The first four hours of an incident, without inventing the playbook in real time.
A free in-browser triage for businesses and product teams handling an incident — or preparing for one. The assessment branches two ways. One path covers general security incidents on your own systems. The other covers a flaw report from a security researcher about your product. With it comes a tactical toolkit: runbooks, message trees, log-capture priorities, and regulator-ready templates.
The triage runs in your browser. Your answers never leave your device.
Two paths into the toolkit.
1. Take the free triage
A short branching assessment. The first question decides whether you are handling an incident on your own systems or a product-flaw disclosure. The triage returns an ordered action list for the next four hours, a do-not-touch list, and the regulatory clocks that may apply to you. About five minutes. Runs in your browser. No email required; nothing is sent anywhere.
Start the free triage →2. Read the free first-hour checklist
"Before You Touch Anything — The First-Hour Incident Checklist": the do-not-touch list, the first three actions in order, who to call, and the clocks that may already be running. Plain English, and yours to keep.
Read the free guide →This is for the first hours of a live incident.
It gives you in-the-moment triage (what to do in the next four hours), not a long-term readiness programme. Once the dust settles and you want to be better prepared next time, see the SMB Security Assessment or PSIRT Response. If the incident is a personal-data breach under the General Data Protection Regulation, the 72-hour clock lives in GDPR Breach Response.
Three tiers: one battle-card for individuals, one infrastructure-incident kit, one vendor-side PSIRT kit.
Each tier serves a different kind of responder. Pick the one that matches the incident you handle (or expect to handle next). The tiers stack: Solo is 9 documents (the incident log also comes as an editable Excel workbook), Commander adds 14 more (23 in all), and PSIRT CRA-Ready adds another 9 — 32 documents, including the free starter guide, and more than 130 pages of runbooks and templates, written before the incident so you do not write them during one. One-time purchase. Your files, yours forever.
- Printable First 4 Hours Battle-Card
- First-hour runbook (decision order, contact tree, capture list)
- Ten Commandments of first-response poster
- Incident log template
- Pocket reference card
- Escalation tree template
- Detection sources quick card
- Evidence-preservation and chain-of-custody card
- Pre-positioning kit (set up now, before any incident)
Enough if you’re the lone responder and need a battle-card and first-hour runbook.
Get the Solo battle-card kit — $49- Everything in Solo
- Infrastructure incident-response runbook
- Log-capture priority sheet
- Communication-tree templates (customers, staff, regulators, insurer)
- Managed-Service-Provider delegation playbook
- Business-email-compromise and account-takeover runbook
- Holding-statements communications pack (pre-drafted for the first hours)
- Cyber-insurance worksheet (what to send the carrier in hour one)
Choose this when you’re commanding a team through an incident on your own systems.
Get the Commander kit — $99- Everything in Commander
- PSIRT first-24-hours runbook
- CVE (Common Vulnerabilities and Exposures) Numbering Authority (CNA) decision tree
- Common Security Advisory Framework (CSAF) sample advisory
- PSIRT advisory drafting checklist
- Worked sample: first vulnerability report at a 14-person startup
- European Union Cyber Resilience Act Article 14 templates
- NIS2 Article 23 notification templates
- Researcher-embargo communication templates
- Coordinated-vulnerability-disclosure intake and researcher communication pack
Step up here if you ship software into the EU and face CRA / NIS2 reporting clocks.
Get the PSIRT CRA-Ready kit — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. The First 4 Hours covers the judgement of early incident response; the Operator's Workbook carries the runbooks.
Build the readiness side, too
First 4 Hours is the in-the-moment product. When the dust settles, build readiness with the matching strategic product so the next incident is calmer.
SMB Security Assessment
The readiness partner to the Commander tier. A twelve-question security assessment, plus the toolkit that heads off most of the incidents First 4 Hours responds to.
PSIRT Response
The readiness partner to the PSIRT CRA-Ready tier. A seventeen-question Product Security Incident Response Team assessment, plus the cross-team toolkit you use on calm days.
GDPR Breach Response
The privacy-domain sibling of First 4 Hours. For the first 72 hours of a personal-data breach under the General Data Protection Regulation.
The situations this toolkit is built for, written up.
The first hour of an incident — ~9 min read.
Your first tabletop exercise — ~8 min read.