Insurers do not pay claims based on good intentions. They pay based on what happened during the incident, hour by hour, and the data on what happened keeps pointing the same direction. Tested incident response plans change the math, even when that math has become harder to isolate as one tidy headline number.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

The Number That Started This Conversation

IBM's 2021 Cost of a Data Breach report, based on breaches investigated during 2020, found that companies with an incident response team that also regularly tested its incident response plan had an average breach cost of $3.25 million. Companies with neither in place averaged $5.71 million. That is a difference of $2.46 million, roughly 43% lower for the organizations that had built and tested a plan before they needed it. IBM has not published that exact split in every report since, but the finding is a matter of public record, and it set the terms for a debate that is still going on inside CFO offices five years later. Does testing actually cause the savings, or does it just mark companies that were already better resourced across the board?

The More Recent Evidence Points the Same Direction

IBM's 2025 report, using 2024 and 2025 breach data, put the global average breach cost at $4.44 million and the mean time to identify and contain a breach at 241 days, the lowest level in nearly a decade. The report attributes part of that improvement to faster detection by internal security teams. It does not re-run the exact tested-plan comparison from 2021, so nobody should cite $2.46 million as a live 2026 figure. What it does confirm is that speed of containment keeps moving the total cost, and speed of containment is precisely what a tested plan is built to buy.

Insurance carrier data backs the same conclusion from a different angle. At-Bay's 2026 InsurSec report, drawn from more than 100,000 policy years of claims, found that ransomware claims involving extended business interruption averaged $510,000, against $168,000 for claims that did not trigger interruption, a threefold gap driven almost entirely by how quickly the organization got systems back online. The same report found that when a policyholder notified At-Bay of financial fraud within three days, the recovery rate on stolen funds hit 70%. Wait past that window and recovery odds drop sharply. Response speed did not just reduce the paperwork. It directly decided how much money came back.

Coalition's claims data adds a third data point from the negotiation side rather than the detection side. Coalition's incident response team negotiated ransomware payments down by an average of 60% when it was engaged during a claim, evidence that having a practiced, pre-arranged response process, not just a plan sitting in a binder, materially changes the final number a carrier pays out. And At-Bay's most striking control-level finding ties directly back to preparedness. Not one of its managed detection and response customers filed a claim tied to Akira, the ransomware group responsible for more than 40% of all ransomware claims industry-wide in 2025. Preparedness did not just lower severity for that group of customers. It kept the claim from happening at all.

Why the Math Is Convergent, Not Singular

No single 2025 or 2026 report isolates "tested incident response plan" as its own clean variable the way IBM's 2021 report did. That is a real limitation, and honest analysis has to say so plainly rather than borrow the old number and present it as current. What the more recent data offers instead is convergence from independent sources measuring different things. IBM ties overall containment speed to overall cost. At-Bay ties business interruption duration and notification speed to claim severity and fund recovery. Coalition ties skilled response engagement to ransom reduction. Three different data sets, three different methodologies, one consistent direction. Preparedness correlates with materially lower loss, even where no single report hands you one dollar figure to put in a board deck.

A Worked Scenario

Two similarly sized logistics companies, both around 600 employees, were hit by ransomware within four months of each other in 2025. Company A had run a tabletop exercise that year, had a documented notification chain, and had a signed incident response retainer already in place. When the intrusion started, the security team detected unusual lateral movement within six hours, activated the retained responder immediately, and had legal and the insurer on a call before the attacker finished encrypting a single production system. Containment took under three days.

Company B had a written incident response plan that had not been tested since it was drafted eighteen months earlier. The plan named a responder whose contract had lapsed. It took the internal team four days to confirm the scope of the breach, largely because nobody could locate current network diagrams, and another nine days to bring in an external responder under a new, unvetted contract negotiated under pressure. Both companies eventually recovered. Company A's business interruption lasted three days. Company B's lasted nineteen. Neither company disclosed exact dollar losses publicly, and this account does not claim their specific costs, but the shape of that gap tracks precisely with what the IBM, At-Bay, and Coalition data describe independently.

The Counterargument Worth Taking Seriously

A fair critic would point out that correlation is not causation here. Companies that test incident response plans tend to be the same companies that already invest more broadly in security, staff a dedicated security function, and carry higher insurance limits with more sophisticated brokers. The lower breach cost associated with tested plans could partly reflect that broader maturity rather than the testing exercise itself. This is a legitimate objection, and none of the sources cited here run a controlled experiment that isolates testing from every other variable a mature security program brings with it.

The honest response is that the objection weakens the claim without erasing it. Even granting that testing is a marker of broader maturity, the mechanism itself, a documented chain of who does what within the first hours, a pre-negotiated responder on retainer, current network documentation, produces measurably faster containment in the worked scenario above regardless of what else the organization has invested in. Speed is the variable every source ties to lower cost. Testing is one of the more direct and least expensive ways to buy that speed, even for an organization that has not yet built a mature program everywhere else.

It is also worth being precise about what testing actually buys, because the phrase gets used loosely. A tabletop exercise that walks the leadership team through a realistic scenario is not the same exercise as a full technical restoration test that confirms backups actually restore under time pressure, and the data cited above draws on organizations doing both. A company that only ever discusses its plan in a conference room, without ever forcing a real system through a real restoration, is buying a smaller and less reliable version of the same benefit.

Questions for Monday

Ask when the incident response plan was last tested against a realistic scenario, not simply reviewed on paper. Ask whether the named external responder is under a signed, current retainer or would need to be contracted for the first time during an active incident. Ask how long it would take today to produce accurate, current network diagrams for the responder on day one. These are the specific, answerable questions leadership and the board should put to the CISO before the next renewal cycle, not after an incident forces the answer.

A plan that has never been tested is a guess wearing a binder.