NEW · AI-DETECTED INCIDENT RUNBOOK
A crisis response plan, when the AI says you need one.
During council processing, the AI evaluates whether your mission warrants an incident runbook. If it does, you're prompted on Tactical Plan open to accept — and a board-ready Crisis Response Plan is attached as a dedicated tab. No manual generation, no noise.
WHAT IT IS
The first hour of an incident, pre-drafted by your AI Council.
Most incidents don't fail on technical response — they fail in the first hour, when severity is unclear, RACI is informal, the regulator clock is ticking and comms drafts don't exist yet. The Crisis Response Plan removes that cold start.
When a mission involves a live incident, suspected breach, ransomware exposure, data loss or regulator deadline, the AI Council flags the mission during processing. If you accept the prompt on Tactical Plan open, the tailored runbook is generated and attached as its own tab. If the AI does not flag the mission, no manual Crisis Plan can be added.
Every section is a draft to be reviewed with your legal counsel and your cyber insurer's panel counsel before sending — but you start the hour with structure, not a blank page.
WHAT'S INSIDE
Six sections. One runbook. Board-ready.
Each plan is generated for the specific decision in front of you — severity, blast radius and obligations are tailored to the mission context.
Severity snapshot
Severity rating, blast radius and headline impact summary so leadership can triage in seconds.
First 60 minutes
Sequenced actions for the first hour — containment, evidence preservation, escalation triggers.
RACI & stakeholder matrix
Who is Responsible, Accountable, Consulted and Informed — across security, legal, exec, board, comms and third parties.
Regulator notifications
Draft notifications keyed to Australian obligations — OAIC, ACSC, APRA, ASIC — with timing thresholds.
Comms templates
Internal all-staff, customer notice, media holding statement and board update drafts ready to adapt.
Do / don't & printable checklist
Decision guardrails plus a one-page printable action checklist your team can work off offline.
TRY IT NOW
Bring one scenario. Get a runbook in minutes.
Free to use. Run a mission and, when the AI flags it, accept the Crisis Plan prompt.
WHEN IT TRIGGERS
Suggested when it matters. Never added manually.
Auto-detected
Live incidents, suspected breaches, ransomware exposure, data loss events, third-party compromise, regulator notification windows. The Architect detects these contexts and prompts you to accept or decline a Crisis Response Plan when the Tactical Plan opens.
AI-only — no manual override
Crisis Response Plans cannot be added manually. The AI Council decides eligibility based on mission context. This keeps runbooks focused on the decisions that genuinely warrant one — and avoids cluttering routine missions with incident scaffolding.
Included in print and email exports
When you print or email a Tactical Plan, the Crisis Response Plan goes with it — so the people who need it on the day already have it.
QUESTIONS
FAQ
What is the Crisis Response Plan?
It is an optional incident response runbook that the AI Council attaches to a Tactical Plan when a mission warrants one. It gives you a board-ready playbook covering the first 60 minutes, severity assessment, RACI, regulator notifications, internal and external comms templates, do/don't lists and a printable action checklist.
When does the AI add a Crisis Response Plan automatically?
During council processing the AI evaluates whether a mission warrants a Crisis Response Plan — live incidents, suspected breaches, ransomware exposure, data loss events, regulator deadlines or third-party compromises. If flagged, you are prompted on Tactical Plan open to accept or decline. Crisis Response Plans cannot be added manually — only the AI decides eligibility.
Is the plan tailored to Australian regulators?
Yes. Notification templates and timelines reference Australian obligations — OAIC Notifiable Data Breaches scheme, ASD/ACSC reporting under the SOCI Act for critical infrastructure, APRA CPS 234 for regulated entities, and ASIC for listed entities — so legal and comms have a defensible starting point.
What if the AI does not flag my mission?
Then no Crisis Response Plan is generated. The Crisis Plan tab on your Tactical Plan stays locked with an explanation. You cannot override the AI's decision — this keeps runbooks focused on missions where they genuinely add value.
Can I use it during a real incident?
It's a drafting aid. Treat outputs as drafts to be reviewed with your legal counsel and your cyber insurer's panel counsel before sending. The plan accelerates the first hour and gives your team a structured framework; it does not replace incident response retainers or legal advice.
Is it included in every mission?
There is no extra mission credit when the AI flags and you accept one, but it is not generated for every mission. It appears inside the Tactical Plan view only when the mission includes a Crisis Response Plan.
Run your first mission free.
Two free missions. No credit card. If the AI flags crisis conditions, the runbook prompt appears inside your Tactical Plan.