Incident Response
Regulated environments where trust, compliance, and operational resilience are non-negotiable.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Outcome Discovery
Align on threat scenarios, regulatory obligations, stakeholders, and the success signals the buyer needs during an incident.
Discovery Questions
Quick check: how your leadership sees this right now
- How concerned is your board about your institution's ability to execute a coordinated breach response right now?
- When was the last time your team declared a security incident that required external counsel or a forensics partner?
- Who on your executive team would be expected to brief the audit committee after a high-impact breach?
- Describe the single fallout from a recent peer incident that makes your leadership most anxious about your own readiness
- Which of the following outcomes would make your board demand immediate retainer activation?
- Would having a named, on-call incident coach available within two hours change your board's confidence?
Who actually owns the two-hour decision and the hard tradeoffs
- If your team had to activate a retainer at 2 AM on a holiday, which three critical tasks do you expect would still not happen within the first four hours?
- Who currently has authority to sign off on privilege-preserving steps for external investigators, and are backup signers documented?
- Walk me through the escalation path when forensics, privilege concerns, and regulator timelines conflict during an incident
- How many hours of pre-negotiated retainer support does your legal team insist on having guaranteed in writing for a single incident?
- If you could not guarantee chain-of-custody in the first 24 hours, would you still proceed with an external retainer model?
Where response friction actually appears in practice
- Walk me through the last incident you declared, from detection to containment, and tell me which step took the longest to reach resolution
- List the tools and platforms your responders must access during an investigation and who controls those credentials
- Are there contracts, change controls, or vendor approvals that routinely delay evidence collection or device imaging?
- Estimate how long it takes to begin forensic imaging on a critical server or endpoint after you authorize it
- Would you prioritize changing vendor terms to guarantee timely log access before signing a retainer?
Regulatory and legal fault lines you cannot ignore
- What single regulatory outcome would force public disclosure or escalation within 24 to 72 hours for your institution?
- List the regulators and mandatory timelines your team must meet for a material incident
- Tell me which member of your legal team has previously briefed regulators during an incident and what evidence they required first
- Describe the privilege-preserving retainer structure your counsel prefers and any red lines we must avoid
- Does your current privilege arrangement prevent disclosure without a court order if regulators request immediate access to forensic images?
Who else you are weighing and what would keep you with them
- What would have to be true about your current provider or in-house setup for you to decide not to change providers?
- Please name the internal teams, incumbent firms, or alternative models you are currently evaluating
- Estimate the likelihood that leadership will push for an internal do-it-yourself approach instead of an external retainer
- Identify the highest-risk gap in each alternative that would stop you from choosing it
- Practically speaking, which procurement or approval steps must clear before you could sign a retainer?
Can you operationalize this quickly, or will practical constraints block it
- When your incident response plan is executed in reality, what single dependency usually fails and blocks activation?
- Name the systems, APIs, and cloud tenants we must integrate with during the first engagement session
- Are there service agreements, change control windows, or legal approvals that will prevent remote evidence collection without 48 hours notice?
- Identify the role responsible for credentialing forensic collection tools and providing emergency access within two hours
- Quantify the headcount and technical skillset you can dedicate to a single high-priority incident for the first 30 days
- Does lack of pre-authorized access to cloud logs disqualify the engagement under your legal requirements?
How you will judge success and when you will move to the next step
- Provide the three measurable signals you would present to the board within 72 hours to show the incident response succeeded
- Name the stakeholders who must sign off on successful evidence preservation for you to consider the retainer effective
- Within what cadence do you prefer scheduled readiness drills after activation to maintain confidence?
- Explain the governance step that most reliably speeds remediation when a post-incident review surfaces a procedural gap
- Should the first live exercise fail to preserve chain-of-custody evidence, do you expect to pause the retainer and require renegotiation?
-
Response Experience
Walk through the incident response lifecycle in the buyer's context, mapping roles, communications, and evidence-preservation steps across realistic breach scenarios.
Solution Experience
- Response Experience Walkthrough
- Confirm the current state and its cost
- You confirm the mapped roles and timelines eliminate the ambiguity that currently causes duplicated or delayed actions during incidents.
