Digital Emergency Response: 5 Critical Steps

Print this out and keep it handy for when things go wrong, and in case you’re locked out of your accounts.  

This checklist applies to incidents like:

Step 1: KNOW WHO TO CALL

Make a list of important contacts. Set up a Signal group for your core team. 

Incident Commander (Name/Phone/Signal)

Technical Lead (Name/Phone/Signal)

Communications Lead (Name/Phone/Signal)

Executive Contact (Name/Phone/Signal)

Support Coordinator (Name/Phone/Signal)

External Support Contacts:

Step 2: STOP AND  DOCUMENT

What to do immediately:

For doxxing/harassment incidents:

Why this matters: Your first action is to preserve evidence. You do not want to inadvertently delete information that can help you recover from this attack.  

Step 3: ACTIVATE YOUR PHONE TREE

Call in this order (within 1 hour):

1.     Incident Lead 

2.     Technical Lead 

3.     Communications Lead 

4.     Executive Contact 

Template message: "We have a security incident involving [brief description]. I've documented what happened. Need immediate coordination - switching to Signal for secure comms."

Step 4: SECURE THE SCENE

Immediate containment actions:

For organizational incidents:

What NOT to do:

Step 5: ENGAGE SYSTEMS AND PRACTICES

Assessment Questions:

External Communications:

Do NOT contact external parties until you've answered:

Media Inquiries:

Escalation Matrix:

Immediate Escalation Required:

Escalate Within 24 Hours:


Revision #12
Created 7 November 2025 18:06:21 by Josh
Updated 7 November 2025 18:22:44 by Josh