Incident response — playbooks and the 'I've been hacked' button
What the response playbooks do, and the two ways an incident starts — automatically on a critical finding, or from the red 'I've been hacked' button.
When something goes wrong, the last thing you want is to figure out the next step from scratch. Incident response gives you a single place to declare an incident and a playbook that starts working the moment you do.
What the playbooks do
Opening an incident kicks off an automatic response:
- Re-scans your assets immediately, so you're working from a fresh picture, not last night's scan.
- Pages you on every channel you've configured — email and WhatsApp — so the right people know without you forwarding anything.
- Starts automated containment where it can. Depending on what's connected, that can include adding a blocking rule at Cloudflare and revoking active login sessions, to slow the attacker down while you respond.
- Gives you a step-by-step checklist on the incident page so nothing gets missed under pressure.
When they trigger
An incident starts one of two ways:
-
Automatically — when a critical finding fires, we open an incident for you, log it, and page you. You don't have to be watching the dashboard for this to happen.
-
Manually — press the red "I've been hacked" button on the Incident response page whenever something looks wrong. You pick what happened from six plain-language options:
- Data breach
- Ransomware
- Phishing attack
- Credentials leaked
- Website defaced or tampered
- Something else (investigate everything)
You can point it at a specific affected domain and add a short description. As soon as you submit, the same playbook runs.
How to set it up
There's nothing to install. To get the most out of it:
- Make sure your alert channels (email, WhatsApp) are configured so paging actually reaches you.
- Connect Cloudflare and your login provider if you want automated containment to have something to act on.
- Add your domains so an incident can be scoped to the right asset.
How to read your results
- The main list shows open and contained incidents, newest first; each row shows a status pill, a severity badge, the type, and when it was opened.
- Open an incident to work through its response checklist and see the timeline.
- Once handled, an incident moves to resolved — use the "View resolved incidents" link at the bottom of the page to review past ones.
An empty list is good news: it means you have no active incidents right now.