defencia/knowledge/emergency management
Capabilities · Triage · Overview

Emergency Management

Handling bad situations starts with knowing your own capabilities and aligning expectations with management — then preparing for the worst and creating a clear overview.

TriageReadiness

Know your capabilities

One of the most important first steps is to know your capabilities and align expectations with management. Some tasks — forensics, malware reverse engineering — need special, expensive skills that many organisations choose to hire in.

Even without those capabilities, you can almost always perform a triage: an introductory investigation over a set window (e.g. 2–4 hours) before handing off to a third party. You can still answer a lot of questions in that time.

Prepare for the worst

Create an overview

Should authorities/Police be contacted? If so, get them on board early — in Denmark you can request an IT contact from NC3, present in every police district.