Preparation for an incident
Preparation is a vital part of the incident response process. And it's not only about the team. It's also about the impacted IT infrastructure. Just imagine you are responding to a ransomware-related incident, but all you have is a fully encrypted infrastructure with only default logging enabled and barely functioning antivirus software. Sounds surreal? But it's true for many incidents I have investigated during my career. Usually, companies don't think about their security until they are impacted.
Another important point is understanding that your infrastructure has lack of security controls and people. You don't need to wait for a real incident; in many cases, just a simple penetration testing assessment may show you are not well protected.
Some companies don't start to think about security even after a successful ransomware attack. And I have a good example – an Australian transportation and logistics company...