Skip to main content
Incident Response Readiness

01. How long does a readiness assessment take?

For a small or mid-sized business, a thorough assessment typically takes one to two weeks, including stakeholder interviews and a technical review. It can be compressed if the organization already has recent documentation in place.

02. Is a readiness assessment the same as a penetration test?

No. A penetration test looks for technical vulnerabilities that could let an attacker in. A readiness assessment evaluates whether your organization can detect, contain, and recover once an incident occurs. Both are valuable, and they answer different questions.

03. Do we need an outside firm to conduct the assessment?

Not always, but an outside perspective often catches gaps that internal teams overlook, especially around whether documented roles match what people actually know. Many organizations use their managed IT provider to conduct or facilitate the assessment.

04. What happens after the assessment is complete?

The assessment should produce a prioritized list of gaps with clear ownership for each fix, along with a recommended timeline. The most effective next step is usually a tabletop exercise to validate that the fixes actually work under realistic conditions.

05. How much does a readiness assessment cost?

Cost varies with organization size and complexity. Many managed IT providers, including DCG, offer an initial readiness assessment as part of evaluating a broader incident response or managed security engagement.

Joe Manis

Joe Manis is a Service Delivery Manager at DCG Technical Solutions with over 25 years of experience in IT services, infrastructure operations, and client-focused technical leadership. He specializes in incident and problem management, service optimization, and ensuring technology delivery aligns with business goals. Joe is passionate about helping organizations improve operational efficiency and achieve better outcomes through strategic IT management.