First 4 Hours Incident Response

The first four hours of an incident — without inventing the playbook in real time.

A free in-browser triage for businesses and product teams handling an incident — or preparing for one. The assessment branches two ways: an infrastructure path for general security incidents, and a product-vulnerability path for teams answering a security researcher's disclosure. With it comes a tactical toolkit: runbooks, communication trees, log-capture priorities, and regulator-ready templates.

The triage runs in your browser. Your answers never leave your device.

Pick a tier

Three tiers — one battle-card for individuals, one infrastructure-incident kit, one vendor-side PSIRT kit.

Each tier serves a different incident-responder identity. Buy the tier that matches the kind of incident you handle (or expect to handle next).

Solo
$49one-time
Single practitioners, founders, fractional Chief Information Security Officers (CISOs), incident-response newcomers
  • Printable First 4 Hours Battle-Card
  • First-hour runbook (decision order, contact tree, capture list)
  • Ten Commandments of first-response poster
  • Incident log template
  • Pocket reference card
  • Escalation tree template
Buy Solo — $49
PSIRT CRA-Ready
$199one-time
Product-security teams handling a vulnerability disclosure under the EU Cyber Resilience Act (CRA) or NIS2 reporting clocks
  • Everything in Commander
  • PSIRT first-24-hours runbook
  • CVE Numbering Authority (CNA) decision tree
  • Common Security Advisory Framework (CSAF) sample advisory
  • PSIRT advisory drafting checklist
  • Worked sample: first vulnerability report at a 14-person startup
  • European Union Cyber Resilience Act Article 14 templates
  • NIS2 Article 23 notification templates
  • Researcher-embargo communication templates
Buy PSIRT CRA-Ready — $199
How it works

Two paths into the toolkit.

1. Take the free triage

A short branching assessment. First question decides whether you are handling an infrastructure incident or a product-vulnerability disclosure. The triage returns a priority-action sequence for the next four hours, a do-not-touch list, and the regulatory clocks that may apply to your situation. About five minutes. Runs in your browser — no email required, no data transmitted.

Start the free triage →

2. Download the free Battle-Card

A one-page printable reference that summarises the first four hours of any incident: the decisions to make in the first 30 minutes, the people to call in the first hour, the artefacts to capture before they're lost. Keep one printed copy near the place you'd be standing when an incident is reported.

Get the free Battle-Card →

Your triage runs in your browser — even mid-incident.

The free First 4 Hours triage scores you locally in your browser. We do not collect your answers, your incident details, the systems involved, the regulators you might need to notify, or any other context. We collect your email address only if you choose to enter it for the Battle-Card download. Nothing else.

Our website uses Cloudflare's server-side traffic analytics for aggregate page counts — no JavaScript injection, no cookies, no identifiable data.