Skip to main content

The Art of CTO Incident Response Planner scores incident response readiness across eight NIST-aligned phases — preparation, detection and analysis, containment, eradication and recovery, communication and reporting, post-incident activities, testing and exercises, and scenario playbooks — returning a maturity score with prioritised gaps.

Are we ready to respond when it breaks?

A response maturity score across preparation, playbooks and post-incident review.

About 15 min · Assessment · Free

About this toolWhy it matters, common mistakes, FAQ

Are You Ready For The Next One?

Response capability is fixed before the incident starts. Whatever is not decided in advance — who declares, who communicates, who can authorize a rollback — gets decided badly, under pressure, by whoever is awake.

Plans document escalation paths and stop there. The parts that fail in practice are the human ones: nobody wants to declare, so declaration is late, and everything downstream inherits the delay.

Questions CTOs ask

What should an incident response plan include?
A comprehensive incident response plan defines roles (incident commander, communications lead, technical lead), severity classification criteria, escalation paths for each severity level, communication templates (internal status updates, customer notifications, executive briefings), technical runbooks for common failure modes, and a post-incident review process. The plan should be accessible during outages (not hosted on the systems that might be down) and rehearsed quarterly through tabletop exercises or game days.
What is the incident commander role?
The incident commander (IC) is the single point of coordination during an incident. They do not fix the problem themselves — instead, they manage the response by declaring severity, assembling the right responders, maintaining the incident timeline, coordinating communication, making escalation decisions, and ensuring nothing falls through the cracks. Rotate the IC role across senior engineers to build organizational resilience. Train ICs through shadowing, tabletop exercises, and formalized incident management courses like those offered by PagerDuty or Google.

Related Reading