← All Blogs

Test Your MSP's Incident Response: A 7-Step Fire Drill You Can Run This Quarter

A ninety-minute tabletop shows what your IT provider actually does when a clock is running. Seven questions cover it, from who answers at 2am to who notifies your regulator. Nothing in production is touched, and the gaps it finds are the ones a written plan hides.

Organisations took a mean of 247 days to identify and contain a breach in 2026
Organisations took a mean of 247 days to identify and contain a breach in 2026
Key takeaways
  • Detection, escalation and lost business make up 63 percent of breach costs.
  • The mean time to identify and contain a breach rose to 247 days in 2026.
  • Agree who may disconnect a system before an incident, not during one.
  • Rehearse the version where the breach starts on your provider's network.
  • Your provider restores systems. Regulatory disclosure stays your obligation.

What does testing your MSP's incident response involve?

Testing your provider's incident response means running a scenario against it before a real one arrives. You pick an incident, start a clock, and work through seven questions with your provider on the call. Nothing in production is touched. Ninety minutes covers it.

The exercise exists to find the gaps that only appear under time pressure. A plan reads well as a document. It fails at the moment somebody has to decide whether to disconnect a site and discovers that nobody knows who is allowed to say yes.

Organisations took a mean of 247 days to identify and contain a breach in 2026
Organisations took a mean of 247 days to identify and contain a breach in 2026

The seven-step checklist below is built from what national cyber authorities tell MSP customers to require. Each step is a question you ask live, with a note on what a confident answer sounds like.

Why does an untested plan fail on the day?

Because the plan is not the hard part. Coordination is, and coordination is what a document cannot rehearse. The joint advisory is direct about the remedy, telling customers to ensure incident response and recovery plans are tested at regular intervals.

The cost of getting this wrong sits in the delay rather than the damage. IBM found organisations took a mean of 247 days to identify and contain a breach, the first increase after five years of decline, and that detection and escalation costs plus lost business made up 63 percent of total breach costs. Nearly two thirds of the bill is generated by how the response goes, not by the intrusion itself.

Detection and escalation plus lost business make up 63 percent of total breach costs
Detection and escalation plus lost business make up 63 percent of total breach costs

Speed is buyable, which is what makes this worth rehearsing. Organisations using automation extensively across security shortened breach times by 65 days and cut costs by 1.93 million dollars. Your provider owns most of the tooling that produces that result, so the drill is partly a test of whether it is switched on.

CISA adds the piece most businesses skip. Organisations should include key vendors such as MSPs in incident response, business continuity and other contingency planning, including in training on those plans. A provider that has never been in your exercise is meeting your process for the first time during the incident.

Step 1. Who do you call at 2am, and who answers?

Call the out-of-hours number during the drill and see who picks up. Not the account manager's mobile, the documented path. This is the single most common failure and the cheapest to find.

Then check the plan lists the people rather than the roles. The advisory expects roles and responsibilities for all organizational stakeholders, including executives, technical leads and procurement officers, which means somebody who can authorise spending is named alongside somebody who can log in.

Ask where the plan lives, too. Organisations should maintain up-to-date hard copies so responders can access them if the network is inaccessible. A contact list stored only in the system you are locked out of is not a contact list.

Step 2. How fast will your provider contain this?

Ask for a number, then ask where that number is written down. Response time and containment time are different commitments, and most agreements only promise the first.

CISA tells customers to obtain detailed guidelines for incident management, including the MSP's incident response responsibilities, compensation for service outages, and a plan to provide continuous support during an outage. Continuous support during an outage is the clause worth reading closely, because an incident that runs for three days needs a rota rather than a hero.

If the honest answer is that containment time depends on the incident, that is fair. Ask instead what the provider commits to within the first hour, and what it needs from you to move faster.

Step 3. Who is allowed to disconnect a system?

Settle this before the drill ends, because it is the decision that stalls real incidents. Isolating a site stops the spread and stops the business at the same time, and providers are often unwilling to make that call unilaterally.

CISA frames it as something to agree in advance, advising that organisations and vendors establish clear authorization protocols for threat hunting and incident response procedures on customer networks. Written pre-authorisation for defined actions, with a named decision maker for everything else, is what good looks like.

Ask the awkward version during the exercise. If your provider believes a server is actively encrypting files at 3am and cannot reach anyone at your company, what is it authorised to do on its own?

Step 4. What changes if the breach is on your provider's side?

Run the scenario in the other direction, because this is the version nobody rehearses. The incident starts on your provider's network, and the first thing you need is to be told.

An incident may begin on your network or on your provider's network
An incident may begin on your network or on your provider's network

The advisory asks providers to notify customers of confirmed or suspected security events and incidents occurring on the provider's infrastructure and administrative networks. Suspected is the operative word, and it is worth confirming your contract carries it. CISA goes further, telling customers to require that vendors provide timely and detailed reporting on incidents affecting vendor networks, even those that did not directly affect customer data and services.

