Module 5: Incident Decision-Making

65 minutes

Module 5: The Hours That Define You

Module 3 taught you how to report an incident upward. This module is about the harder half: the decisions that are yours while the incident is running. Not the containment techniques — your responders own those. The calls only a leader can make: when to engage counsel, when the insurer hears about it, whether anyone talks to the attacker, what the company says in public, and who’s told what, on what clock.

The bad news: you will make these decisions with incomplete information, under time pressure, while people watch. The good news: almost every one of them has been made before, publicly, expensively, by someone whose incident is now caselaw or an 8-K filing. Colonial Pipeline. MGM and Caesars, three weeks apart, facing the same crew with opposite answers. Joe Sullivan, whose decision earned a federal conviction. This module strip-mines their hindsight.

  • Your job during an incident — the decide-vs-delegate line, drawn in advance
  • Regulators, insurers, lawyers — who wants what, on what clock, and why call order matters
  • Ransom decisions — OFAC, restore math, and what payment actually buys
  • Public comms — what not to say, learned from the people who said it

Then the marquee scenario of this course: Friday 4:47 PM — one intrusion, five decisions, from Hour 1 to Day 7. And a printable Incident Decision Log + Regulator Matrix to keep by the fire extinguisher.

What you’ll walk away with

  • A decide/delegate matrix you can circulate to your exec team before anything is on fire
  • The notification clocks — SEC, state AGs, GDPR, your insurer — in one table
  • A ransom-decision framework that doesn’t require you to have an opinion about hackers
  • Practice living with your own calls across a seven-day incident timeline

Time

~65 minutes. Four lessons, one scenario worth rerunning badly on purpose, one template.