Everyone's under a lot of pressure to get things back up and running, and that's a big incentive to cut corners with procedure. Suppose someone calls you during a DDOS crisis and says "hi, I'm the highly paid consultant your boss' boss hired to handle this. I need you to go to www.wefixsecurityforyou.ru and download and run the DDOS diagnostics tool." You can't reach your boss to verify because your email and IP phones are down. What would you do? Do you have the guts to say no and risk being the guy who delayed recovery for hours, costing your company a million dollars?