The First 30 Days · crisis profile
01 / 06
The Architect
You went through the 30 days like a drill you'd run before: the verification call, the isolation, people informed, a written page at the end. The funny part is that your company probably doesn't even realise what it just survived — around you, crises die young and never get to become stories. You're the kind of director nobody writes articles about. That's a compliment: the articles get written about the others.
3 recommendations
- Test what you've built, regularly: one real restore from backup and one crisis exercise a year tell you whether the system works or merely looks good.
- Write the succession plan for your calm: if the next crisis lands while you're on holiday, who decides — and from which page?
- Hold your suppliers to the same standard as your own company — your next incident may well start inside their computers.
What's your profile?
12 decisions, 3 minutes — and you'll know how you lead when nobody gives you time to think.
Play it yourself — 3 minutesThen this story isn't just a game for you.
Companies in regulated sectors have legal security obligations — NIS2, in Romania GEO 155/2024 — with reporting deadlines, mandatory measures and real fines. CERTO walks you through them step by step, in plain language, no jargon.
See CERTO — NIS2 compliance without the bureaucracyThe good news: everything you practised here can be trained for real.
The instinct from that first email, the reflex to pick up the phone and verify, a culture where people report — that is exactly what our training programmes build, with realistic simulations and no blame hunts.
A work of fiction — the characters and companies are invented. The attack mechanisms and the lessons are real.