Practice (almost) makes perfect
One piece of advice that all security experts agree on is that rehearsing the corporate incident response plan through table top exercises can have a major positive impact. Practice may never quite make perfect, but it will substantially improve cyber resilience. In a table top exercise, crucial information known to one department head becomes known to all. Does the sales director know how long it might take for the IT department to rebuild core systems after an attack? Does the legal department understand the urgent requirements of the corporate communications department in a crisis? What policies can be agreed calmly beforehand rather than hastily thrashed out in an emergency situation?
Much that is unknown can be revealed when practicing a crisis response. Logically speaking, quadrant four is the most productive place to invest time and money. It is far easier to raise awareness than to try to quantify the unquantifiable.