What we solve ·What happens the day this goes down?
Taskforce · Sustain
Who is in command in your organization when something big goes down?
When something big goes down, we find out late and we communicate it worse.
So your leaders know how to command and communicate during a crisis, with a real incident of yours reconstructed in the room.
Major incident commandSend this page to whoever decides
Use this today, without hiring anyone
The four decisions of the first fifteen minutes of a crisis. Write them down today, with names, and you will have in writing what most operations improvise on the day of the incident.
- Who can declare that this is a major incident? If it needs permission from someone who is asleep, you have already lost half an hour. Whoever is on shift has to be able to declare it.
- Who commands, and why is it not the person fixing it? The person with their hands on the keyboard cannot at the same time keep the time, decide the paths and talk to leadership. It is two people, or it is one person doing both badly.
- What is the first message, and to whom? Write it beforehand, as a template: what is happening, who it affects, what is being done and when there will be news again. The last part is the one left out and the one that prevents twenty phone calls.
- How often does communication go out again, even with no news? Without a fixed cadence, silence reads as nobody doing anything.
One question separates a mature operation from the rest. At what point do you decide to abandon the path you are on and try another? Without that criterion written down, crises drag on because nobody wants to be the person who says that what we have been trying for two hours is not going to work.
This sounds like you if
- In the last serious incident, the official communication arrived after the rumor.
- In the crisis room there is no command role separate from the fixing role.
- The same incident has already come back more than once.
How we solve it
The method, not the promise.
- Your real incident logs get read before the session. The workshop gets built on what is yours.
- It opens with the three roles in the crisis room and why whoever commands does not fix.
- The declaration protocol and the communication template get written, in the room and with your names on them.
- One of your own incidents gets reconstructed minute by minute, looking for the failure mode and not for who is to blame.
- It closes with the path abandonment criterion and with how an incident gets closed so that it does not come back.
What you receive
- The major incident declaration protocol, with who can declare it.
- The communication templates upward, to the customer and to the team, with their cadence.
- The reconstruction of one of your own incidents with its decisions marked.
- The written criterion for abandoning a path and trying another.
The proof that applies here
- Critical situation escalation lead for the largest accounts of a global software company in Latin America and worldwide.
- Recoveries that saved contracts at risk, with on site work in seven countries.
- Major incident command in operations of 60,000 servers, 24/7.
Before you hire
This is training so your people command the crisis: the firm does not take part in your real incidents, and this engagement does not include a standing watch or a committed response time.
There is plenty of material on incident management. What barely exists is someone who has commanded recoveries with large contracts at stake and can tell you what was decided at minute twenty and why. That is why the workshop is run by the person who was there.
In your last crisis, who was in command, and did they also have their hands on the keyboard?
If the problem is a different one
The process already depends on the agent and nobody remembers how it was done by hand.
Agent continuity planning
Everything escalates, nothing gets resolved at the front line and the internal customers have already complained upstairs.
Service operation turnaround
We know that if it goes down, it goes down. No one has wanted to write what happens next.
Operational readiness diagnostic
