Executive self-assessment

Incident Response Readiness Assessment

Measure whether your incident plan will work under pressure when decisions, evidence, communications, and recovery must happen quickly.

Result logic

What this tool evaluates

Evaluates incident roles, detection, severity, escalation, evidence, containment, recovery, communication, exercises, and lessons.

Roles & command 20%
Detection & triage 20%
Containment & investigation 22%
Recovery & continuity 20%
Communications & learning 18%
0 / 10
0%
01 Are incident commander, technical lead, executive decision maker, communications, legal/privacy, and business roles predefined?
02 Are after-hours contact paths and decision authorities current and tested?
03 Can likely incidents be detected using sufficient logs, alerts, telemetry, and user reporting?
04 Are severity, escalation, evidence-preservation, and external-notification decision criteria defined?
05 Can affected identities, endpoints, cloud resources, applications, and integrations be contained quickly?
06 Are investigation evidence, timelines, decisions, and chain-of-custody needs understood?
07 Are backups protected, restoration tested, and critical recovery dependencies known?
08 Are recovery criteria, business validation, monitoring, and return-to-service decisions defined?
09 Are internal, customer, partner, regulator, and public communication paths prepared for material incidents?
10 Has leadership participated in a realistic tabletop within the last 12 months and tracked actions to closure?