Skip to main content
Cybersecurity Framework

1. How often should an incident response plan be updated?

At minimum annually, and after any significant infrastructure change, personnel change in key response roles, or following a completed incident. Outdated plans are a false sense of preparedness.

2. What is the difference between an incident response plan and a disaster recovery plan?

An incident response plan covers the detection, containment, and investigation of security incidents. A disaster recovery plan covers restoration of systems and operations after any disruptive event, including non-security events like hardware failure or natural disaster. Both are necessary; neither replaces the other.

3. Should we hire an external incident response team or rely on internal staff?

Internal teams handle day-to-day security operations well, but major incidents benefit from external forensic expertise and the surge capacity that an IR retainer provides. Most mature organizations maintain a hybrid model.

4. What should a tabletop exercise cover?

Tabletop exercises should simulate realistic attack scenarios, ransomware, business email compromise, insider threat, and force decision-makers to work through the choices they would face during a real incident. The goal is to surface gaps before they appear under pressure.

5. Is a written incident response plan enough, or do we need to test it?

A written plan that has never been tested is a hypothesis. Testing through tabletop exercises and simulations is how you validate that the plan works when people are under stress and normal systems may be unavailable.

John Angelotti

John Angelotti is the President of DCG Technical Solutions, beginning his technology journey on a Commodore 64 and at swap meets with his mother. For more than two decades, he has helped businesses grow through secure, strategic, and cost-effective IT leadership.

At DCG, he works to ensure clients can grow without worrying about downtime. As the leader of a security-forward MSP, he develops tailored solutions that safeguard each client’s operations and reputation.

John is known for making complex technology easy to understand and guiding organizations through key improvements, from cloud migrations to cybersecurity hardening. Outside of work, he enjoys building things with his hands, archery, hiking, and competitive custom car audio.