WAR ROOM

When it's SEV-1,
everyone's in here.

A major incident spins up a war room in seconds — roster paged, roles assigned, one shared timeline. Decisions, actions, and comms in a single place that writes its own report.

SEV-1INC-0912 · ransomware00:14:32
ON THE BRIDGE · 6
MR
IC
JL
FORENSICS
AP
COMMS
DK
LEGAL
+2
ENG
DECISION LOG
11:02MR declared SEV-1 · roster paged
11:06JL isolated 14 hosts · snapshots taken
11:14DK regulator clock started · 72h
THE BOARD · LIVE SITUATIONAL PICTURE
SEV-1INC-0912 · ransomware · acme-prodELAPSED 00:14:32
CONTAINMENT
68%
IMPACT
14
HOSTS ISOLATED
3
ACCOUNTS LOCKED
0
CONFIRMED EXFIL
71:46
REG CLOCK · H:M
OBJECTIVES
Contain ransomware spreadDONE
Preserve forensic imagesDONE
Revoke compromised identitiesDONE
Restore from clean backupIN PROGRESS
LIVE FEEDAUTO-LOGGED
11:02MR declared SEV-1 · roster paged
11:04system auto-isolated 9 hosts on detection
11:06JL captured memory + disk images
11:09AP drafted customer holding statement
11:14DK started 72h regulator clock
11:18MR approved ring-fenced backup restore
HOW IT WORKS

Coordination, without the chaos.

01
Convene

A SEV-1 auto-spins the room, pages the roster, and opens the bridge.

02
Align

Roles, objectives, and one shared timeline keep everyone on the same page.

03
Act

Run containment from the room; every decision is logged as it's made.

04
Debrief

The timeline becomes the post-incident report, ready for review.

IN THE ROOM

A single source of truth, live.

Live roster

Roles paged and tracked — IC, forensics, comms, legal, engineering.

Synced timeline

Detections, actions, and decisions on one clock everyone shares.

Comms bridge

Chat, video, and your tooling joined to the incident, not scattered.

Exec rollup

A live status the board can read without interrupting the responders.

AFTER-ACTION

The timeline already wrote the report.

When the room closes, the record is the report — metrics, root cause, and lessons drafted from what actually happened, ready for the board and the regulator.

AFTER-ACTION REPORT · INC-0912DRAFT GENERATED · 2m AFTER CLOSE
RESPONSE METRICS
4m
MTTD
42m
MTTC
3h18
MTTR
ROOT CAUSE

Phished MFA token replayed from new infrastructure; lateral spread via an over-permissioned service account.

Exported · PDF + regulator pack · SHA-256 sealed
REPORT CONTENTS · AUTO-DRAFTED
Executive summary
Timeline of events47 ENTRIES
Impact assessment
Remediation actions
Lessons → playbook updatesREVIEW
// WAR ROOM

When it's SEV-1,
everyone's in here.

A major incident spins up a war room in seconds — roster paged, roles assigned, one shared timeline. Decisions, actions, and comms in a single place that writes its own report.

SEV-1INC-0912 · ransomware00:14:32
ON THE BRIDGE · 6
MR
IC
JL
FORENSICS
AP
COMMS
DK
LEGAL
+2
ENG
DECISION LOG
11:02MR declared SEV-1 · roster paged
11:06JL isolated 14 hosts · snapshots taken
11:14DK regulator clock started · 72h
// THE BOARD · LIVE SITUATIONAL PICTURE
SEV-1INC-0912 · ransomware · acme-prodELAPSED 00:14:32
CONTAINMENT
68%
IMPACT
14
HOSTS ISOLATED
3
ACCOUNTS LOCKED
0
CONFIRMED EXFIL
71:46
REG CLOCK · H:M
OBJECTIVES
Contain ransomware spreadDONE
Preserve forensic imagesDONE
Revoke compromised identitiesDONE
Restore from clean backupIN PROGRESS
LIVE FEEDAUTO-LOGGED
11:02MR declared SEV-1 · roster paged
11:04system auto-isolated 9 hosts on detection
11:06JL captured memory + disk images
11:09AP drafted customer holding statement
11:14DK started 72h regulator clock
11:18MR approved ring-fenced backup restore
// HOW IT WORKS

Coordination, without the chaos.

01
Convene

A SEV-1 auto-spins the room, pages the roster, and opens the bridge.

02
Align

Roles, objectives, and one shared timeline keep everyone on the same page.

03
Act

Run containment from the room; every decision is logged as it's made.

04
Debrief

The timeline becomes the post-incident report, ready for review.

// IN THE ROOM

A single source of truth, live.

Live roster

Roles paged and tracked — IC, forensics, comms, legal, engineering.

Synced timeline

Detections, actions, and decisions on one clock everyone shares.

Comms bridge

Chat, video, and your tooling joined to the incident, not scattered.

Exec rollup

A live status the board can read without interrupting the responders.

// AFTER-ACTION

The timeline already wrote the report.

When the room closes, the record is the report — metrics, root cause, and lessons drafted from what actually happened, ready for the board and the regulator.

AFTER-ACTION REPORT · INC-0912DRAFT GENERATED · 2m AFTER CLOSE
RESPONSE METRICS
4m
MTTD
42m
MTTC
3h18
MTTR
ROOT CAUSE

Phished MFA token replayed from new infrastructure; lateral spread via an over-permissioned service account.

Exported · PDF + regulator pack · SHA-256 sealed
REPORT CONTENTS · AUTO-DRAFTED
Executive summary
Timeline of events47 ENTRIES
Impact assessment
Remediation actions
Lessons → playbook updatesREVIEW