The First 30 Days · crisis profile
02 / 06
The Sergeant
Procedures — you have them. Discipline — you have it. Results — those too. And a team that reports exactly what you want to hear, which is to say, less and less. Around you, the rules work impeccably right up to the day someone makes a mistake and would rather swallow the story than bring it to you. The good news: half the system is already built. The less good news: the missing half can't be bought and can't be ordered — it has to be earned.
3 recommendations
- Change a single question: "who messed up?" becomes "what happened?" — same investigation, ten times the answers.
- Publicly praise the next three problem reports, especially the ones that turn out to be false alarms — you pay little and buy the reflex that matters.
- Run a test-email exercise and announce up front that the results carry no sanctions: you're measuring the system, not hunting people.
What's your profile?
12 decisions, 3 minutes — and you'll know how you lead when nobody gives you time to think.
Play it yourself — 3 minutesThen this story isn't just a game for you.
Companies in regulated sectors have legal security obligations — NIS2, in Romania GEO 155/2024 — with reporting deadlines, mandatory measures and real fines. CERTO walks you through them step by step, in plain language, no jargon.
See CERTO — NIS2 compliance without the bureaucracyThe good news: everything you practised here can be trained for real.
The instinct from that first email, the reflex to pick up the phone and verify, a culture where people report — that is exactly what our training programmes build, with realistic simulations and no blame hunts.
A work of fiction — the characters and companies are invented. The attack mechanisms and the lessons are real.