- Deliver a tailored incident timeline that maps named roles, escalation phone trees, and two-hour activation checkpoints for your environment.
- You agree that the demonstrated evidence-preservation steps meet your legal team's expectations for chain-of-custody and privilege protection.
- Scenario walkthrough — payment/settlement system compromise
- Share a draft privileged-retainer clause that preserves attorney-client privilege over forensic findings and outlines activation triggers.
- You accept the two-hour activation expectation and identify any remaining barriers to approving a privileged retainer for board presentation.
- Scenario walkthrough — ransomware affecting endpoints and backups
- Provide the current list of legal and SOC contacts, and the top 10 critical assets to include in the tailored timeline and evidence-preservation plan.
- Evidence preservation and communications choreography
- Confirm whether a brief orientation of the end-to-end retainer lifecycle is required at the session start for any attendees unfamiliar with this engagement model.
- Validation: confirm this maps to your needs
- Response Experience Walkthrough
- Response Experience Deck
- Response Experience Solution Brief
- meeting
- slides
- document
-
Tabletop Exercises
Run structured simulations with legal, security, and executive stakeholders to surface timing gaps, escalation paths, and regulatory communication triggers.
Exercise Sessions
- Exercise Kickoff and Scenario Selection
- Detection to Escalation Tabletop
- Legal Privilege and Regulatory Notification Drill
- Executive Communication and Press Coordination Tabletop
- After-Action Review and Playbook Update Decision
- A clear sign-off path and timing requirements for any public statement or press engagement.
- Recap scenario facts and legal posture assumptions
- A decision tree that defines when to assert attorney-client privilege and when to commence regulator notification.
- A documented evidence handling protocol that preserves chain of custody and privilege assertions.
- Publish the privilege decision tree and the regulator notification triggers derived from the drill.
- Produce an evidence handling checklist aligned to privilege assertions and chain-of-custody requirements.
- Set objectives for executive and board communications
- A scripted executive briefing for the first 72 hours with explicit escalation decision points.
- Confirm scope and rules of engagement
- Produce the 72-hour executive briefing script with placeholders for case-specific facts.
- Document the sign-off steps and timing for public statements and regulator disclosures.
- Present consolidated findings and gap list
- An approved exercise report that consolidates findings and prioritizes playbook updates and remediations.
- A timeline and verification plan for each prioritized remediation and a schedule for recurring exercises.
- Publish the final exercise report with prioritized playbook changes and remediation timelines.
- Schedule the next tabletop exercise and define the readiness metrics to be tracked before that exercise.
- A ratified list of 1 to 3 scenarios to exercise with a brief rationale for each.
- Documented rules of engagement that define what will be simulated and what is out of scope.
- Defined success criteria and explicit decision gates for each selected scenario.
- Publish the final exercise scope, selected scenarios, rules of engagement, and participant list.
- Distribute scenario scripts and timelines to participants for prework and review.
- State the scenario and baseline assumptions
- A documented minute-by-minute incident timeline for the exercised scenario with annotated timing gaps.
- A ratified escalation path with clear thresholds that will trigger retainer activation and executive notification.
- Record and distribute the annotated incident timeline with identified timing gaps.
- Update the retainer activation checklist with confirmed escalation thresholds.
- Walkthrough detection, triage, and escalation steps
- Prioritize remediation and playbook changes
- Walk through the 72-hour executive notification timeline
- Select and prioritize scenarios
- Run decision drills at key timeline points
- Identify timing gaps and bottlenecks
- Map evidence preservation steps that preserve privilege and chain of custody
- Define success criteria and decision gates
- Decide owners, timelines, and verification steps
- Simulate external communications and press statement approvals
- Confirm recurring exercise schedule and readiness metrics
- Confirm participants, roles, and logistics
- Validate regulator notification ladder and template needs
- Confirm escalation thresholds and interim communications
- Confirm readiness criteria for public statements
-
Retainer Scope
Define retainer coverage: guaranteed response SLAs, forensic depth across endpoint/network/cloud, included modules, out-of-scope items, and regulatory support levels.
