirm current drill-frequency requirements applicable to your entity category.

Numbers every board should know

What tabletop testing actually finds

Half-yearly

RBI's drill requirement

Disaster recovery drills with documented RTO/RPO, required under the 2026 Framework.

6 hrs

CERT-In window

Only realistically achievable with a rehearsed response plan already in place.

1st

Phase of incident response

Preparation is the first phase of the standard NIST incident response lifecycle — readiness work happens before detection, not after.

24%

Rise in ransomware

Reported by CERT-In — the volume this readiness work is preparing an organisation to face.

Why SIRI for readiness specifically

Playbooks built by people who'll be the ones running your actual response

The same team that designs your tabletop exercise is available to lead the real response if it's ever needed.

01

Built by the team that would respond

The same responders who design and run your tabletop exercises are available to lead the actual response if an incident occurs.

02

Realistic scenarios, not generic templates

Exercises are built around your actual systems, vendors, and organisational structure, not a one-size-fits-all incident scenario.

03

Documentation that satisfies the regulation

Drill outcomes are recorded in the format RBI's framework and similar requirements actually expect — not just an internal debrief note.

04

A recurring programme, not a project

Readiness is built as an ongoing cadence from the start, matched to the half-yearly requirement rather than treated as a single deliverable.

Who this is built for

Organisations this readiness programme is built for

Banks & NBFCs facing RBI's drill requirement SEBI-regulated intermediaries Organisations without a tested IR plan Post-incident programme rebuilds Boards requesting demonstrated readiness

How we work

From current-state assessment to drilled capability

01

Current-State Review

Assessing existing plans, playbooks, and escalation procedures.

Week 1
02

Playbook Build

Developing or updating scenario-specific response playbooks.

Weeks 2–3
03

Tabletop Exercise

Running a facilitated simulation with your actual response team.

Week 4
04

Documentation & Cadence

Recording outcomes and scheduling the recurring drill programme.

Week 5+

Frequently asked

Incident Readiness, answered directly

What actually happens during a tabletop exercise?

Your response team is walked through a realistic simulated incident scenario — for example, a ransomware detection — and has to make the same decisions they would during a real incident: who to notify, what to isolate, what to communicate, in what order. A facilitator runs the scenario and captures gaps as they surface.

How is this different from just running our incident response plan as a training exercise?

A tabletop exercise specifically tests the plan under simulated pressure and captures where it breaks down — outdated contacts, unclear authority, missing steps — rather than simply walking through the document. The output is a gap list and plan revisions, not just familiarity.

Does this satisfy RBI's half-yearly drill requirement on its own?

A properly documented tabletop or technical DR drill, run on the required cadence with recorded RTO/RPO outcomes, is generally what the requirement expects — the specific format needed depends on your entity category and should be confirmed against current RBI guidance.

How often should we actually run these exercises?

RBI's framework sets a half-yearly minimum for regulated entities; organisations outside that specific requirement often benefit from at least an annual cadence, with more frequent exercises after any significant infrastructure change.

Can this be combined with the Cyber Resilience Audit?

Yes — many engagements start with the Audit to establish a baseline, then move into Incident Readiness to build and test the specific gaps the audit identified.

Test it before you need it

Build a tested incident readiness programme.

Start with a current-state review, or go straight to a tabletop exercise if you already have a plan on paper.

24/7 for active incidents: +91 79819 12046

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes and does not constitute legal advice. References to RBI's 2026 Resilience & Assurance Framework, SEBI CSCRF deadlines, CERT-In obligations, the Bharatiya Sakshya Adhiniyam 2023, and cited statistics reflect publicly available information as of publication and remain subject to regulatory change; verify current applicability to your specific entity category before relying on any specific requirement. No lawyer-client relationship is formed by viewing this page. Engagement requires a formal retainer. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top