How Cyber Crisis Desk works

During an incident the hardest part is not knowing what to do next. Cyber Crisis Desk turns a messy situation into one ordered workflow: triage what happened, follow a playbook built for that incident type, keep the evidence in one place, and finish with reports you can actually hand to a bank, provider, insurer or authority.

Everything below is the workflow as implemented in the product today — no roadmap promises.

1. Emergency triage

The entry point is a short structured triage. You tell us the incident type, whether you still have access to the affected account or system, whether money or payments are involved, and whether other people's data may be affected.

Triage is free and does not require a subscription. Your answers are held in the browser while you complete the wizard and become a private case when you save it.

2. Playbook selection

Your answers select a versioned crisis playbook — mailbox compromise, business email compromise, website compromise, phishing, malware, ransomware, data-breach concern, financial fraud and others. Selection is deterministic: the same answers always produce the same playbook and severity, so the response is repeatable rather than improvised.

Playbooks are versioned. If your triage answers change materially, the plan can be re-materialised without losing the progress you have already recorded.

3. Immediate Rescue Plan

The selected playbook produces an Immediate Rescue Plan grouped by time bucket — what to do now, within the first hours, and in the following days. Each item states the action, why it matters, and what “done” looks like.

4. Client Next Action

A long list is still overwhelming under pressure, so the case shows a single Client Next Action: the one step that matters most right now, based on priority, dependencies and what is already complete. Finish it, and the next one appears.

5. Evidence

Evidence requests tell you precisely what to capture — sign-in logs, mailbox rules, message headers, transaction references, server logs, screenshots — and why each item is useful. Uploads are stored in private storage attached to your case, visible to you and to the reviewing specialist only.

  • Each request has a status, so nothing is silently outstanding.
  • Reviewed evidence is marked, with notes where clarification is needed.
  • Nothing from a case is ever published or indexed.

6. Recovery operations

Recovery is tracked, not assumed. Tracks cover regaining access, hardening authentication, removing attacker persistence, restoring services and handling financial exposure. Each action records who did what and when, and financial items keep amounts attached to the relevant track so the picture stays honest.

7. Findings and reports

Confirmed findings are recorded against the case with the evidence that supports them. From those, the platform generates structured documents: an incident summary, a recovery pack and, where relevant, a technical report. They are prepared as PDFs in private storage and shared to you deliberately, not automatically.

Reports are written so a bank fraud team, a provider support desk, an insurer or a national reporting channel can follow them. You remain the person who submits them.

8. Monitoring and closure

An incident is not over the moment access is restored. Monitoring checks cover the follow-up window — re-checking rules and sessions, watching for repeat attempts, and confirming recovery actions held. Closure is blocked until the dependencies pass, and a final Closure Summary records what happened, what was done and what remains recommended.

Subscription versus specialist support

Emergency triage and your rescue plan are free. Paid plans add case capacity, AI-assisted drafting for the reviewing specialist, monitoring and closure, technical reports and secure messaging with a specialist. A one-time Emergency Pass covers a single incident without a subscription.

Full details are on the Cyber Crisis Desk pricing page.

Defensive-use boundary

Cyber Crisis Desk supports defensive incident response only. It does not perform hack-back or retaliation, does not trace or identify attackers, and does not access systems without authority. You confirm you are authorised to act on the accounts and systems in your case.

It is not a law-enforcement, legal or forensic service, does not provide legal advice, and does not guarantee recovery of data, access or money. For severe, regulated or contested incidents you should also engage a qualified incident-response team. The Terms of Service set the boundary out in full.

Common questions

Do I need an account to get a plan?
You can complete triage without an account. Saving the case, uploading evidence and receiving reports require an account so your data stays private to you.
Is my case data visible to anyone else?
No. Case data sits behind authentication and row-level security, files sit in private storage, and reports are shared explicitly. Nothing from a case appears on public pages.
What if my situation does not match a playbook exactly?
Choose the closest incident type. Playbooks cover the common containment and evidence steps, and a specialist can adjust the plan and request the specific evidence your situation needs.
Can you speak to my bank or provider for me?
No. Only you or an authorised administrator can act on your accounts. We prepare the structured information so those conversations are short and specific.

Incident help

Start where it matters

Triage takes a couple of minutes and costs nothing.