ClearSecurity VISION
EN / RO

The First 30 Days · crisis profile

02 / 06

The Sergeant

Procedures — you have them. Discipline — you have it. Results — those too. And a team that reports exactly what you want to hear, which is to say, less and less. Around you, the rules work impeccably right up to the day someone makes a mistake and would rather swallow the story than bring it to you. The good news: half the system is already built. The less good news: the missing half can't be bought and can't be ordered — it has to be earned.

3 recommendations

  1. Change a single question: "who messed up?" becomes "what happened?" — same investigation, ten times the answers.
  2. Publicly praise the next three problem reports, especially the ones that turn out to be false alarms — you pay little and buy the reflex that matters.
  3. Run a test-email exercise and announce up front that the results carry no sanctions: you're measuring the system, not hunting people.

What's your profile?

12 decisions, 3 minutes — and you'll know how you lead when nobody gives you time to think.

Play it yourself — 3 minutes

Then this story isn't just a game for you.

Companies in regulated sectors have legal security obligations — NIS2, in Romania GEO 155/2024 — with reporting deadlines, mandatory measures and real fines. CERTO walks you through them step by step, in plain language, no jargon.

See CERTO — NIS2 compliance without the bureaucracy

The good news: everything you practised here can be trained for real.

The instinct from that first email, the reflex to pick up the phone and verify, a culture where people report — that is exactly what our training programmes build, with realistic simulations and no blame hunts.

See the training programme Book a free briefing

A work of fiction — the characters and companies are invented. The attack mechanisms and the lessons are real.