Field guides

Systems under pressure.

Use them solo. Use them with a team. They work either way.

By incident

The same guides, routed by what happened rather than when.

Wire fraud Controls, then the first hour. Wire fraud controls → Wire fraud, the first hour → 02 guides
Ransomware Readiness, then the first hour. Ransomware readiness → Ransomware, the first hour → 02 guides
Account takeover The exposure drill, then the response. Credential exposure drill → Account takeover response → 02 guides
Data exfiltration Suspected exfiltration. No readiness guide yet. Data exfiltration suspected → 01 guide
Any incident Aftermath, review, and the people who held the line. Immediate aftermath (24 to 72h) → Post-incident review → Operator recovery → 03 guides

Rehearsal

Produce the behaviour under pressure before reality asks for it.

paged Live Rehearsal Live fire One indicator. Forty-five minutes. Work out what it is, what it touched, and whether it is still active. Curated scenarios plus a random mode: wire fraud, kerberoasting, ransomware staging, insider exfil. Solo or with a team. paged.breakpointhq.co → 90 min session

The thinking behind these lives in the observations. If the guide you need is not here, say which one.