Triage cyber hotline calls, attacks in progress first
Each hotline call, email or notice gets an incident type, an urgency and flags for a live attack, ransom and data. It never advises on paying a ransom.
Try it on this example
How the incident was reported (hotline call, email or portal form): Hotline call
Call transcript, coordinator notes, email or form text
- What kind of incident does the policyholder report?Payment fraud100%
- Does the text say the attacker may still have access, or the attack may still be going on?Yes97%
- Does the text say the business cannot operate normally because of the incident?No95%
- Does the text mention a ransom or extortion demand?No82%
- Does the text say money has already been paid to a fraudster or an attacker?Yes96%
- Does the incident involve information about identifiable people?Yes98%
- Does the text say affected systems have been, or are about to be, wiped, rebuilt, restored or reset?Yes96%
- Does the text say the police or a national cyber or fraud reporting service has been told?No83%
- How fast must the response partners act on this notice?Within the hour100%
- Is there enough in the text to tell what happened and what is affected?Yes96%
These are real answers stored from one run on this example.
The prism behind it
Triage cyber hotline calls, attacks in progress first
Fields
- How the incident was reported (hotline call, email or portal form)
- Call transcript, coordinator notes, email or form text
Context
We are a UK cyber insurer. Policyholders report incidents to our 24-hour hotline, by email or through the claims portal. Each notice is read here as soon as it arrives. The answers set how fast our response partners act: the breach coach, a panel law firm that leads the response, and the incident response firm that contains an attack and preserves the evidence. Nothing here decides cover. Nothing here advises on paying a ransom; the breach coach and lawyers do, and sanctions rules may apply. Legal deadlines are worked out in code from the time the policyholder became aware, and the breach coach advises on them. For example, the UK GDPR requires a controller to report a personal data breach to the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. Our first-call guidance to policyholders: do not pay or contact the attacker; do not wipe, rebuild or restore systems before the incident response firm has preserved evidence; disconnect affected machines from the network but leave them switched on; if money was sent, call the bank at once. Go only on what the text says about the incident. Do not infer anything from names or the way people speak.
Questions
What kind of incident does the policyholder report? Choice
When one incident has several parts, such as an email account taken over and then used to redirect a payment, choose the part that needs the fastest action, in this order: ransomware or extortion, payment fraud, data breach, account compromise, then the rest.
Does the text say the attacker may still have access, or the attack may still be going on? Yes / No
Yes: The text says the attack is still spreading, the attacker still has or may still have access (for example a password not yet changed, or new alerts arriving), or the caller does not know whether it has stopped. No: The text says the attack is over and access has been removed, such as systems cut off and passwords changed, or describes no attack.
Does the text say the business cannot operate normally because of the incident? Yes / No
Yes: The text says key systems are down, work or trading has stopped, or appointments, orders or services are being cancelled. No: The business is working normally, or the text says nothing about it.
Does the text mention a ransom or extortion demand? Yes / No
Count a ransom note, a demand to pay, or a threat to publish or leak data unless the policyholder pays or makes contact. Yes: The text mentions a demand or threat of this kind. No: No demand or threat is mentioned.
Does the text say money has already been paid to a fraudster or an attacker? Yes / No
Yes: The text says money has already been paid out because of the incident, by the business or by one of its clients, including a payment the bank is now trying to recall. No: The text says no money has been paid, or a payment was stopped before it left, or mentions no payment.
Does the incident involve information about identifiable people? Yes / No
Count information about customers, staff or others held in the systems, accounts or devices the text says were accessed, encrypted, forwarded or taken, such as client files, payroll or patient records. Yes: The text says or shows that systems, accounts or devices holding details about identifiable people were affected. No: The text says no personal data was involved, or describes no affected system that holds it.
Does the text say affected systems have been, or are about to be, wiped, rebuilt, restored or reset? Yes / No
This goes to the incident response firm so it can preserve evidence first. Count a plan to do it even when the caller has been asked to wait. Removing a rule or blocking an account is not wiping. Yes: The text says a device, server or account has been or will soon be wiped, reinstalled, rebuilt, restored from backup or reset to factory settings. No: The text says nothing of this kind.
Does the text say the police or a national cyber or fraud reporting service has been told? Yes / No
Yes: The text says the incident has been reported to the police or to a national reporting service. No: The text says it has not been reported, or does not say.
How fast must the response partners act on this notice? Scale
Rate from what the text describes now, not from what might happen later.
Is there enough in the text to tell what happened and what is affected? Yes / No
Yes: The text says what happened and which systems, accounts, data or payments are affected, clearly enough to call the right partner. No: The text is too short or vague to tell, such as "we think we have been hacked, please call".
Lens columns
incident_type, incident_type_probability, active_now, active_now_probability, operations_down, operations_down_probability, ransom_demand, ransom_demand_probability, funds_sent, funds_sent_probability, personal_data_involved, personal_data_involved_probability, evidence_at_risk, evidence_at_risk_probability, police_told, police_told_probability, urgency, urgency_average, enough_information, enough_information_probability
Run it on your own text
Add this prism in the app, change any question, and test it on a file of your own.