Knowing you have an incident response plan is not the same as knowing it works. As part of a comprehensive incident response planning strategy, organizations should regularly validate whether those procedures will perform during a real-world attack. Most organizations have documentation that describes what to do when a breach occurs. Far fewer have tested whether their people know what to do, whether their detection tools would surface the right signals in time, whether their response procedures would contain the damage before it became catastrophic, and whether their recovery capabilities would restore normal operations within a timeframe their business could absorb.
A breach readiness assessment is the structured process for finding out. It evaluates your actual ability to respond to a significant security incident, not the theoretical ability described in your incident response plan, but the operational reality of your detection, response, and recovery capabilities today.
What a Breach Readiness Assessment Evaluates
Detection Capability
Attackers who penetrate enterprise environments typically spend weeks or months inside the network before detection. The average dwell time remains measured in days, but the tail of the distribution, the incidents that result in the most damage, involves attackers who were present for months before being identified. Detection capability assessment evaluates whether your logging infrastructure supports an effective cyber incident response, enabling your team to identify threats before attackers can establish persistence alert configurations, and monitoring processes would surface the indicators of compromise associated with the most likely attack scenarios against your environment.
Response Procedures and Playbooks
Incident response plans are typically written for the plan author, not for the person who will be executing the response at 2 AM during an active breach. The assessment evaluates whether your playbooks are specific enough to guide action under pressure, whether they are current with your actual environment, and whether the people responsible for executing them have practiced doing so. A plan that has never been tested is a plan whose failure modes are unknown.
Communication and Escalation Protocols
Effective breach response requires rapid, accurate communication across functions that do not normally coordinate: security operations, legal, communications, executive leadership, and potentially regulators, insurers, and affected customers. Assessment of communication protocols evaluates whether escalation paths are clearly defined, whether notification requirements are understood, and whether the organization has a documented approach to managing the external communications that accompany a significant incident.
Containment and Isolation Capabilities
Containing an active breach requires the ability to isolate affected systems quickly without creating collateral damage that disrupts business operations beyond the affected scope. The assessment evaluates your technical ability to isolate network segments, disable compromised accounts, revoke active sessions, and quarantine affected endpoints, and the operational procedures that govern when and how those capabilities are used.
Evidence Preservation and Forensic Readiness
The evidence generated during a breach has legal, regulatory, and insurance implications that extend well beyond the technical response. Forensic readiness assessment evaluates whether your logging configurations capture the data needed for post-incident investigation, whether your evidence preservation procedures would survive legal scrutiny, and whether your retention policies align with the regulatory and contractual requirements that may govern your response obligations.
Recovery Time and Recovery Point Capabilities
Recovery capability assessment should be performed alongside a broader cybersecurity risk assessment to identify weaknesses that could delay recovery after a breach, recovery procedures, and business continuity capabilities would allow you to restore operations within a timeframe your business could absorb. For organizations with mature backup infrastructure, the gaps most commonly found are in the recovery procedures themselves: backups exist, but the procedures for restoring from them quickly, verifying their integrity, and operating in reduced-capacity mode during recovery have never been tested.
The Readiness Assessment Process
Documentation Review
The assessment begins with a review of your incident response plan, playbooks, communication protocols, and supporting documentation. This phase establishes the documented baseline against which operational capability will be evaluated. The documentation review surfaces the most obvious gaps: missing playbooks for likely attack scenarios, escalation paths that reference people who no longer work for the organization, and notification procedures that are inconsistent with current regulatory requirements.
Technical Environment Evaluation
The technical evaluation assesses your detection infrastructure, log sources, SIEM configuration, alert rules, and monitoring coverage, against the attack scenarios most relevant to your organization. Armour Cybersecurity evaluates whether your current technical environment aligns with a comprehensive Cybersecurity Posture Assessment, helping identify visibility gaps across the attack lifecycle would generate the signals needed to detect a breach at each stage of the attack lifecycle: initial access, lateral movement, privilege escalation, data access, and exfiltration.
Tabletop Exercise
A structured tabletop exercise walks your response team through a realistic breach scenario, testing their understanding of response procedures, decision-making under pressure, and coordination across functions. The exercise is designed to surface the gaps that documentation review and technical evaluation do not find: the assumptions that are wrong, the handoffs that break down, and the decisions that nobody has clear authority to make. The tabletop is the most valuable component of the readiness assessment for most organizations because it reveals the human and process dimensions of response capability that technical evaluations miss.
Gap Analysis and Remediation Roadmap
The assessment output is a gap analysis organized by capability area, with findings classified by severity and remediation complexity. The remediation roadmap sequences the improvements needed to bring your breach response capability to the level your risk exposure requires, with priority given to the gaps most likely to affect outcomes in the scenarios most relevant to your threat environment.
Signs That Your Organization Needs a Breach Readiness Assessment
- Your incident response plan has not been updated in more than twelve months
- Your response team has never conducted a tabletop exercise for a ransomware scenario
- You are unsure whether your current logging infrastructure captures the data needed for forensic investigation
- Your breach notification procedures have not been reviewed against current regulatory requirements in your jurisdiction
- You have recently undergone significant infrastructure changes, cloud migration, M&A activity, remote work expansion, that your response procedures have not caught up with
- Your cyber insurance underwriter has asked about your incident response capabilities and you are not fully confident in your answers
Breach Readiness as a Continuous Practice
A breach readiness assessment is not a one-time certification exercise. The threat landscape, your infrastructure, your team, and the regulatory environment all change continuously. Armour Cybersecurity recommends that organizations conduct a formal breach readiness assessment annually, supplement it with tabletop exercises for specific scenarios on a more frequent basis, and update response procedures whenever significant infrastructure changes occur.



