The difference between a bad day and a catastrophe is whether the plan existed, whether people had rehearsed it, and whether someone was awake to run it. We do all three: playbooks and drills before, a response desk that stands up in minutes during, and an after-action report within five business days after. The same floor that runs the watch runs the response.
We start with what you have. Existing plans are read, gaps are mapped against your footprint and threat picture, and the playbooks are written for the scenarios that actually apply to you.
Crisis and continuity planning. Crisis plans aligned to ISO 22301, business impact analysis, an incident command structure, escalation trees and communication protocols.
Signed playbooks. Standard procedures for active hostile events, mass-casualty hazards, civil unrest escalation, infrastructure outage, a cyber incident from your security tooling, traveller panic, unacknowledged cascades and persons of concern.
Drills and exercises. Tabletop and live exercises with injects drawn from real reporting, and after-action reports that change the plan rather than file it.
The response desk. When it happens: a named incident lead, a case opened on the watch floor, notification cascades with acknowledgement tracking, a muster board, situation reports on the hour and a decision log.
Evacuation, relocation and communications. Corridors, assembly points, transport and safe locations planned on the live picture with the field app on every mover; holding statements and stakeholder updates from a fact base that keeps pace with events.
During an incident the same platform that runs the watch floor runs the response: case files, cascades with acknowledgement tracking, muster boards, evacuation corridors and situation reports. The incident lead decides; the machine keeps the record.
A confirmed event inside your footprint, a panic, a missed cascade, an outage. The playbook for it is already signed.
thresholdA named incident lead, the case on the floor, the decision log started. Minutes, not a meeting.
named leadCascades to the people in scope with acknowledgement tracked, a muster board that works the unaccounted list to zero.
accountabilitySituation reports on the hour on your template, holding statements from the fact base, stakeholder updates.
hourlyStand-down through the same chain, then the after-action report within five business days, and the changes it makes.
5 business daysRead what you have, map the gaps against your footprint and threat picture, write the playbooks that apply, rehearse them with real injects.
Named incident lead, open case, cascades, muster, situation reports on the hour, the decision log. On the same picture as the watch.
Findings, gaps and the changes made, within five business days of stand-down. The plan gets better every time it is used.
Roles, triggers, escalation, communications, recovery. Aligned to ISO 22301 and to how your organisation actually works.
Signed off and rehearsed, for the scenarios that apply to your footprint. Eight to start from, extended for you.
Findings, gaps and the changes made to the plan, from tabletop or live exercises with real injects.
On your template, from the case record, every hour until stand-down.
Who is accounted for, who is not, who decided what, when, on what evidence.
What happened, what worked, what did not, and the changes made to the plan and the playbooks.
Plants, depots, offices and camps in places where the first hour decides the outcome.
Evacuation and relocation with the field app on every mover and the roll worked to zero.
A crisis week bought as a fixed sprint: the desk stood up the next business day, stood down when it passes.
Plans aligned to the standard your auditors read, with the exercise reports to show they were rehearsed.
Access, corridors and accountability for programmes in the places where it matters most.
A response desk behind your brand for the clients you already have.
A crisis week can be bought as a fixed-scope sprint. Ongoing readiness is part of the managed GSOC or a named seat. Either way the same floor that watches your sites runs the response when one of them has a bad day.
Existing plans, your footprint, who is in scope, and the scenarios that keep you up at night.
The gap map, the playbooks we will write, the exercise date, and the quote. A crisis week starts the same day you say yes.
Playbooks signed, the first exercise run, the response desk ready to stand up in minutes.
| The job | The binder | GeoBit crisis management |
|---|---|---|
| The plan | Written once, aligned to a template | Written for your footprint and threat picture, aligned to ISO 22301 |
| Rehearsal | An annual tabletop, if the calendar allows | Exercises with injects drawn from real reporting, and reports that change the plan |
| The first hour | Finding the binder, finding the lead | A named lead, an open case, cascades running, in minutes |
| Accountability | A spreadsheet, eventually | A muster board worked to zero, every acknowledgement tracked |
| Reporting | When someone has time | Situation reports on the hour, on your template |
| Afterwards | A meeting | After-action report within five business days, and the plan updated |
You do not have to hire a desk to start. Pick one fixed first thing, or describe something else entirely, tell us where and when, and a person comes back within one working day with a scope, the date it lands, and the quote. Say yes and the work starts the next business day.
Hire any desk on this site and the platform, the watch, the other desks and the people come with it. Nothing is a module.
The whole system, everything included. Every chair comes with all of it.
We build your maps for you — daily or weekly — and deliver them.
Draw your areas; our AI watches them 24/7 and alerts you.
An AI-driven Global Security Operations Center for your org.
An engineer embedded with your team, deployed anywhere.
A named analyst on your channels, with the whole system behind them.
Hire the team and get the output: one to ten operators, every offering included.
A piece of intelligence work, done for you and delivered on a date.
How exposed a site is, from the fence line outward, with ranked fixes.
Who would do it and could they: actors placed by intent and capability.
What could go wrong, how likely, how bad, and what moves the score.
Find the pathway before the act: subjects assessed, places watched, cases filed.
Physical and control-system posture together, the dependency graph, the cascade.
Send us what you have and what keeps you up at night. We come back within one working day with the gap map, the playbooks we would write, and a quote.