Use cases

Triage cyber hotline calls, attacks in progress first

Each hotline call, email or notice gets an incident type, an urgency and flags for a live attack, ransom and data. It never advises on paying a ransom.

Try it on this example

Example · Hotline call: a supplier payment sent to new bank details, a mailbox still open, a laptop about to be wiped

How the incident was reported (hotline call, email or portal form): Hotline call

Call transcript, coordinator notes, email or form text

Coordinator: Cyber incident line, you are through to Rhian. Can I take your name, the business name and your policy number, please? Caller: Helen Crane. I'm the practice manager at Pellow and Finch, we're accountants in Exeter. The policy number is CY-208817. Coordinator: Thanks, Helen. Tell me what's happened. Caller: Our IT supplier rang this morning to ask why their invoice from last month hadn't been paid. We paid it on Tuesday, thirty-eight thousand four hundred pounds. Our finance manager showed me the email we got a couple of weeks ago, from their address, saying they'd changed banks and giving new account details. We paid to those. The supplier says they never sent it. Coordinator: Okay. Have you spoken to your bank? Caller: Yes, I rang them straight after, about half past nine. They've opened a case and said they'll try to recall it from the other bank, but they couldn't promise anything. Coordinator: Good. Do you know how the email got in? