Please read and accept the terms of use to continue.
What this is
This is a free self-triage tool for the first hours of a security incident — either an attack on your infrastructure or an inbound vulnerability report against a product you ship. It offers recommended practices drawn from widely recognised incident-response and coordinated-vulnerability-disclosure standards. It is general guidance.
What this isn't
It is not a substitute for engaging qualified incident-response counsel, a forensics team, or legal advice. Every recommendation is optional, and following it reduces common risks but does not guarantee a successful response or any particular outcome.
Your responsibility
Responsibility for your business's security, products, and data remains with you.
Verify any recommendation against your own circumstances before acting.
If a real incident is in progress, engage qualified professionals (forensics, counsel, cyber-insurance carrier) without delay.
A fast, structured triage for the first hours of a security incident — either an attack on your infrastructure or a vulnerability report against a product you ship. Designed to take two minutes and prevent costly first-hour mistakes.
Free edition · 9 questions · no email required
How This Works
Answer one path-select question, then eight questions about the situation. At the end you will get a triage band (Stable / Elevated / Acute / Critical), a breakdown across the four response phases (Triage, Containment, Evidence, Notification), a list of any regulatory clocks that may already be running, the actions to avoid right now, and a recommended priority list.
The questions reflect widely recognised incident-response and Product Security Incident Response Team (PSIRT) practices. Which actions fit your situation is your call.
Step 1 — What kind of incident is this?
This determines which set of questions you see next. Pick the closest fit. If both apply, pick the one that is more time-urgent.
Path A — Triage & Containment
The discovery time is when the first reporting clocks start running, not when the breach actually occurred.
Pick the closest fit. "Unsure" is a valid answer in the first hours; the assessment adjusts for it.
Knowing the blast radius is what makes containment and notification decisions possible.
Some "obvious" first moves destroy the forensic record. Honest answer matters more than the right answer.
Sensitivity drives both regulatory exposure and the urgency of notification.
Different categories trigger different statutory reporting clocks. Pick all that apply by selecting the closest single answer; the assessment surfaces all relevant clocks on the results page.
Most cyber-insurance policies require notification within a short window of awareness; some void coverage if missed. Counsel usually has to be in the loop before external communications.
Online backups are commonly encrypted alongside production in ransomware events. "Offline / immutable" is the relevant baseline.
Path B — Vulnerability Intake & Triage
The channel often shapes the embargo window and the reporter's expectations.
The reporter's claim is a starting point; you will score it yourself with the Common Vulnerability Scoring System (CVSS) before acting.
Active exploitation changes which clocks start (under the EU Cyber Resilience Act, a 24-hour notification window) and shortens embargo tolerances.
Confirming a report is real before acting on it avoids both false alarms and dismissed real issues.
EU deployment brings the Cyber Resilience Act (CRA) into scope from 11 September 2026. Affected products shipped to the EU before that date are also in scope.
A documented embargo (acknowledgement + agreed disclosure window) protects both sides during coordinated disclosure.
A standing PSIRT (or named owner) shortens the first hours considerably; ad-hoc response tends to drop steps.
Starting the advisory draft and a CVE Numbering Authority (CNA) submission early reduces the time-to-disclosure when the fix lands.
Sylvan Assurance — First 4 Hours Incident Triage
Prepared for: · Date:
Free Edition snapshot · scored entirely in the browser — answers never leave the device
Your Triage Result
0/ 32
—
—
Phase Breakdown
Triage
0 / 8
Containment
0 / 8
Evidence
0 / 8
Notification
0 / 8
Regulatory Clocks That May Be Running
Things to Avoid Right Now
Your Recommended Next Actions
Free download
The Two-Page "First 4 Hours" Battle-Card
A printable, laminate-on-the-wall checklist of the first-hour moves and the actions to avoid — one side for an infrastructure incident, the other for a vulnerability disclosure. Enter your email and we'll send it over.
Optional, and separate from your assessment — your assessment answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
The Free Triage Shows Where You Stand. The Paid Editions Tell You What to Do Next.
Each paid edition adds the runbook, the pre-filled templates, and the toolkit appropriate to your situation — so you have the documents in front of you, not just the score.
Tier 1
Solo
$49
The Battle-Card plus a basic first-hour runbook — for single practitioners and founders.