Incident response plan — what to do when it happens
Detection and prevention keep you from complying; this plan tells you what to do once an operation is suspected or confirmed. Six phases, in order — each with its objective, immediate actions, and the mistake to avoid. Adapted from the book's incident-response procedure (chapter 6.3).
Countermeasures catalogue — CM-Hxxx by tactic
The defensive counterpart of the 13 tactics. Each countermeasure set (CM-H001 → CM-H013) maps to the tactic it neutralizes. Unlike a CVE, a human vulnerability (HVE) is never "patched" — it is compensated for with the structured vigilance below.
Individual checklists
Concrete daily gestures. Ticks are saved in your browser so you can track progress over time.
Digital hygiene — review regularly
Relational vigilance — reflexes to build
Organizational measures — 5 priority axes
For teams and organizations. Human and technical security are synergistic, not substitutable.
Bonus — the 4 questions your brain asks at first contact
According to Christopher Hadnagy, when someone approaches you for the first time your brain instinctively processes four questions within seconds — often unconsciously. A skilled attacker answers them before you consciously ask, through appearance, tone, pretext and urgency, to disable your natural vigilance and keep you in System 1.
- Who are you? — your identity, role, legitimacy to contact me.
- What do you want? — the intent behind the approach.
- Are you a threat? — is there danger, risk, a reason to distrust?
- How long will this take? — can I afford this interaction right now?