Respond · Quick reference
Incident Kickoff — Quick Reference
The card to keep at hand during a live incident. Print it. The full checklists and templates live in the Incident Kickoff Toolkit.
Incident start checklist
- Confirm it's incident-shaped (P1–P4). Not sure? Default to P3 and adjust.
- STOP before acting: Stand still. Take it all in. Observe. Proceed.
- Name an Incident Commander — one person, one voice, full authority.
- IC assigns roles as needed: Ops / Logistics / Communications / etc.
- Set the priority level. Log it.
- Open one incident channel or bridge. No side channels.
- Start the clock — log start time, detection method, who declared it.
- Open the incident log (Run Sheet) and the Detail Form.
- Notify stakeholders per the priority's escalation path.
- Schedule the first status brief before you hang up.
Priority levels
- P1 Critical — business outage, all users affected. Urgent fix.
- P2 High — major impact, multiple services down. Fast resolution.
- P3 Medium — limited impact, workaround exists. Normal SLA.
- P4 Low — cosmetic or single user. Planned resolution.
Briefing checklist
Keep it small: IC, active Section Chiefs, PIO, one stakeholder rep. This is a sync, not a meeting.
Every brief, same order
- Situation — current state, plain language.
- Impact — who/what is affected right now.
- Actions taken since the last brief.
- Actions in progress, and who owns each one.
- Blockers / asks — what's needed from outside the room.
- Set the time of the next brief before you close.
Cadence (adjust to your org)
- P1 — every 30 minutes · P2 — hourly
- P3 — once per shift · P4 — as needed
Ground rules
- Be kind — it probably wasn't one person's fault.
- Be clear — keep it simple, avoid jargon.
- Be honest — facts only, no blame.
Stakeholder update (separate from internal brief)
What happened. What we're doing. When we'll update again.
Run sheet — essentials
Log every material action in real time, timestamped. One line per event. Don't reconstruct it later.