Answer guide · Incident response and logging

Incident response plan: how to answer it in a security questionnaire

Usually asked as: “Describe your incident response plan (IRP).”

Updated

What the buyer is really asking

Do you have a written plan, do people know their roles in it, and has it been tested? Expect the buyer to ask for the document itself or a summary.

Other ways buyers ask it

Every one of these wants the same answer:

  • “Do you have a documented incident response plan?”
  • “How often is the incident response plan tested?”
  • “Who is on your incident response team?”
  • “Can you share your incident response plan?”

Evidence to have ready

  • An incident response plan with roles and severity levels
  • Records of a tabletop exercise or real incident review

How Tyrvar answers this

Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.

Related incident response and logging questions

All incident response and logging questions

Private alpha application

Bring one real questionnaire.

We are recruiting the first teams willing to work through the imperfect version with us. The form is the primary path; a calendar is optional.

  1. 01Send a work email, company, and role. Context is optional.
  2. 02Troy replies directly by email to check mutual fit.
  3. 03If it fits, we agree on one evidence set and one real questionnaire to start.
Not ready to apply? Email a question to [email protected] or read the response workflow guide.

Check mutual fit

Required fields are marked with an asterisk.

Sending this form starts a one-to-one alpha conversation. No newsletter and no automatic sales sequence. See the privacy policy.

Prefer a live conversation? Schedule an optional fit call.