By the end
What you'll build
- Run an incident from detection to closure using the agreed workflow
- Assign impact, urgency and priority consistently and defend the assignment
- Declare a major incident against defined criteria and open the correct bridge
- Coordinate a technical bridge and keep a usable timeline of actions and decisions
- Write stakeholder updates that separate confirmed facts from working theories
- Produce a factual post-incident review and hand causes to problem management
Curriculum
What's inside
7 modules · 41 lessons
- 01
The incident lifecycle
6 lessons- From detection to closure: the workflow and its decision points
- Detection sources: people, monitoring and automation
- Diagnosis versus workaround: restoring service first
- Holding ownership through hand-offs
- Reopened incidents, and what they tell you
- + 1 more lesson
- 02
Prioritisation under pressure
6 lessons- Impact and urgency when the information is incomplete
- Priority matrices and their common failure modes
- Service hours, business criticality and seasonal peaks
- Re-prioritising cleanly as the facts change
- Priority inflation and how to resist it
- + 1 more lesson
- 03
Declaring and running a major incident
6 lessons- Declaration criteria and the first fifteen minutes
- Roles: incident commander, communications lead, technical leads
- Running a bridge that stays focused
- Keeping a decision log while the work is happening
- Stand-down criteria and handover to recovery
- + 1 more lesson
- 04
Communicating during a major incident
6 lessons- Writing the first stakeholder update
- Cadence: what to send when nothing has changed
- Confirmed facts, working theories and stated unknowns
- Internal wording versus consumer-facing wording
- Closing communications and the commitments they create
- + 1 more lesson
- 05
After the incident
6 lessons- A blameless review that produces actions people actually close
- Building the timeline from evidence rather than memory
- Contributing factors instead of a single root cause
- Turning findings into problem records and improvements
- Tracking actions through to closure
- + 1 more lesson
- 06
Working with the other practices
6 lessons- Where incident, problem, change and continuity meet
- Incidents caused by changes, and how to prove it
- When an incident becomes a security matter and must be escalated
- Invoking continuity or recovery plans
- The data you owe to service-level reporting
- + 1 more lesson
- 07
Practice and check
5 lessons- Who owns what, when it is on firematch pairs
- The first fifteen minutessequence order
- Under pressure, preciselyfill blank
- 14:20, orders are failingscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
41 lessons across 7 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
