Field guides
Systems under pressure.
Use them solo. Use them with a team. They work either way.
During
It is happening now. Open the checklist on the call. Tick as you go.
Wire fraud, the first hour A wire has gone to the wrong account. Recovery odds drop sharply after the first 60 minutes. The mailbox is probably still compromised. Move on the bank, not the keyboard. Ransomware, the first hour Ransom notes are visible. The chain that put them there is not. The first hour is decided in the months before it. Contain, preserve, hold the line on irreversible decisions. Account takeover response A privileged account is in someone else's hands. Cut the access, scope what they touched, decide whether the account is salvageable. The cuts are a sequence, not a checklist. Data exfiltration suspected Something looks like it left. Quiet investigation is the discipline. Premature disclosure damages trust if it was wrong. Premature containment tips off the attacker and loses you scope.
Before
Readiness. Drills. Controls. Run these when nothing is on fire.
Ransomware readiness Quarterly readiness walk for executives, defenders, and the people who keep the lights on. Modern ransomware steals first, encrypts maybe, and most damage happens after the first signs were already visible. Wire fraud controls Wire fraud is rarely a technology failure. It is a trust-routing failure inside an organisation. The controls below are for finance, IT, and the executives who keep accidentally being the weakest link. Credential exposure drill Tabletop for the moment you discover a privileged credential is in the wrong hands. Run this with your team before you need it. The drill is where you find out whether your revocation story is real.
After
Recovery. Review. The human side. What you do once it stops moving.
Immediate aftermath (24 to 72h) The incident has stopped moving. The work is not over. Preserve, restore trust, and stabilise the team before anything else. Most second-incidents start here. Post-incident review Blameless review for week one or two. The point is to learn, not to assign. The artefact is a small number of actions that will measurably reduce time-to-detect, time-to-contain, or time-to-decide next time. Operator recovery The system is back. The people are not. This is the part most teams skip. The bill for an incident arrives later than the incident, and it arrives in the people who held the line.
Rehearsal
Produce the behaviour under pressure before reality asks for it.
paged Live
One indicator. Forty-five minutes. Work out what it is, what it
touched, and whether it is still active. Curated scenarios plus a
random mode: wire fraud, kerberoasting, ransomware staging,
insider exfil. Solo or with a team.
paged.breakpointhq.co →
The thinking behind these lives in the observations. If the guide you need is not here, say which one.