Scope Configuration
- Rapid retainer response activation
- Endpoint forensic imaging
- Network traffic capture and analysis
- Cloud environment forensics
- Malware and threat artifact analysis
- Live incident containment and isolation
- Threat eradication and host remediation
- Chain-of-custody evidence packaging
- Suspicious Activity Report (SAR) support
- Regulatory notification and disclosure coordination
- Legal-privilege evidence segregation
- Expert witness and litigation support
Scope Questions
Rapid retainer response activation
- After you declare a security event, what guaranteed response SLA (minutes) must we commit to for on-call acknowledgement and initial arrival to remote triage?
- Who on your incident response decision team is authorized to activate the retainer and declare a formal incident for escalation (example: your general counsel, CISO, or head of operations)?
- Which communication channels are pre-approved for immediate activation (examples: encrypted call bridge, SOC secure chat, designated escalation phone tree)?
- How many concurrent incident activations can you tolerate before you require confirmation of provider capacity (to account for vendor handling multiple customers)?
- List any blackout windows or restricted operational periods when we should not initiate remote imaging or in-person work without executive sign-off (example: board meetings, end-of-day clearing windows).
- Specify the pre-authorized access level we have after activation (examples: read-only access to SIEM and logs, remote forensic imaging, console access to production payment switch).
Endpoint forensic imaging
- Which endpoint classes require forensic imaging in-scope (examples: workstation endpoints, Windows domain controllers, Linux payment switch hosts, virtual machine images in hypervisor pools)?
- How many endpoints do you expect to require full disk imaging in a single incident (approximate count)?
- Identify your current endpoint detection and response (EDR) coverage status and vendor-agnostic footprint so we can plan imaging methods (examples: EDR installed on 95% of endpoints, selective coverage on branch teller PCs).
- Specify whether volatile memory (RAM) capture is required by your legal or investigative standards for compromised servers involved in payment processing or SWIFT hosts.
- Describe the preferred forensic image format and hashing standard you require for evidentiary use (examples: E01 with MD5/SHA256, raw dd with SHA256).
- Indicate whether remote forensically-sound imaging is acceptable for branch or remote-office endpoints, or whether physical media collection is required for those locations.
Network traffic capture and analysis
- Which network capture sources are available for in-scope analysis (examples: core switch SPAN/tap, firewall logs, packet capture (PCAP) appliances, virtual private cloud (VPC) flow logs)?
- How many hours or days of raw PCAP retention do you currently have for corporate and payment network segments (examples: 24 hours, 7 days, 30 days)?
- Specify whether we will have read or full access to your Security Information and Event Management (SIEM) and the expected log retention windows for payment switching and core banking events.
- Identify any encrypted links or TLS termination points we should plan to access for decrypted traffic analysis (examples: load balancer TLS offload, reverse proxy, HSM-protected termination).
- Estimate whether live packet capture will risk disrupting clearing and settlement; indicate required approvals or maintenance windows for in-line capture on payment VLANs.
- Provide the name or location of any third-party managed network segments (examples: outsourced datacenter, payment processor cloud segment) we must coordinate with to obtain PCAP or firewall logs.
Cloud environment forensics
- Which cloud environments host in-scope assets (examples: public cloud VPCs hosting payment API, SaaS vendor storing customer PII, private cloud running core ledger)?
- Where are audit trails and control plane logs retained for cloud workloads (examples: CloudTrail or equivalent, object storage access logs, host-level auditd), and what is the retention period?
- Indicate whether we will have console-level access or need to route requests through your cloud provider support to obtain snapshots, instance metadata, and object storage artifacts.
- Specify the number of cloud storage buckets or object containers that may require forensic collection in an incident involving customer PII or payment files.
- Describe any cloud-native identity sources in scope (examples: Azure Active Directory, federated identity providers) and whether access to identity logs is available for correlation.
- Identify whether you require preservation of cloud snapshots as evidence and whether snapshot fees or provider egress costs are the buyer's responsibility.
Malware and threat artifact analysis
- Do you permit malware detonation in an isolated lab for behavioral analysis of samples originating from your environment (examples: payment file malware, ransomware binary)?
