Incident Command

Incident Command · Major Incident Management · Crisis Coordination

Steady when the clock is running and the executive team wants a straight answer.

Thrive had no Incident Commander function before I built one: methodology, playbooks, an escalation model, and a knowledge base, and then 200+ P1 and P2 incidents directed through it for an international MSSP serving 2,000+ clients globally.

This is post-detection work. The alert has already fired and the question has already become someone's problem. What follows is the part where a person has to make the call out loud, on incomplete information, with the clock running: what is contained, what is not, who has to be told, and what the business does next.

The Function, Built From Zero

  • Methodology, playbooks, escalation, knowledge base. Built Thrive's Incident Commander function from zero: methodology, playbooks, escalation model, and knowledge base. Directed 200+ P1 and P2 incidents through it.
  • A containment unit, and a Deputy IC. Authored the Containment and Remediation Unit business proposal. Designed the Deputy IC role to scale CIRT capacity.

Running the Incident

  • Declaration through restoration, every time. Directed every P1 and P2 from declaration through restoration across time zones, from the West Coast to Hong Kong, coordinating teams of up to 20 on sustained incidents.
  • 10 servers encrypted, back in 24 hours. Led ransomware recovery on a 10-server encryption event: containment through restoration in 24 hours against a 5-to-7-day industry standard.
  • Accountability without authority. The people on an incident bridge do not report to the incident commander. Teams of up to 20, across regions and time zones, are held together by the method and the escalation model rather than by the org chart.

The Breach Coalition

A serious breach is not run by one organization. Breach counsel, a third-party forensic firm, and the cyber insurance carrier all arrive at the same event, and each of them needs something different held intact out of it.

  • Ran the coalition. Ran the breach-response coalition of breach counsel, third-party forensic firms, and the cyber insurance carrier, holding evidence, chain of custody, and privilege each party needs.
  • Preserve for the outcome, not for the meeting. That means working out early whether this ends in litigation, with a regulator, or as an insurance claim, and preserving for that outcome before anyone thinks to ask.

Executive Advisory Under Pressure

Translated threat data into business impact for C-suite leadership during active incidents: facts, options, and pathways forward in real time.

What an executive team needs mid-incident is not the technical detail. It is what the technical detail means for the business, what the options are, and what the pathway forward is, delivered while the incident is still moving rather than written up afterwards.

Federal, International & Critical Infrastructure

An incident that crosses a border, or touches something a community depends on, stops being one company's problem. Agencies have to be brought in, and the relationship with them is worth building before the day it is needed.

  • Federal and international coordination. Coordinated with the FBI, CISA, and the UK National Cyber Security Centre on multi-jurisdictional matters, and shared case intelligence with the FBI.
  • A partnership that did not exist before. Initiated Thrive's NCSC partnership and enrolled clients in the NCSC program, so UK notifications route through Thrive ahead of NCSC direct outreach.
  • Standing relationships at CISA. Built standing CISA relationships across multiple contacts and pursued a cleared-access arrangement for deeper agency briefings. That arrangement was in progress and was never completed, so what carries forward is the working relationships themselves.
  • InfraGard NJ. Member of InfraGard NJ, the FBI's critical-infrastructure community, where the people who run the infrastructure and the people who would have to respond to an attack on it are in the same room outside of an emergency.
  • Critical infrastructure and preparedness, trained formally. Critical infrastructure resilience and community lifelines, critical asset risk management, critical infrastructure security and resilience awareness, and threat and hazard identification and risk assessment with stakeholder preparedness. Federal preparedness has its own vocabulary and its own frameworks, and coordination is easier when they are already familiar.
Infrastructure Protection
TEEX, Texas A&M Engineering Extension Service (DHS / FEMA)
PER-371, Cybersecurity Incident Response and Management
TEEX, Texas A&M Engineering Extension Service (DHS / FEMA)
Certified Information Systems Security Professional (CISSP)
ISC2
InfraGard NJ
FBI critical-infrastructure community

Readiness Before the Incident

  • CIRT Readiness. Built the CIRT Readiness program: executive tabletop exercises that put client leadership through an incident before a real one arrives.
  • IC Office Hours. Ran monthly IC Office Hours across regions, turning front-line incident patterns into remediation guidance clients acted on before the same issue recurred.

The full certification and training inventory is published at Certifications & Training. The detective decade behind the evidence handling is set out at Investigations, and the insider side of it at Insider Threat.