Sample — fictitious data for feature preview. Not a real organization.

Incident Response Packet

Pre-built briefing documents for incident responders — generated from your completed assessment, tool inventory, and organization profile. Keep a downloaded copy offline where your response team can reach it.

Included in your bundle Encrypted with your organization key
Organization: Client Company Source assessment: CIS Controls v8.1 — completed 2026-08-14 Last refreshed: 2026-08-25 14:32 (check-in saved)
Reports refresh automatically whenever data that feeds them changes — an assessment save or check-in, a tool inventory update, or an organization profile edit. Your downloaded copy shows its generation date; re-download after significant changes.
Download all (ZIP)

Incident Response Plan

The plan itself — 55 sections for this district, from a 70-section template synthesised from NIST SP 800-61r3, CISA’s response playbooks and IRP Basics, the NCIRP, the SANS handbook and industry readiness guidance. Cover page, contents, part dividers and an appendix citing every source. Sections this district has written are shown alongside ones still to be completed, which is what a plan in progress actually looks like.

Sector-aware · K-12 sections included, other sectors one click away

Responder Brief

The environment snapshot an external responder normally spends days assembling: identity provider, email platform, data types, staffing, and your assessed security capabilities — EDR, logging, MFA, backups — each with the assessment evidence behind it.

Generated 2026-08-25 14:32 · basis: CIS v8.1 check-in #2

Kill-Chain Gap Overlay

Enter the ATT&CK techniques observed in an incident and see how your assessed controls line up against each one — where the attacker likely progressed unopposed, and which containment actions your organization can actually execute today.

Interactive at incident time · sample below uses a ransomware scenario

Tool KEV History

Your tool inventory checked against products with confirmed CISA Known Exploited Vulnerabilities history — a starting list for "what should we look at first" during triage. Tool-level, honestly labeled: it does not know your installed versions.

Generated 2026-08-25 14:32 · basis: 34 inventoried tools

Notification Obligations

The reporting and notification duties your vertical, location, and data types are likely to trigger in a breach — with the deadlines that matter in the first 72 hours. Decision support to bring to counsel, not legal advice.

Generated 2026-08-25 14:32 · basis: organization profile (K-12, Nebraska)

Evidence Bundle Companion ZIP

Every evidence file submitted during the assessment and its check-ins — one folder per control, a clickable index, and a hash-verified manifest. Delivered as a separate download so you can hand responders the reports freely and share raw evidence deliberately. Controls with zero evidence are listed as zero: that absence is information too.

Generated 2026-08-25 14:32 · 11 files across baseline + 2 check-ins

Remediation Crosswalk Coming soon

Post-incident findings mapped through the Common Capability Layer to every framework you care about — remediate once, close the gap in CIS, CMMC, CSF, and your insurance questionnaire at the same time. Arrives with the capability question bank.

Not yet available