The value of a plan is almost entirely in having decided things in advance: who declares an incident, who can take production offline, who talks to customers, where the notes go, which regulator has to be told and within how long. None of those are decisions to make at two in the morning with an audience.
The part most often missing is the capacity to reconstruct what happened. If the logs were not kept, or were kept somewhere the attacker could reach, the honest report is that the scope is unknown — and "we cannot rule it out" is a far more expensive sentence than the storage it would have cost to avoid it.
Related terms
Blue team
The defensive side: hardening the systems, watching them, and handling it when something happens.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
Data exfiltration
Getting data out of a system that was not supposed to let it leave.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
