Response & defensive playbooks

Incident response plan — what to do when it happens

Detection and prevention keep you from complying; this plan tells you what to do once an operation is suspected or confirmed. Six phases, in order — each with its objective, immediate actions, and the mistake to avoid. Adapted from the book's incident-response procedure (chapter 6.3).

Countermeasures catalogue — CM-Hxxx by tactic

The defensive counterpart of the 13 tactics. Each countermeasure set (CM-H001 → CM-H013) maps to the tactic it neutralizes. Unlike a CVE, a human vulnerability (HVE) is never "patched" — it is compensated for with the structured vigilance below.

Individual checklists

Concrete daily gestures. Ticks are saved in your browser so you can track progress over time.

Digital hygiene — review regularly

Relational vigilance — reflexes to build

Organizational measures — 5 priority axes

For teams and organizations. Human and technical security are synergistic, not substitutable.

Bonus — the 4 questions your brain asks at first contact

According to Christopher Hadnagy, when someone approaches you for the first time your brain instinctively processes four questions within seconds — often unconsciously. A skilled attacker answers them before you consciously ask, through appearance, tone, pretext and urgency, to disable your natural vigilance and keep you in System 1.

Protective exercise. When an unusual contact approaches, explicitly ask yourself these four questions before replying. The mere act of verbalizing them internally activates System 2 and slows the process down — enough to detect most low-sophistication attacks.