Description
Six modules, each with a short teaching section and a concrete action step, that take you from “we should have an IR plan” to a playbook your team has actually rehearsed. Work through one module per week, or run all six in a single-day workshop.
The modules: 1. The incident lifecycle and the four roles no incident can leave empty (incident commander, communications lead, technical lead, scribe). 2. Detection and triage, including a 10-minute triage method and a four-level severity matrix tied to business impact. 3. Containment decisions: short-term vs long-term containment, the “pull the plug” question and preserving evidence first. 4. Communication under pressure: internal update cadence, external notification clocks and pre-written holding statements. 5. Eradication and recovery: confirming the attacker is gone, credential rotation order and stricter monitoring for 30 days after rebuild. 6. Running the playbook: tabletop exercises, playbook maintenance and how to measure readiness.
What you get: the complete workbook as a PDF, delivered immediately after purchase, including copy-ready templates: a P1–P4 severity matrix, three tabletop scenario cards (phished finance user, ransomware on a file server, vendor breach notification) and an incident status-update template. Built for security and IT leads at organisations that need a working IR program without a dedicated IR team.

Reviews
There are no reviews yet.