Incident Response Readiness Score
12 questions. 2 minutes. You get a 0–36 score across the five pillars of small-team incident response — taxonomy, on-call escalation, playbooks, drills, vendor coordination — plus the one thing to fix first. Nothing leaves your browser.
1. Can you classify an incident by business impact (revenue, data, trust, compliance) in under a minute?
Impact-first taxonomy stops you "classifying" a P1 as a P3 because it looks small in Slack.
2. Does every incident get mapped to a technical category (availability, security, data, third-party) before work starts?
The category decides who fixes it and what the fix class is — wrong category, wrong on-call.
3. Do you have written escalation tiers with time limits (e.g. Tier 1 at 15 min, Tier 4 at 4 hours)?
Time-boxed tiers turn "wait and hope" into an automatic ladder that fires whether or not anyone is watching.
4. Is there a dedicated incident channel structure (declared channels, roles, message conventions) rather than an ad-hoc thread?
Ad-hoc threads scatter decisions; declared structure makes the incident readable after the fact.
5. Does your on-call rotation have defined cadence and handoff (e.g. 4-week schedule, handoff checklist)?
Rotations without handoff discipline burn people out and drop context between shifts.
6. When an incident starts, does a triage rule (type + severity → playbook) pick the runbook — not the loudest person?
A selection rule removes the worst-minute-of-the-outage debate about "what do we do".
7. Do you have a quick-reference matrix matching incident types to playbooks?
The matrix is the 10-second version of your whole library — if it doesn't fit on one screen, triage stalls.
8. Have you run a scheduled incident simulation (game day) in the last quarter?
Untested incident response is a hope, not a plan — same as untested backups.
9. After incidents and drills, do you produce an after-action report with lessons and prevention owners?
Without owned prevention items, the same incident recurs with a new name.
10. Do you keep a vendor incident contact matrix (cloud, payments, DNS, email — with escalation contacts)?
During a vendor outage you need their escalation line in 30 seconds, not a status-page refresh loop.
11. Do you track vendor incident SLAs and know when you're owed compensation or an RCA?
Every enterprise vendor has SLA credits; almost nobody collects them without a tracker.
12. Can a new joiner run the first 30 minutes of an incident without asking anyone anything?
The first-30 test: if the newest person can start containment and comms from a card alone, the system is real.
Your result
Score bands
| Score | Band | What it means |
|---|---|---|
| 0–11 | Firefighting | Incidents run you. Fix the first-30-minutes card before anything else. |
| 12–19 | Stabilizing | You improvise well. Now make triage and escalation written and boring. |
| 20–27 | Systematizing | The structure exists. Drills and vendor SLAs are your gap. |
| 28–36 | Proven | You have a system. Prove it with scored drills and a done-for-you runbook review. |
Want the whole pillar system?
The five pillars above (taxonomy, escalation mesh, playbook triage, simulation reports, vendor coordination) ship as a complete pack with 15+ checklists, matrices and templates — built for 5–30 person teams.
Get the Ops Mega Bundle — all 5 kits Done-for-you Custom Incident Runbook Small-Team Ops Audit (prioritized findings)Not ready to buy? Start with the free card: The First 30 Minutes — free