Lesson 5.6

5.6: The Incident Decision Log

5 minutes

The Incident Decision Log + Regulator Matrix

The template this module has been pointing at. It’s one printable page in three parts, and it’s designed to be filled out in two sittings: the calm-day half now, and the incident half never, hopefully.

The three parts

Part 1 — The calm-day page. Counsel’s number, broker’s number, policy number, panel firms, break-glass contacts, and your pre-decided defaults (update cadence, ransom posture, who can declare an incident over). Lesson 5.2 argued this page is most of the module operationalized; fill it out this week, print two copies, and keep one somewhere a ransomware event can’t encrypt.

Part 2 — The regulator matrix. The notification table from lesson 5.2 with an owner column: SEC materiality, state AGs, GDPR, sector rules, insurer notice, customer MSA clauses. The matrix isn’t for you to memorize — it’s for you to hand to counsel in hour one and say “confirm the clocks.”

Part 3 — The decision log. One row per leader-decision: time, decision, decided by, alternatives considered, what was known at the time, approver. This is the artifact that answers “who knew what, when” — for the regulator, the insurer, the board, and the postmortem. Write entries during the incident, in the moment, in plain language. A decision log reconstructed afterward is a different document with a different name: a story.

Why the log matters more than it looks

Run the Friday 4:47 PM scenario again and notice: every terminal state references what was written down. The disciplined ending is defensible because the refusal reasoning was logged. The Sullivan ending is a felony largely because the record showed concealment. Regulators and courts don’t expect perfect decisions under uncertainty — they expect honest, contemporaneous ones. The log is how honesty gets a timestamp.

That’s Module 5. Modules 6 through 9 — AI governance, risk prioritization, your first hire, and awareness that isn’t theater — are coming next.