PCI DSS Requirement 12.10 gets summarised everywhere as "have an incident response plan ." That's true, but it undersells what an assessor actually checks — a single plan document doesn't evidence seven sub-requirements spanning 24/7 staffing, annual testing, risk-based training frequency, and a defined response to a very specific and often-missed scenario: stored account data turning up somewhere it was never supposed to be.