Vendor IR Plan Maturity
Two-Page IR Overview. Last Exercise: Unknown. Ransomware Playbook: Not Documented.
5 min read · 5 May 2026 · Security
A multinational consumer goods company assessed their logistics software vendor's incident response capability as part of the annual TPRM review. The questionnaire asked whether the vendor had a documented incident response plan and whether it was regularly reviewed and updated. The vendor confirmed both: yes, documented IR plan, reviewed annually. The assessment accepted these confirmations as evidence of IR capability maturity. When a ransomware event struck the logistics vendor eight months later, the gaps in the IR plan's practical maturity became immediately apparent. The vendor's team spent the first four hours determining who had decision authority , the plan described roles without specifying decision rights for the specific scenario of ransomware with operational impact. No ransomware-specific playbook existed , the plan had general incident categories but no scenario-specific procedures. The first external communication to customers, which should have been a preliminary notification, was an operational status update from the account management team that did not mention the ransomware or its potential impact on customer data. The IR plan had been reviewed annually. The reviews had confirmed the plan's existence and updated contact details. They had not exercised the plan against realistic scenarios, validated that playbooks covered critical scenarios, or measured the team's ability to execute the plan under incident conditions.
What is the Vendor IR Plan Maturity Problem, Really?
IR plan maturity is the degree to which an incident response plan reflects a genuine, tested operational capability , not just the existence of documentation that describes intended procedures. A mature IR plan has been exercised against realistic scenarios, refined through lessons learned from actual incidents and exercises, and validated to produce effective response under the conditions of actual incident pressure. An immature IR plan has been documented and possibly reviewed but not exercised, scenario-tested, or measured for operational effectiveness.
The documentation-versus-capability gap is the core maturity problem. IR plans are documents. IR capabilities are organisational skills, tested procedures, and validated technical infrastructure that enable effective response under incident conditions. The gap between the document and the capability depends on how much the document has been translated into operational reality through exercises, tabletops, and incident post-mortems. An IR plan that has been written and updated is a document. An IR plan that has been exercised under realistic conditions is the beginning of a capability.
The scenario-specific playbook gap is the most operationally consequential maturity element. General IR frameworks describe phases , preparation, detection, containment, eradication, recovery , without the scenario-specific decision trees, technical procedures, and communication templates that enable effective response to specific incident types. A vendor who faces a ransomware incident with only a general IR framework must improvise the ransomware-specific decisions , to pay or not, to isolate or maintain service, to notify regulators before or after confirming scope , in real time, under pressure, without pre-defined guidance. Scenario-specific playbooks address this gap by pre-defining the decisions and procedures for the most likely scenarios.
- IR plan documented but not exercised , no tabletop or simulation to validate effectiveness
- No scenario-specific playbooks , general framework without ransomware, data exfiltration, or supply chain compromise procedures
- Last exercise date unknown , no regular exercise cadence
- Annual review updating contacts without testing execution capability
- No lessons learned from past incidents incorporated into plan
Why this matters
Vendor IR plan maturity matters for TPRM because the customer's outcome in a vendor breach depends on the quality of the vendor's IR execution , and execution quality depends on maturity that documentation alone cannot demonstrate. A vendor who responds to a ransomware event by spending four hours determining decision authority, improvising customer communication, and operating without scenario-specific playbooks will produce a slower, less effective, and less coordinated response than a vendor who has exercised the ransomware scenario, has defined playbooks, and has team members who have practiced the procedures.
Where most teams get this wrong
The most consistent failure is accepting IR plan documentation as evidence of IR capability. Documentation is the minimum evidence for plan existence. Exercise records, post-mortem improvements, and scenario-specific playbook existence are the evidence for operational capability.
- IR plan documentation accepted as capability evidence
- Exercise cadence and most recent exercise date not asked
- Scenario-specific playbook existence not verified , ransomware, data exfiltration, supply chain
- Post-mortem improvement process not assessed
- Mean time to contain in last IR exercise not requested
What good looks like
Mature IR programmes exercise their plans against realistic scenarios at least annually, maintain scenario-specific playbooks for the most likely incident types, incorporate lessons learned from exercises and actual incidents into plan updates, and measure IR performance metrics , MTTD, MTTC , during exercises.
- Annual exercise with realistic scenarios , tabletop at minimum, simulation preferred
- Scenario-specific playbooks for ransomware, data exfiltration, and supply chain compromise
- Exercise performance metrics , MTTD, MTTC, notification timeline measured
- Post-exercise improvement incorporated into plan updates
- Lessons learned from actual incidents documented and applied
Tooling
IR Exercise Platforms , SANS IR training, Tabletop Simulator
Tabletop exercise platforms and facilitation services provide structured scenario exercises that reveal IR plan gaps without the pressure of a real incident. For TPRM practitioners, asking whether the vendor conducts annual tabletop exercises with scenario-specific scenarios , specifically including ransomware , provides a specific exercise capability question.
Governance challenges
The governance challenge with IR plan maturity assessment is moving beyond document confirmation. Exercise records, scenario playbook availability, and IR performance metrics provide a more complete maturity picture but require specific evidence requests rather than standard questionnaire questions.
- Ask for most recent exercise date and scenario , not just confirmation that exercises occur
- Ask for scenario-specific playbook availability , ransomware, data exfiltration
- Ask for IR performance metrics from most recent exercise , MTTD, MTTC
- Ask how the plan was updated after the last incident or exercise
- Ask for post-mortem improvement evidence
If you are a small team
Ask your highest-risk vendor four questions beyond confirming the plan exists. First: when was your most recent IR exercise and what scenario did it test? Second: do you have a specific ransomware playbook and when was it last tested? Third: what was your mean time to contain in the last exercise? Fourth: what specific changes were made to the IR plan based on the last exercise findings? Those four questions reveal the difference between a documented plan and an exercised capability.
- Ask date and scenario of most recent IR exercise
- Ask whether ransomware-specific playbook exists and when last tested
- Ask MTTD and MTTC from most recent exercise
- Ask what changed in the plan after the last exercise
What to require
Ask directly:
"For your incident response programme , when was your most recent tabletop exercise, what scenario did it test, and what specific changes were made to your IR plan or playbooks as a result of the findings?"
Expect as evidence
- Most recent exercise date and scenario
- Scenario-specific playbook availability , ransomware, data exfiltration
- IR performance metrics from exercises , MTTD, MTTC
- Post-exercise improvement evidence
A vendor who confirms a documented annual IR plan should be asked when it was last exercised and what changed as a result. Documentation describes intent. Exercise records describe capability. Post-exercise improvements describe whether the intent is being translated into operational reality.
How to evidence it
- IR exercise date and scenario records
- Scenario-specific playbook documentation
- IR performance metrics records
- Post-exercise improvement documentation
Key Takeaway
The IR plan was documented and reviewed annually. The review updated contact information and confirmed the plan was current. The ransomware incident revealed that the decision authority was unclear, the ransomware playbook did not exist, and the first customer communication was an operational status update rather than an incident notification. The plan had been reviewed. It had not been exercised. Documentation describes what should happen in an incident. Exercises reveal what actually happens. Ask for the exercise date. Ask for the scenario. Ask what changed. The plan is the document. The exercise is the proof.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association