The Art of CTO Incident Response Planner scores incident response readiness across eight NIST-aligned phases — preparation, detection and analysis, containment, eradication and recovery, communication and reporting, post-incident activities, testing and exercises, and scenario playbooks — returning a maturity score with prioritised gaps.
Are we ready to respond when it breaks?
A response maturity score across preparation, playbooks and post-incident review.
About 15 min · Assessment · Free
About this toolWhy it matters, common mistakes, FAQ
Are You Ready For The Next One?
Response capability is fixed before the incident starts. Whatever is not decided in advance — who declares, who communicates, who can authorize a rollback — gets decided badly, under pressure, by whoever is awake.
Plans document escalation paths and stop there. The parts that fail in practice are the human ones: nobody wants to declare, so declaration is late, and everything downstream inherits the delay.
Questions CTOs ask
- What should an incident response plan include?
- A comprehensive incident response plan defines roles (incident commander, communications lead, technical lead), severity classification criteria, escalation paths for each severity level, communication templates (internal status updates, customer notifications, executive briefings), technical runbooks for common failure modes, and a post-incident review process. The plan should be accessible during outages (not hosted on the systems that might be down) and rehearsed quarterly through tabletop exercises or game days.
- What is the incident commander role?
- The incident commander (IC) is the single point of coordination during an incident. They do not fix the problem themselves — instead, they manage the response by declaring severity, assembling the right responders, maintaining the incident timeline, coordinating communication, making escalation decisions, and ensuring nothing falls through the cracks. Rotate the IC role across senior engineers to build organizational resilience. Train ICs through shadowing, tabletop exercises, and formalized incident management courses like those offered by PagerDuty or Google.
Related Reading
On-Call Rotation Planner Guide: How to Build a Fair, Sustainable Schedule
On-call rotation planner: how to build a fair, sustainable schedule
guidesIncident Severity Classification Tool Guide: SEV Level Definitions That Don’t Collapse Under Pressure
Incident severity classification tool guide: SEV level definitions that don’t collapse under pressure
case-studiesThe Outage
It's 2:14 PM on a Tuesday. Error rates just spiked from 0.2% to 34%. Three enterprise customers are on the phone with your CEO. You have 60 seconds before someone expects an answer.