Crisis Management & Incident Response
Stand up a war-room, preserve evidence, communicate cleanly, and recover fast — defensible under scrutiny.
ICS
War-room roles
Comms
Matrix & channels
Evidence
Preserve & log
Recovery
Milestones
Filter by role:
Overall
0%
Controls
0%
Escalation
0%
72-Hour Flow
0%
Mark items as implemented. Use the role filter to focus each team.
ICS / War-Room
0%
Communications
0%
Evidence & Legal
0%
Facilities & Safety
0%
Logistics & Resources
0%
IT/OT Coordination
0%
Notify | Within | Channel | Log | Done |
---|---|---|---|---|
Security Lead | 2h | Ticket + Email | Incident # + summary | |
Facilities | 4h | Ticket | Action items |
Notify | Within | Channel | Log | Done |
---|---|---|---|---|
IC + Security + Facilities | 1h | Bridge + Ticket | Initial severity set | |
Legal + PR | 2h | Email (privileged) | Privilege note |
Notify | Within | Channel | Log | Done |
---|---|---|---|---|
IC + Legal + Exec | 15m | Bridge + Signal | Decision log started | |
LE/Fire (if applicable) | 30m | Phone | POC/time |
Notify | Within | Channel | Log | Done |
---|---|---|---|---|
All-hands (IC, Security, Facilities, IT/OT, Legal, PR, HR, Exec) | Immediate | War-Room | Chronology live | |
Regulators/LE (as required) | 1h | Phone + Email | Preservation order |
Elapsed: 00:00:00
Started: —
T+0 to 1h — Stabilize & Preserve
0%
T+1 to 4h — Contain & Communicate
0%
T+4 to 24h — Investigate & Document
0%
T+24 to 72h — Recover & Review
0%