- Which sample handling and storage policies must we follow for binary artifacts that may become evidence in regulatory matters or prosecution?
- How should indicators of compromise (IOCs) discovered during analysis be pushed into your detection stack for containment (examples: SIEM IOC feed, EDR IOC blocklist)?
- Specify turnaround expectations for initial malware triage and a written artifact summary for executive and legal review for incidents affecting customer payment data.
- Provide required cryptographic hashing standards for delivered artifacts (examples: SHA256 digest, timestamped hash manifest) when artifacts will be used in regulatory filings or litigation.
- Indicate whether we should coordinate with your malware threat intelligence subscriptions or submit samples to your internal intel team before public disclosure.
Live incident containment and isolation
- Who within your escalation tree has the authority to approve immediate network isolation actions that could impact payment processing or customer-facing systems?
- Which containment techniques are acceptable on production payment systems (examples: network VLAN isolation, host quarantine via EDR, hypervisor snapshot and freeze)?
- When isolating an affected host, do you require prior sign-off from legal counsel before disconnecting systems that are involved in clearing and settlement?
- Estimate acceptable maximum downtime for a single payment switch or clearing node in minutes/hours to guide containment decisions.
- Describe any automated controls that must not be triggered during containment (examples: automatic customer notification, transaction replay, auto-scaling in cloud).
- Identify any secondary systems (examples: reconciliation engines, batch job schedulers) that must be preserved or isolated together with primary hosts.
Threat eradication and host remediation
- Which remediation paths do you prefer for compromised hosts that perform financial clearing (examples: rebuild from golden image, in-place remediation with forensic preservation)?
- How does your change control process handle emergency remediation outside normal maintenance windows for high-risk systems?
- Specify rollback or validation criteria you require after remediation on systems handling customer funds (examples: transaction reconciliation matches, no residual IOC in logs).
- Indicate whether you require us to produce a remediation playbook and runbook for each system class (examples: teller POS, payment gateway, ACH batch server).
- Provide the time window you require for a verified remediation-to-production acceptance test on ledgers or clearing systems before resuming normal processing.
- Identify whether you expect us to perform post-remediation threat-hunting sweeps across identity stores (example: Active Directory) and transaction logs.
Chain-of-custody evidence packaging
- What evidence packaging and transfer acceptance criteria will validate chain of custody for regulatory exams or criminal proceedings (examples: hashed image manifest, sealed evidence bags, timestamped transfer logs)?
- Which hash algorithms and packaging standards do you require for forensic images and logs intended for disclosure to regulators or use in litigation?
- Where should collected evidence be retained after acquisition (examples: customer-controlled secure evidence repository, provider-controlled privileged vault, chained S3 bucket with restricted keys)?
- Specify the handoff procedure and signed documentation you require when physical media or printed logs are transferred between your team and responders.
- Indicate preferred methods for transporting physical evidence across sites for multi-branch incidents (examples: secure courier, tamper-evident packaging, bonded transport).
- Identify any regulatory or internal retention windows that dictate how long images, PCAPs, and log exports must be preserved for potential investigations.
Suspicious Activity Report (SAR) support
- Which thresholds or transaction patterns from your transaction monitoring system should trigger SAR support and evidence collection (examples: large outbound wires, anomalous clearing activity, structured deposits)?
- Who in your anti-money laundering (AML) chain must sign off prior to any SAR filing and what documentation do they require from the investigation (examples: forensic timeline, transaction logs)?
- When a SAR is expected, what format and level of technical detail do you require for attachment (examples: CSV of affected transactions, timeline with packet captures, hashed forensic images)?
- Indicate whether we should coordinate directly with your AML counsel and file to the Financial Crimes Enforcement Network (FinCEN) on your behalf if requested.
- Describe any internal SAR escalation timelines you must meet once a potential reportable incident is identified (examples: initial AML review within 24 hours).
- Identify whether historic transactional reconstitution will be required as part of SAR support and the expected lookback window (examples: 30 days, 90 days, 1 year).
