// PREPARE BY RESPONSIBILITY
Bring the right
decision owner.
The first brief becomes more useful when it names who owns the question, what decision is due, and what evidence can safely support it. Choose the closest responsibility; the service lane can remain undecided.
01 / Public-sector / government owner
Make authority and procurement visible.
Bring the program or procurement decision, accountable owner, public requirement or contract context, evidence-handling boundary, and what must be defensible. Keep controlled or restricted material out of ordinary email.
Safe first step: Keep the description high-level; do not attach credentials, customer records, private incident evidence, or live target details.
Prepare a role-aware brief ↗
Review public-sector fit →
02 / Defense supplier / technology provider
Make the supplier boundary defensible.
Bring the prime, subcontract, or technology-provider context; system or service boundary; contract or requirement question; authorization owner; and supply-chain, continuity, or testing concern. Keep export-controlled, classified, and contract-restricted material out of ordinary email.
Safe first step: Keep the description high-level; do not attach credentials, customer records, private incident evidence, or live target details.
Prepare a role-aware brief ↗
Review defense-supplier fit →
03 / Buyer / third-party-risk owner
Make the supplier decision defensible.
Bring the relationship, service and data boundary, review purpose, evidence contact, contract or exit question, and the owner of the commercial or risk decision.
Safe first step: Keep the description high-level; do not attach credentials, customer records, private incident evidence, or live target details.
Prepare a role-aware brief ↗
Review vendor due diligence →
04 / Security / engineering / technical owner
Scope the technical boundary.
Bring the named asset, service, or architecture boundary; the authorization owner; the safety contact; and the evidence or output the technical team needs to act on.
Safe first step: Keep the description high-level; do not attach credentials, customer records, private incident evidence, or live target details.
Prepare a role-aware brief ↗
Review exposure services →
05 / Continuity / service / incident owner
Prepare for the disruption scenario.
Bring the critical service, impact priority, dependencies, recovery assumptions, decision date, and the authority to run a restore test, tabletop, or exercise.
Safe first step: Keep the description high-level; do not attach credentials, customer records, private incident evidence, or live target details.
Prepare a role-aware brief ↗
Review resilience services →