Skip to content
days until launch · 31 July 2026 ·
Cyber Toolbox
Lifecycle · Incident response

Walk the response. Promote to a case.

Most teams know what to do in an incident — they lose time and make mistakes coordinating it. Cyber Toolbox makes the response auditable and repeatable: every decision has an owner and a timestamp, and the regulator clock is ticking where you can see it.

Browse IR playbooks
The walk, end to end

From playbook to closed case. One record, one audit trail.

  1. P1

    Pick a playbook

    Phishing, BEC, ransomware, account takeover, malware, data exfiltration, insider threat, lateral movement and more — start from a playbook a practitioner wrote for that exact scenario, never a blank page.

  2. P2

    Walk it asset by asset

    Each step is guided — task, decision, evidence, runbook, comms and classification — with dependency locks so you can’t skip a prerequisite. Tier-aware runbooks adapt to the tooling you actually license.

  3. P3

    Promote to a case

    The moment the walk earns it, promote to a managed case: an operational record with a severity engine, asset board, members and SITREPs — coordinated from a Cyber Incident Commander view.

  4. P4

    Decide on the record

    Every consequential decision is logged with an owner and timestamp. High-consequence calls require two-person sign-off. Evidence is hashed with chain-of-custody. Nothing is done off the record.

  5. P5

    Meet the clock, then close

    Regulator declaration obligations and timers sit on screen so the deadline is visible, not a surprise. Walk to closure with the decisions, evidence and timeline assembled into a defensible record.

What you get

The defensible record is the database — not a side-effect.

  • Playbook walker — keyboard-driven, step-by-step, with dependency locks.

  • Promote-to-case the moment a walk earns it — no re-keying.

  • Severity engine and case board with members, SITREPs and folder structure.

  • Decision log with dual control on high-consequence calls.

  • Evidence chain-of-custody — artefacts hashed (SHA-256), collector recorded immutably, every access logged.

  • Regulator declaration obligations and timers, visible the whole way through.

  • Cyber Incident Commander view for coordinating a live response.

Pick a playbook. Walk it. Promote to a case when it earns one.