Regulatory notification and disclosure coordination
- Which regulators must be notified for a material compromise of customer data or payment systems (examples: Office of the Comptroller of the Currency (OCC), Securities and Exchange Commission (SEC), state banking regulator)?
- How soon after evidence of material impact do you require notification drafts to be delivered for counsel approval prior to regulator contact (examples: within 2 hours, same day)?
- Who is authorized to approve regulator notification language on your behalf (example: your general counsel), and which file formats do regulators expect (examples: PDF executive timeline, log extracts)?
- Indicate whether you require us to coordinate regulator briefings (example: prep and attend OCC briefing calls) and whether attendance by your counsel is mandatory.
- List any regulator reporting deadlines or statutory windows that are binding for you in breach events (examples: state breach notification within 30 days, bank regulator immediate notification).
- Specify whether you require a redlines-ready regulator notification template and whether that template must be approved annually by your legal team.
-
Mutual Commit
Finalize commercial and legal terms including engagement activation, privilege-preserving retainer structure, chain-of-custody protocols, and billing triggers.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW) — Retainer Scope
- Retainer Activation & Billing Terms
- Privilege Preservation Addendum
- Chain-of-Custody & Evidence Handling Protocol
- Service Level Agreement (SLA)
- Regulatory & Examiner Support Addendum (Financial Institutions)
- Data Processing Agreement (DPA)
- Expert Witness & Legal Support Addendum
- Mutual Non-Disclosure Agreement (NDA)
-
Deployment
Lock readiness facts and configuration values before execution begins.
-
Onboarding Readiness
Capture concrete operational facts—SOC contacts, legal counsel contacts, escalation phone trees, monitoring access, and evidence custody locations—required before activation.
Pre-Deployment Questions
Environment and access
- Which environments are in-scope for immediate retainer activation? (select all that apply — used to scope access and responder tooling)
- Can the detection/monitoring team grant emergency read-only access to in-scope monitoring, SIEM, and log platforms within two hours of activation? (so we can triage immediately)
- Provide the named owner for each in-scope environment and the team responsible (name and team). (Used to route access requests and approvals.)
Data and evidence custody
- Has the buyer designated a secure evidence custody model for incident artifacts (choose the closest match)?
- Who is authorized to approve chain-of-custody transfers and removal of artifacts from custody during an incident? (name and role)
- Are forensic preservation practices and privilege‑preserving templates pre‑approved by legal for use during a live incident?
People and ownership
- Provide the primary and secondary SOC on‑call contacts for incident activation, including escalation order and preferred contact method (name, role, escalation order).
- Has a single legal point of contact for incident response and privilege decisions been named?
- List the executives authorized to declare retainer activation and the escalation order (e.g., CISO, GC, CRO). (name and role)
Timing and constraints
- Are there blackout windows, regulatory moratoria, or operational constraints that would delay seller mobilization? (select the closest answer — specific dates go in deployment config)
-
Operational Configuration
Lock exact configuration values the response team will use—forensic imaging settings, collector endpoints, secure evidence storage details, notification templates, and escalation thresholds.
Configuration Details
Operational Configuration — Locking the Values We Will Use
- Enter the canonical name for this production environment (format: single token, e.g., prod-us-east). Default: prod
- Select the primary geographic region where incident response activities and data handling will be performed (this drives routing and legal considerations)
- Enter the primary operational timezone to use for all timestamps (format: IANA TZ name or common abbreviation). Default: UTC
- Enter the single point-of-contact role that will be considered Incident Commander for activation events (format: Role — Example: CISO)
- Enter the name and role of the specific individual who will act as the Incident Commander for this configuration (format: Full Name — Role)
- Default working hours for non-executive escalations (format: HH:MM-HH:MM, timezone is the value above). Default: 08:00-18:00
Forensic Imaging & Collection — Exact Tooling and Formats
- Forensic disk image format to use by default for endpoint imaging (choose one). Default: E01 (forensic container)
- If you selected Custom above, enter the exact custom image format identifier (leave blank if not Custom)
- Hash algorithm to generate image/verifier hashes (choose one). Default: SHA256
- If you selected Other for hash algorithm, enter the exact algorithm name (leave blank if not Other)
- Is memory (RAM) acquisition required as part of the default imaging workflow? Default: Yes
- If memory acquisition is required, enter the memory acquisition tool identifier or method name to use (do not provide a secret)
- Should imaging use a write-blocker by default for physical drives? Default: Yes
- Maximum acceptable time from acceptance of activation to start of forensic imaging (hours). Default: 2
Collectors & Endpoints — Where and How We Pull Data
- Enter the primary collector endpoint URL or hostname used for automated artifact collection (format: https://... or host.example.local)
- Collector authentication method (choose one). Do NOT paste secrets — only select method.
