Answer yes if your organisation's Incident Response Plan is tested through regular exercises grounded in real inputs rather than generic templates. This includes drawing on the organisation's own past incidents, publicly known incidents affecting comparable organisations, current threat intelligence, and the organisation's own risk assessment findings.