Ask one blunt question here. If your provider is compromised, who tells you, and does that person work for your provider?

Step 5. Who tells your customers, insurers and regulators?

Name the person for each audience, and write the deadline next to it. Your provider restores systems. It does not make your disclosures, and that boundary surprises people at the worst moment.

A public company must file an Item 1.05 Form 8-K within four business days of determining materiality
A public company must file an Item 1.05 Form 8-K within four business days of determining materiality

External clocks run whether or not anyone is watching them. A public company must file an Item 1.05 Form 8-K within four business days of determining a cybersecurity incident was material. Sector rules and cyber insurance policies add their own windows, and insurers commonly require prompt notice as a condition of cover.

CISA asks that organisations and vendors establish clear protocols for vulnerability disclosure, incident notification, and communication with external stakeholders during an incident. Draft the holding statement now. Writing it calmly beats writing it at hour six.

Step 6. Can the business operate while systems are down?

Ask each department what it does for a day without its main system, and listen for silence. This is the half of the drill your provider cannot answer for you.

Ransomware makes the question routine rather than theoretical. IBM found ransomware appeared in 39 percent of breached organisations, up from 34 percent the previous year, and that threatening brand reputation is now the most common extortion tactic, cited by 41 percent of organisations that suffered a ransomware incident. An attacker who plans to publish is not deterred by your restore times.

Decide the small things during the exercise. Which phone numbers matter if email is gone, where the paper copies live, and who is allowed to speak publicly.

Step 7. What gets written down afterwards?

Close the drill with a findings list, an owner for each item, and a date. An exercise that produces a good feeling and no document has not changed anything.

The seven steps of an incident response fire drill
The seven steps of an incident response fire drill

Include your provider in that write-up rather than sending it afterwards. CISA advises organisations to include vendors in after-action and lessons learned reporting, and to obtain remediation acceptance criteria that define the steps the MSP will take to mitigate known risks. The second one turns a finding into a commitment with an end state.

Then diarise the next one. Plans must be updated regularly to align with changes in vendor relationships, and the relationship changes every time your provider gains a client, loses an engineer or is acquired.

How do you run this without disrupting the business?

Run it as a tabletop, which changes nothing in production. Everyone sits in a room or on a call, someone reads a scenario aloud, and the group talks through what happens next while a facilitator keeps the clock and takes notes.

Keep the room small and senior enough to decide. Someone from your provider who works incidents rather than accounts, whoever owns IT internally, one person from finance or operations who can authorise spending, and whoever would speak to customers. Four to six people is plenty.

Pick a scenario that is boring and likely rather than dramatic. A finance mailbox sending invoices to suppliers overnight teaches more than a nation-state actor, because it is the one that actually turns up.

Once a year is a reasonable floor, and after any change of provider, contract or key staff. If the first run finds nothing, the scenario was too easy.

FAQ

How do you test an MSP's incident response?

Run a tabletop exercise with your provider in the room. Pick a realistic scenario, start a clock, and work through seven questions: who answers out of hours, how fast containment is promised, who may disconnect a system, what changes if the breach started on the provider's side, who notifies customers and regulators, how the business operates meanwhile, and what gets written down afterwards. Nothing in production is touched and ninety minutes is usually enough.

How often should incident response be tested?

At least annually, and again after any change of provider, contract or key personnel. The joint advisory from CISA and six partner cyber authorities tells MSP customers to ensure incident response and recovery plans are tested at regular intervals, and CISA separately advises updating those plans whenever vendor relationships change. A provider that has never taken part in your exercise will be meeting your process for the first time during a real incident.

Should your MSP be allowed to disconnect systems without asking?

For defined actions, yes, and that authority should be written down before it is needed. CISA advises organisations and vendors to establish clear authorization protocols for threat hunting and incident response on customer networks. The workable pattern is pre-authorising specific containment actions, such as isolating a single endpoint, while naming a decision maker for anything that stops a site or a line of business.

Does your MSP handle breach notification for you?

No. Your provider restores systems and supplies technical facts. The legal and regulatory disclosures remain your obligation, and the deadlines run independently of the recovery. A public company must file an Item 1.05 Form 8-K within four business days of determining an incident was material, and sector regulators and cyber insurance policies impose their own windows. Name the person responsible for each audience before you need them.

What if your provider will not take part in a drill?

Treat the reluctance as a finding and record it. Participation costs a provider ninety minutes and CISA explicitly advises including key vendors in incident response and business continuity planning and training. A provider that declines is telling you it will be improvising alongside you on the day. Ask instead for a written walkthrough of the same seven questions, and put the request and the response in the file.

Sources

Compare managed IT providers in your city

Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.

Browse Vetted Providers

← All Blogs