- Enter the identifier for the integration service account or certificate name used by the collector (format: service_account_name or cert_name). Do NOT paste credentials
- Enter the owner (Name — Role) responsible for the collector credential identified above (who will provide the secret at kickoff)
- Which secure channel will you use to transfer collector secrets at deployment kickoff (choose one)
- If you selected other for secure channel above, enter the exact channel name or procedure (leave blank if not applicable)
- Enter the network egress endpoint (IP or CIDR) the collector is allowed to reach for evidence upload (format: IP or CIDR). If multiple, provide the primary value only
Evidence Storage & Retention — Exact Locations and Limits
- Primary evidence storage endpoint (enter S3-compatible URL, bucket name, or UNC path exactly as it will be configured). Example: s3://ir-evidence-prod or \\fileserver\evidence
- Is encryption at rest required for evidence storage? Default: Yes
- Default evidence retention period in days (Default: 365)
- Maximum allowed evidence volume per incident (GB). Default: 500
- Evidence transfer method (choose one). This determines how collected artifacts reach the storage endpoint
- If you selected Other above, enter the exact transfer method name or procedure (leave blank if not applicable)
- Enter the designated evidence custodian (format: Full Name — Role). This person signs chain-of-custody custody transfers
Chain-of-Custody & Logging — Verifiable Records
- Persistent identifier field name to use as the canonical incident ID across systems (enter exact field name). Example: incident_id
- Where will chain-of-custody records be stored (enter exact system name or URL — e.g., ticket-system-name or https://host.example/coc)
- Hash algorithm to record for chain-of-custody verification (choose one). Default: SHA256
- If you selected Other for chain-of-custody hash algorithm, enter the algorithm name (leave blank if not applicable)
- Role that will sign chain-of-custody entries by default (choose one)
- If Other above, enter the exact role that will sign entries (leave blank if not applicable)
Notification Templates & Required Fields — What Alerts Contain
- Enter the exact identifier or name of the initial incident activation notification template to use (format: template_name or template_id)
- Primary notification channel for initial activation (choose one)
- Primary recipient role for the initial activation notification (choose one)
- If you selected Other for primary recipient, enter exact role name (leave blank if not applicable)
- Select which minimum data fields MUST be present in the initial notification (multi-select allowed)
- Enter the exact subject-line template for automated notifications (use placeholders {incident_id}, {severity}, {timestamp} as needed). Example: "IR Activation — {incident_id} — {severity}"
- Enter the exact filename prefix convention for evidence exports (single token, e.g., ir_{incident_id})
Escalation Thresholds & SLA Numbers — Numerical Limits We Enforce
- Activation SLA — guaranteed maximum minutes from buyer activation to seller onboarding start. Default: 120
- Time from activation to first forensic imaging start (hours). Default: 2
- Time-to-first-technical-report (hours). Default: 8
- Executive notification escalation threshold (minutes after activation). Default: 180
- Maximum allowed concurrent incidents under this retainer configuration (numeric). Default: 1
- If the maximum concurrent incidents above is exceeded, select the default escalation action (choose one)
- If Other, enter the exact escalation action text (leave blank if not applicable)
Access & Integration Points — Exact Identifiers
- Enter the exact field name in your SIEM that will be used as the canonical incident identifier (do not provide examples — enter exact field)
- Monitoring access method to provide to the seller (choose one)
- If you selected an API or integration above, enter the integration identifier (service account name, dashboard ID, or bucket name). Do NOT paste credentials
- Enter the owner (Name — Role) who will approve integration access requests for the identifier above
- Identity provider type for any SSO/token flows (choose one)
- If SSO/IdP is used, enter the entity ID or issuer URL exactly as it should be configured (format: https://... or entity-id). Leave blank if not applicable
Operational Runbook Values — Names, Templates, and Trees
- Incident Commander (exact: Full Name — Role). This person will be named in runbooks and notifications
- Primary legal contact for privilege questions (exact: Full Name — Role)
- Enter the escalation phone-tree order as a single comma-separated string of roles (highest priority first). Example: CISO, General Counsel, Head of Ops
- Enter the exact evidence labeling convention string (use {incident_id} placeholder). Example: {incident_id}_device_hostname_timestamp
- Runbook playbook owner (Name — Role) who will be assigned recurring readiness checks
- Enter the cadence in days for recurring readiness checks once activated (numeric). Default: 90
-
Retainer Activation & Exercises
Execute onboarding tasks, run a live rehearsal or activation drill, schedule recurring readiness checks, and assign named owners for playbook execution.
