Incident Readiness — the plan tested before you need it, not written the day you do.
An incident response plan that's never been rehearsed behaves differently than expected the first time it's needed for real. SIRI Incident Readiness builds and tabletop-tests your playbooks before an incident — satisfying RBI's half-yearly drill requirement along the way.
The gap between written and rehearsed
A plan nobody has run through is a document, not a capability.
Most organisations that have an incident response plan wrote it once — often years ago, often by someone no longer at the company — and have never actually rehearsed it. The people who would execute it during a real incident have never seen it in practice, the escalation contacts may be outdated, and the assumptions baked into it about system architecture may no longer hold.
RBI's 2026 Resilience & Assurance Framework converts this from a best practice into a specific, recurring requirement: half-yearly disaster recovery drills with documented outcomes. CERT-In's incident response expectations similarly assume an organisation has thought through its response before an incident, not during one. A tabletop exercise — walking a response team through a simulated incident scenario — is the standard way to find out whether a plan actually works before finding out the hard way.
SIRI Incident Readiness builds the plan, then tests it under realistic conditions, then documents the outcome — producing both an improved capability and the drill documentation that RBI's framework specifically requires.
What organisations get wrong
Four assumptions readiness testing routinely exposes
These show up almost every time a plan meets an actual simulation.
“Our escalation list is in the plan document”
Escalation contacts change with staff turnover far more often than incident response plans get updated — a plan reviewed only during drafting frequently has stale contact information by the time it's needed.
“Someone will make the call when it happens”
Without a pre-defined decision authority — who can authorise isolating a system, who can approve a public statement — real incidents lose critical time to internal debate about who's actually in charge.
“The plan covers our systems”
Infrastructure changes — new cloud services, new vendors, architecture changes — routinely outpace plan updates. A tabletop exercise against current systems, not the systems that existed when the plan was written, is what actually validates coverage.
“We tested this once, we're covered”
RBI's framework specifically requires half-yearly drills, not a one-time exercise — systems, staff, and threats all change enough in six months to justify the recurring cadence.
What Incident Readiness covers
From written plan to tested, drilled capability
Built once, then exercised on a recurring cadence — not a one-time deliverable.
Current-State Review
Assessing your existing plan, playbooks, and escalation procedures against current systems and staff.
- Plan & playbook review
- Escalation-contact validation
- Gap identification
Playbook Development
Building or updating incident-specific playbooks — ransomware, data breach, BEC, and others.
- Scenario-specific playbooks
- Decision-authority mapping
- Communication templates
Tabletop Exercises
Running realistic simulated incidents with your actual response team to test the plan under pressure.
- Scenario design
- Facilitated exercise execution
- Real-time gap capture
Drill Documentation
Producing the documented outcomes RBI's framework requires — not just running the exercise, but recording it properly.
- RTO/RPO validation record
- Findings & remediation log
- Board-ready summary
Response Team Training
Building familiarity and confidence in the response team before a real incident tests it.
- Role-specific training
- Escalation-procedure walkthroughs
- New-hire onboarding to the plan
Recurring Drill Programme
Establishing the half-yearly (or more frequent) testing cadence as an ongoing programme, not a one-off project.
- Scheduled recurring exercises
- Plan updates between drills
- Continuous improvement tracking
Evidence, not guesswork
Written plan vs. tested plan — what actually differs when it matters
Both look similar in a folder. Only one has actually been run through.
| Approach | Written plan, never tested | One-time tabletop exercise | SIRI Readiness Programme |
|---|---|---|---|
| Plan exists on paper | Yes | Yes | Yes |
| Escalation contacts validated as current | No | At time of test | Validated each cycle |
| Decision authority clearly assigned | Assumed, untested | Tested once | Tested recurringly |
| Satisfies RBI's half-yearly drill requirement | No | No — one-time only | Yes — ongoing cadence |
| Documented, board-ready drill outcomes | No | Sometimes | Yes, every cycle |
Sources: RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, effective 31 July 2026 — half-yearly DR drill requirement; CERT-In Directions 2022. Summarised for comparison; confirm current drill-frequency requirements applicable to your entity category.
Numbers every board should know
What tabletop testing actually finds
RBI's drill requirement
Disaster recovery drills with documented RTO/RPO, required under the 2026 Framework.
CERT-In window
Only realistically achievable with a rehearsed response plan already in place.
Phase of incident response
Preparation is the first phase of the standard NIST incident response lifecycle — readiness work happens before detection, not after.
Rise in ransomware
Reported by CERT-In — the volume this readiness work is preparing an organisation to face.
Why SIRI for readiness specifically
Playbooks built by people who'll be the ones running your actual response
The same team that designs your tabletop exercise is available to lead the real response if it's ever needed.
Built by the team that would respond
The same responders who design and run your tabletop exercises are available to lead the actual response if an incident occurs.
Realistic scenarios, not generic templates
Exercises are built around your actual systems, vendors, and organisational structure, not a one-size-fits-all incident scenario.
Documentation that satisfies the regulation
Drill outcomes are recorded in the format RBI's framework and similar requirements actually expect — not just an internal debrief note.
A recurring programme, not a project
Readiness is built as an ongoing cadence from the start, matched to the half-yearly requirement rather than treated as a single deliverable.
Who this is built for
Organisations this readiness programme is built for
How we work
From current-state assessment to drilled capability
Current-State Review
Assessing existing plans, playbooks, and escalation procedures.
Week 1Playbook Build
Developing or updating scenario-specific response playbooks.
Weeks 2–3Tabletop Exercise
Running a facilitated simulation with your actual response team.
Week 4Documentation & Cadence
Recording outcomes and scheduling the recurring drill programme.
Week 5+Frequently asked
Incident Readiness, answered directly
What actually happens during a tabletop exercise?
Your response team is walked through a realistic simulated incident scenario — for example, a ransomware detection — and has to make the same decisions they would during a real incident: who to notify, what to isolate, what to communicate, in what order. A facilitator runs the scenario and captures gaps as they surface.
How is this different from just running our incident response plan as a training exercise?
A tabletop exercise specifically tests the plan under simulated pressure and captures where it breaks down — outdated contacts, unclear authority, missing steps — rather than simply walking through the document. The output is a gap list and plan revisions, not just familiarity.
Does this satisfy RBI's half-yearly drill requirement on its own?
A properly documented tabletop or technical DR drill, run on the required cadence with recorded RTO/RPO outcomes, is generally what the requirement expects — the specific format needed depends on your entity category and should be confirmed against current RBI guidance.
How often should we actually run these exercises?
RBI's framework sets a half-yearly minimum for regulated entities; organisations outside that specific requirement often benefit from at least an annual cadence, with more frequent exercises after any significant infrastructure change.
Can this be combined with the Cyber Resilience Audit?
Yes — many engagements start with the Audit to establish a baseline, then move into Incident Readiness to build and test the specific gaps the audit identified.
Test it before you need it
Build a tested incident readiness programme.
Start with a current-state review, or go straight to a tabletop exercise if you already have a plan on paper.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

