ISO 27035 scenario testing with simulations
ISO/IEC 27035 covers information security incident management, from preparation to lessons learned.
iluminr simulations let teams rehearse the decisions ISO 27035 cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.
Simulations mapped to ISO 27035
Mapping is indicative. Confirm scope against your own obligations.
Frequently asked questions
What is ISO 27035?
ISO/IEC 27035 covers information security incident management, from preparation to lessons learned.
How do simulations help with ISO 27035?
Simulations let teams rehearse the decisions ISO 27035 cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.
Which iluminr simulations map to ISO 27035?
Simulations mapped to ISO 27035 include Bracing for Impact: Communications Test, Data Breach: Major Leak, Extortion: Ransomware Invasion, Inside Job: Data Breach, Trading Halt: Ransomware Chaos and Double Tap: Cyber Attack, among others.
Who should take part?
These simulations are most often run with Technology & Security, Risk, Compliance and Legal.
Can I build a 12-month ISO 27035 testing program?
Yes. The iluminr program builder suggests a 12-month plan of simulations for ISO 27035. You can add or remove scenarios and export the plan as a PDF for your board.
Can we customize these simulations?
Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.
Is this mapping legal or compliance advice?
No. The mapping between simulations and ISO 27035 is indicative. Confirm scope against your own obligations.

