Platform · Incident Response
Structured command from first alert to lessons learned.
Log and classify incidents, assign a commander, track every action taken and maintain a time-stamped record that satisfies regulators. When it is over, findings flow automatically into Action Hub and the risk register.
Response lifecycle
A structured command process from start to close.
Log and classify
Record the incident, assign severity (critical/high/medium/low), mark reportability under the NDB scheme or Privacy Act, and note whether it has been contained.
Assign a commander
Designate the incident commander who owns the response. All communications, decisions and escalations flow through the commander, with a live record in the platform.
Contain and investigate
Document containment actions, capture forensic evidence, track affected systems and record investigation findings, all time-stamped in an append-only log.
Recover and verify
Log recovery actions and verification steps. The platform tracks each milestone and flags when systems are restored to normal operation.
Close and learn
Complete the post-incident review, link any new risks back to the risk register, and push recovery actions to Action Hub so lessons learned are tracked to completion.
Capabilities
Everything your team needs when it matters most.
AI-drafted response plan
Generate a guided incident response plan with roles, escalation paths, containment procedures, communication requirements and stakeholder contacts. Saved to your policy library.
Tabletop exercises
Schedule structured tabletop exercises via Case Management. Pre-populated 10-step checklists test your team's readiness against specific incident scenarios.
Append-only timeline
Every action, decision and communication is recorded with a timestamp. The immutable log supports NDB scheme reporting, Privacy Act obligations and regulatory review.
Action Hub integration
Incident findings and recovery tasks are pushed directly to Action Hub with the incident linked. Resolve the task, update the incident, from either direction.
Risk register link
When an incident closes, the platform prompts review of related risks. New risks identified during response are added to the register with the incident as evidence.
Severity and reportability
Fields for occurred, detected, acknowledged, contained and resolved timestamps support structured breach notification requirements and insurance reporting.
Regulatory readiness
Notifiable breach reporting built in.
Australian and New Zealand organisations face mandatory breach notification obligations under the Privacy Act and NDB scheme. The platform captures every required timestamp: occurred, detected, acknowledged, contained and resolved, in a format your legal team can use to assess notification obligations without reconstructing the timeline from emails.
- Structured breach timeline with occurred / detected / acknowledged / contained / resolved timestamps
- Reportability flag assessed at incident creation and reviewable throughout response
- Post-incident review documents root cause, lessons learned and remediation steps
- Incident history preserved as auditable evidence for regulatory enquiry
Action Hub integration
Recovery and post-incident remediation actions go straight to Action Hub. Each task links back to the incident. Closing the task updates the incident record.
See Action HubTabletop exercise scheduling
Schedule structured exercises with pre-populated 10-step checklists via Case Management. Test your team's readiness before you need it in a real event.
Know exactly what to do when something goes wrong.
Build your incident response plan, run a tabletop exercise and be ready before an incident happens.

