A few minutes of structured triage for the first hours of a real incident. It helps you avoid the costly first-hour mistakes that make a bad day worse. Two paths: infrastructure incident, or product vulnerability. Runs in your browser; no email needed.
Triage a live incident — without us ever seeing your answers. Everything stays in your browser. Nothing about your answers is transmitted or tracked.
Two paths. The triage splits into an infrastructure-incident path (ransomware, business email compromise, lost device, vendor breach) and a product-vulnerability path, so the priorities match what you're actually facing.
What you get. A four-hour priority sequence, a do-not-touch list for the first hour, and the regulatory clocks that may apply — drawn from widely recognised incident-response practice.
What it isn't. This is general guidance for a fast-moving situation, not a professional incident-response engagement and not legal advice. Responsibility for your response remains with you.
Version 1 · Updated 2026-07-21
For whoever would pick up the phone at 2am and wants to know what the first four hours look like before they happen.
When you have worked through this, you will have: your free readiness result, and a battle-card printed and on the wall. Download this as a PDF.
When you outgrow the free tier, the Solo toolkit turns the battle-card into a worked first response — the triage runbook, the decision log, and the communication templates — with a Start here catalog to sequence them. See the Solo, Commander and PSIRT CRA-Ready editions →
Everything behind this free assessment — the working documents, templates, runbooks, and depth to put it into practice. Three editions to fit how you work.
See the full toolkit & pricing →One-time purchase · files you own forever · 30-day money-back guarantee.