Within 48 hours, I review the public and client-supplied non-sensitive material for one product chain and deliver:
• an incident and responsibility map
• affected hardware, firmware, cloud/app and integration scope
• the three most important evidence gaps
• prioritized actions for the 24- and 72-hour reporting workflow
• an example reporting-evidence pack