Comparing the period's incidents, a pattern appears separating those who contained quickly from those who took weeks: companies with better outcomes had processes and response contracts ready before the attack.
The difference isn't technical competence but calendar. Contracting incident response during an incident means negotiating price and scope under maximum pressure, with the clock running and without knowing the size of the problem.
The same applies to operational decisions. Knowing in advance which system can be switched off without halting the entire operation, who authorises the shutdown and how to communicate with customers is half an hour's work on an ordinary Tuesday and nearly impossible to do well during a crisis.
Backups belong on the same list, with a condition usually missing: genuinely tested, with a full restore in a separate environment. A backup never restored is a hypothesis, not protection.
For small operations, none of this requires a large budget. It requires an afternoon's work and the discipline to repeat the restore test periodically, which is the part almost nobody does.
