It's worth noting that "do nothing" can be a perfectly valid contingency plan. If the cost of preparation exceeds the cost of the expected number of incidents then it makes business sense not to bother.
Of course, this is a gross simplification and can be biased either way by how wide-ranging you make your cost base in order to get the answer you want.