Readiness before the incident
Cyber incidents create immediate operational, legal, regulatory and reputational decisions. The worst time to decide who has authority, whom to call or which notification regime applies is after the incident has already started.
Use this checklist to assess whether your organisation has a documented, owned and practically usable response process.
The objective is not perfect cybersecurity. It is to reduce dependency on improvisation when time, information and management attention are under pressure.
What the checklist covers
- Incident governance and ownership
- Escalation and first response
- GDPR and cyber regulatory assessment
- Cyber insurance and third-party notifications
- Ransomware, BEC and other scenario playbooks
- Recovery and business continuity
- Board reporting and post-incident learning