When this review is useful
Review whether escalation, response authority and recovery arrangements are supported by usable evidence.
A board resilience review, a changed response provider or concern that backup success is being treated as recovery assurance.
The scope should identify the business service, control owner, assessment period and intended report reader. Include supplier dependencies and explain what has changed since the previous review. This prevents an apparently narrow request from silently expanding into an unsupported opinion about the whole organisation.
Assessment procedures to agree
- Trace a sampled escalation from alert ownership to authorised decision maker.
- Review incident plans, exercise records and outstanding corrective actions.
- Compare recovery objectives with restore-test evidence and documented dependencies.
Procedures are proposed until the engagement scope is accepted. Record the population used for each sample, the selection rationale and the date on which evidence was collected. Follow exceptions to their cause; do not extrapolate a sample failure rate to the entire estate without a defensible method.
Evidence and context to prepare
- Critical-service dependencies and recovery objectives
- Incident plan, contacts and decision authority
- Exercise, restore and follow-up records
Begin with approximate counts and non-sensitive descriptions. Full evidence belongs in an agreed secure channel after confidentiality, access and retention arrangements are settled. Avoid sending passwords, secret values or unnecessary personal records.
Expected outputs
- Readiness and recovery evidence gaps
- Prioritised exercise and dependency actions
- Closure conditions tied to observed recovery results
The report should distinguish verified observations from management explanations and open questions. Findings need proportionate recommendations and measurable closure conditions. Management retains responsibility for risk acceptance and changes.
Questions that change effort and coverage
- Which services have approved recovery objectives?
- Who can authorise containment outside office hours?
- When was application usability verified after restoration?
Assessment boundary
A document review does not activate incident-response cover or prove a recovery objective has been met. Live exercises require separate planning.
Build your audit scoping brief, or send your requirements with an NDA or RFP. High-level context is sufficient for the first conversation.

