Walk the response. Promote to a case.
Most teams know what to do in an incident — they lose time and make mistakes coordinating it. Cyber Toolbox makes the response auditable and repeatable: every decision has an owner and a timestamp, and the regulator clock is ticking where you can see it.
From playbook to closed case. One record, one audit trail.
P1
Pick a playbook
Phishing, BEC, ransomware, account takeover, malware, data exfiltration, insider threat, lateral movement and more — start from a playbook a practitioner wrote for that exact scenario, never a blank page.
P2
Walk it asset by asset
Each step is guided — task, decision, evidence, runbook, comms and classification — with dependency locks so you can’t skip a prerequisite. Tier-aware runbooks adapt to the tooling you actually license.
P3
Promote to a case
The moment the walk earns it, promote to a managed case: an operational record with a severity engine, asset board, members and SITREPs — coordinated from a Cyber Incident Commander view.
P4
Decide on the record
Every consequential decision is logged with an owner and timestamp. High-consequence calls require two-person sign-off. Evidence is hashed with chain-of-custody. Nothing is done off the record.
P5
Meet the clock, then close
Regulator declaration obligations and timers sit on screen so the deadline is visible, not a surprise. Walk to closure with the decisions, evidence and timeline assembled into a defensible record.
The defensible record is the database — not a side-effect.
Playbook walker — keyboard-driven, step-by-step, with dependency locks.
Promote-to-case the moment a walk earns it — no re-keying.
Severity engine and case board with members, SITREPs and folder structure.
Decision log with dual control on high-consequence calls.
Evidence chain-of-custody — artefacts hashed (SHA-256), collector recorded immutably, every access logged.
Regulator declaration obligations and timers, visible the whole way through.
Cyber Incident Commander view for coordinating a live response.