Choose a scenario that crosses team boundaries
Use a realistic scenario such as a finance account compromise that affects a supplier conversation and shared documents. Map each system, provider and decision-maker involved. Ask what leadership would need to know about access, impact and recovery. Starting with a scenario reveals gaps that a list of installed security tools may miss. It also makes the readiness exercise relevant to business owners.
Check records, access and retention in practice
For each source, identify the relevant event types, time coverage, export method and person able to retrieve it. Verify a sample rather than relying only on configuration screenshots. Cloud retention can depend on licences, policies and the event involved; Microsoft documents those dependencies for its audit service. Record any limitations and who is responsible for resolving them.
Make provider responsibilities explicit
An outsourced provider may hold important records while the client retains the business risk. Review how an evidence request is authorised, what can be exported and which dependencies affect delivery. Identify an alternative contact if the normal administrator is unavailable. For group structures, check whether one entity can authorise access to another’s records instead of assuming that a shared brand means shared authority.
Practise the handling and decision trail
Run a controlled exercise that includes evidence requests, secure exchange, time-zone reconciliation and a record of changes made during response. Test how IT, security, management and advisers coordinate. The aim is to expose practical friction before an incident: unavailable permissions, unclear approval, incomplete exports or reporting that arrives without sufficient context. Assign each gap to an owner with an acceptance test.
Connect readiness to the wider risk programme
NIST SP 800-61 Revision 3 places incident response within cybersecurity risk management, connecting preparation with detection, response and recovery. Use that broader perspective when prioritising improvements. A logging change should support a decision, a response procedure or a recovery check. The exercise is complete when the organisation has both an evidence picture and an actionable improvement plan.
Repeat after material changes
Acquisitions, tenant migrations, new AI services and provider changes can alter the evidence landscape. Add readiness questions to change review and periodically retest critical sources. Record the date, scope and result so leadership understands what has actually been demonstrated. This produces a more reliable basis for response than a plan whose assumptions have never been exercised.
Further reading
Put the guidance to work
Evidence-source mapping, logging and retention review, preservation procedures and scenario exercises for investigation readiness.
Forensic readiness