First 4 Hours Incident Response

The first four hours of an incident, without inventing the playbook in real time.

A free in-browser triage for businesses and product teams handling an incident — or preparing for one. The assessment branches two ways. One path covers general security incidents on your own systems. The other covers a flaw report from a security researcher about your product. With it comes a tactical toolkit: runbooks, message trees, log-capture priorities, and regulator-ready templates.

The triage runs in your browser. Your answers never leave your device.

Free first

Two paths into the toolkit.

1. Take the free triage

A short branching assessment. The first question decides whether you are handling an incident on your own systems or a product-flaw disclosure. The triage returns an ordered action list for the next four hours, a do-not-touch list, and the regulatory clocks that may apply to you. About five minutes. Runs in your browser. No email required; nothing is sent anywhere.

Start the free triage →

2. Read the free first-hour checklist

"Before You Touch Anything — The First-Hour Incident Checklist": the do-not-touch list, the first three actions in order, who to call, and the clocks that may already be running. Plain English, and yours to keep.

Read the free guide →
Who this is for

This is for the first hours of a live incident.

It gives you in-the-moment triage (what to do in the next four hours), not a long-term readiness programme. Once the dust settles and you want to be better prepared next time, see the SMB Security Assessment or PSIRT Response. If the incident is a personal-data breach under the General Data Protection Regulation, the 72-hour clock lives in GDPR Breach Response.

Pick a tier

Three tiers: one battle-card for individuals, one infrastructure-incident kit, one vendor-side PSIRT kit.

Each tier serves a different kind of responder. Pick the one that matches the incident you handle (or expect to handle next). The tiers stack: Solo is 9 documents (the incident log also comes as an editable Excel workbook), Commander adds 14 more (23 in all), and PSIRT CRA-Ready adds another 9 — 32 documents, including the free starter guide, and more than 130 pages of runbooks and templates, written before the incident so you do not write them during one. One-time purchase. Your files, yours forever.

Solo
$49one-time
Single practitioners, founders, fractional Chief Information Security Officers (CISOs), incident-response newcomers
  • Printable First 4 Hours Battle-Card
  • First-hour runbook (decision order, contact tree, capture list)
  • Ten Commandments of first-response poster
  • Incident log template
  • Pocket reference card
  • Escalation tree template
  • Detection sources quick card
  • Evidence-preservation and chain-of-custody card
  • Pre-positioning kit (set up now, before any incident)

Enough if you’re the lone responder and need a battle-card and first-hour runbook.

Get the Solo battle-card kit — $49
PSIRT CRA-Ready
$299one-time
Product-security teams handling a flaw disclosure under the EU Cyber Resilience Act (CRA) or NIS2 (EU Network and Information Security Directive) reporting clocks
  • Everything in Commander
  • PSIRT first-24-hours runbook
  • CVE (Common Vulnerabilities and Exposures) Numbering Authority (CNA) decision tree
  • Common Security Advisory Framework (CSAF) sample advisory
  • PSIRT advisory drafting checklist
  • Worked sample: first vulnerability report at a 14-person startup
  • European Union Cyber Resilience Act Article 14 templates
  • NIS2 Article 23 notification templates
  • Researcher-embargo communication templates
  • Coordinated-vulnerability-disclosure intake and researcher communication pack

Step up here if you ship software into the EU and face CRA / NIS2 reporting clocks.

Get the PSIRT CRA-Ready kit — $299

Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.

How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.

From Sylvan Press

The companion books: the field guide and the workbook behind this toolkit.

The books teach the discipline; the toolkit does the work with you. The First 4 Hours covers the judgement of early incident response; the Operator's Workbook carries the runbooks.

Your triage runs in your browser, even mid-incident.

The free First 4 Hours triage scores you in your browser. We do not collect your answers, your incident details, the systems involved, the regulators you might need to notify, or any other context. We collect your email address only if you choose to enter it for the Battle-Card download. Nothing else.

Our website uses Cloudflare's server-side traffic counts for page totals — no scripts added to the page, no cookies, no data that identifies you.

From the blog

The situations this toolkit is built for, written up.

The first hour of an incident — ~9 min read.

Your first tabletop exercise — ~8 min read.