Incident Response Packet
Pre-built briefing documents for incident responders — generated from your completed assessment, tool inventory, and organization profile. Keep a downloaded copy offline where your response team can reach it.
Incident Response Plan
The plan itself — 55 sections for this district, from a 70-section template synthesised from NIST SP 800-61r3, CISA’s response playbooks and IRP Basics, the NCIRP, the SANS handbook and industry readiness guidance. Cover page, contents, part dividers and an appendix citing every source. Sections this district has written are shown alongside ones still to be completed, which is what a plan in progress actually looks like.
Sector-aware · K-12 sections included, other sectors one click away
Responder Brief
The environment snapshot an external responder normally spends days assembling: identity provider, email platform, data types, staffing, and your assessed security capabilities — EDR, logging, MFA, backups — each with the assessment evidence behind it.
Generated 2026-08-25 14:32 · basis: CIS v8.1 check-in #2
Kill-Chain Gap Overlay
Enter the ATT&CK techniques observed in an incident and see how your assessed controls line up against each one — where the attacker likely progressed unopposed, and which containment actions your organization can actually execute today.
Interactive at incident time · sample below uses a ransomware scenario
Tool KEV History
Your tool inventory checked against products with confirmed CISA Known Exploited Vulnerabilities history — a starting list for "what should we look at first" during triage. Tool-level, honestly labeled: it does not know your installed versions.
Generated 2026-08-25 14:32 · basis: 34 inventoried tools
Notification Obligations
The reporting and notification duties your vertical, location, and data types are likely to trigger in a breach — with the deadlines that matter in the first 72 hours. Decision support to bring to counsel, not legal advice.
Generated 2026-08-25 14:32 · basis: organization profile (K-12, Nebraska)
Evidence Bundle Companion ZIP
Every evidence file submitted during the assessment and its check-ins — one folder per control, a clickable index, and a hash-verified manifest. Delivered as a separate download so you can hand responders the reports freely and share raw evidence deliberately. Controls with zero evidence are listed as zero: that absence is information too.
Generated 2026-08-25 14:32 · 11 files across baseline + 2 check-ins
Remediation Crosswalk Coming soon
Post-incident findings mapped through the Common Capability Layer to every framework you care about — remediate once, close the gap in CIS, CMMC, CSF, and your insurance questionnaire at the same time. Arrives with the capability question bank.