Test and improve your incident response plan

We run hands-on technical and process-based exercises to assess the effectiveness of your incident response capability across your environment.
Talk to an expert
Security Incident Response Testing

Security testing that builds confidence and capability

Our testing services help validate your technical response controls, playbooks and escalation paths under pressure. We design tests that match your threat profile and maturity, so you get actionable insights that strengthen real-world readiness.

  • Simulate targeted cyberattacks in a safe, controlled way
  • Test tools, team responses and decision-making effectiveness
  • Identify gaps in containment, communication and escalation
Service detail

Details that drive readiness and improvement

From technical tooling to team decision-making, we break down each test outcome so you can sharpen your detection, response and escalation maturity.

Make every test count

Practical insights that close the loop

You’ll receive a detailed report highlighting strengths, areas for improvement and next-step recommendations that align with your security objectives.

  • Maturity-ranked scoring across control areas
  • Realistic timelines and response benchmarks
  • Recommendations mapped to industry standards

Our delivery process

How testing is planned and delivered

Our testing process is collaborative and outcome-focused. We’ll work with your technical teams and decision-makers to design a scenario that’s relevant, realistic and impactful.
Select threats, systems and participants
We define realistic attack vectors and assign team roles, ensuring the exercise reflects your risk
Facilitate and observe in real time
Our consultants guide the session, prompting technical and governance responses.
Debrief, analyse and recommend
We deliver a structured report with observations, strengths and priority improvements to strengthen your incident readiness.
Benefits

Why work with us

We bring frontline experience, proven frameworks and a practical mindset. From first conversation to final report, we're focused on improving your real-world resilience.
One team from start to finish
You'll work directly with the people delivering your engagement, not just pre-sales or project managers. No handovers, no surprises.
Built for your business
We tailor every exercise to your environment, from technical depth to stakeholder roles. No generic templates or off-the-shelf scenarios.
Trusted by critical sectors
We support incident readiness and response planning across government, utilities, finance and essential services. Our work stands up to scrutiny.
What comes next

Expand your security coverage

We can help you go further, whether that means validating your incident response plan, improving stakeholder readiness or supporting NZISM certification.

  • Schedule a tailored tabletop or live-play exercise
  • Run an NZISM-aligned security review or gap analysis
  • Extend training to executives, boards or technical teams
Talk to an expert
Executive and Board Security Governance Training
We train executives and boards on their cybersecurity oversight role — focusing on risk framing, accountability, and key governance responsibilities.
Advanced OSINT Training Course
This hands-on course teaches advanced open-source intelligence techniques, tools, and tradecraft for investigations, threat profiling, and situational awareness
Frequently asked questions

Frequently asked questions

From risk assessment to rapid response - we’re with you every step of the way.

What is incident response testing and why is it important?

How often should we run an incident response exercise?

We recommend running a tabletop or scenario-based exercise at least once a year, or after major changes to systems, staff or risk posture. Regular testing keeps your team sharp and your plan aligned with real-world threats.

What’s the difference between a tabletop exercise and a live-play scenario?

A tabletop exercise is a discussion-based walkthrough of an incident, ideal for strategy and role clarity. A live-play scenario simulates an actual attack, testing systems, tools and responses in real time.

Who should be involved in an incident response test?

Key participants typically include IT, security, communications, legal, HR and executive stakeholders. Our exercises are tailored to match your organisation’s structure and critical roles.

Can you help us improve our response plan after the test?

Yes. Every Bastion-led exercise includes a lessons-learned report with practical recommendations to strengthen your incident response plan and align it with industry best practices.

Contact us

Talk to an expert

Please call our office number during normal business hours or submit a form below
Where to find us
If you experience a security breach outside normal working hours, please complete the form and we will respond as soon as possible.