-
-
Success
Validate operational readiness through recurring reviews, capture lessons from incidents and exercises, and maintain a shared tracker for issues and enhancement requests.
Success Reviews
- Go-live Health Check (Week 1-4)
- First Measurement Review (Weeks 4-10)
- Acceptance Gate, Operational Readiness Decision (Day 90)
- Quarterly Operational Review
- Annual Lessons and Continuous Improvement Review
Issues & Enhancements
- Ensure the top three tracker items are assigned target close dates and a verification step scheduled.
- Deliver a metric reconciliation package showing raw logs and calculation methodology for each reported metric.
- Add remediation tasks to the shared tracker with target completion dates ahead of the Acceptance Gate.
- Restate the acceptance criteria and numeric targets
- Produce a documented acceptance decision with pass/fail per acceptance criterion recorded in Retainer Scope and Mutual Commit.
- List remediation items for any failed criteria with clear owners and completion dates to remove conditional acceptance.
- Publish the signed acceptance statement and the acceptance evidence packet to the shared workspace.
- Add remediation exceptions to the tracker and schedule follow-up verification on or before the agreed completion dates.
- Quarterly performance trends
- Confirm that quarterly performance on the named metrics is documented against Retainer Scope targets and that outliers have remediation plans.
- Re-confirm deployment scope and owners
- Update the shared tracker with quarter-end metric exports and attach incident evidence summaries for any activations reviewed.
- Schedule required training or configuration updates and document expected impact on the named metrics.
- Year-to-date performance summary
- Agree a prioritized annual improvement plan that addresses recurring failure modes and is tied to measurable metric improvements.
- Designate the continuous improvement owner and a quarterly check-in schedule to monitor progress on the annual plan.
- Publish the annual performance and lessons report, including the prioritized enhancement plan and expected metric impact.
- Add approved enhancement items to the shared tracker with estimated completion windows and verification criteria.
- Confirm that all critical deployment artifacts listed in Onboarding Readiness and Operational Configuration are present and accessible.
- Produce a short list of open issues with owners and target resolution dates before the next review.
- Publish a deployment verification checklist with status and owners for each item.
- Schedule a follow-up verification within two weeks to confirm remediation actions completed.
- Present first-period performance data
- Document where each named metric stands relative to the numeric targets recorded in Retainer Scope and Mutual Commit.
- Agree a timebound remediation plan for each metric that is not meeting target, with owners and dates.
- Validate deployment artifacts
- Present consolidated outcomes
- Diagnose gaps and root causes
- Consolidated lessons from incidents and exercises
- Review incidents and exercise lessons
- Document pass or fail per criterion
- Open issues tracker and enhancement backlog
- Agree corrective actions and ownership
- Review early adoption and usage signals
- Prioritize enhancement requests and backlog
- Capture formal acceptance decision and signatory
- Confirm readiness for Acceptance Gate
- Agree short-term operational adjustments
- Surface open issues and blockers
- Confirm continuous improvement cadence and owners
- Agree immediate remediation actions
- Agree remediation items and resolution timeline