How This Works

Answer one path-select question, then eight questions about the situation. At the end you will get a triage band (Stable / Elevated / Acute / Critical), a breakdown across the four response phases (Triage, Containment, Evidence, Notification), a list of any regulatory clocks that may already be running, the actions to avoid right now, and a recommended priority list.

The questions reflect widely recognised incident-response and Product Security Incident Response Team (PSIRT) practices. Which actions fit your situation is your call.

Step 1 — What kind of incident is this?

This determines which set of questions you see next. Pick the closest fit. If both apply, pick the one that is more time-urgent.

Path A — Triage & Containment

The discovery time is when the first reporting clocks start running, not when the breach actually occurred.

Pick the closest fit. "Unsure" is a valid answer in the first hours; the assessment adjusts for it.

Knowing the blast radius is what makes containment and notification decisions possible.

Some "obvious" first moves destroy the forensic record. Honest answer matters more than the right answer.

Sensitivity drives both regulatory exposure and the urgency of notification.

Different categories trigger different statutory reporting clocks. Pick all that apply by selecting the closest single answer; the assessment surfaces all relevant clocks on the results page.

Most cyber-insurance policies require notification within a short window of awareness; some void coverage if missed. Counsel usually has to be in the loop before external communications.

Online backups are commonly encrypted alongside production in ransomware events. "Offline / immutable" is the relevant baseline.

Path B — Vulnerability Intake & Triage

The channel often shapes the embargo window and the reporter's expectations.

The reporter's claim is a starting point; you will score it yourself with the Common Vulnerability Scoring System (CVSS) before acting.

Active exploitation changes which clocks start (under the EU Cyber Resilience Act, a 24-hour notification window) and shortens embargo tolerances.

Confirming a report is real before acting on it avoids both false alarms and dismissed real issues.

EU deployment brings the Cyber Resilience Act (CRA) into scope from 11 September 2026. Affected products shipped to the EU before that date are also in scope.

A documented embargo (acknowledgement + agreed disclosure window) protects both sides during coordinated disclosure.

A standing PSIRT (or named owner) shortens the first hours considerably; ad-hoc response tends to drop steps.

Starting the advisory draft and a CVE Numbering Authority (CNA) submission early reduces the time-to-disclosure when the fix lands.

Your Triage Result

0 / 32

Phase Breakdown

Triage
0 / 8
Containment
0 / 8
Evidence
0 / 8
Notification
0 / 8

Regulatory Clocks That May Be Running

Things to Avoid Right Now

    Your Recommended Next Actions

    The Free Triage Shows Where You Stand. The Paid Editions Tell You What to Do Next.

    Each paid edition adds the runbook, the pre-filled templates, and the toolkit appropriate to your situation — so you have the documents in front of you, not just the score.

    Tier 1
    Solo
    $49
    The Battle-Card plus a basic first-hour runbook — for single practitioners and founders.
    See Solo →
    Tier 2
    Commander
    $99
    Infrastructure incident kit — tabletop scenarios, communication tree, log-capture checklist, regulatory decision tree.
    See Commander →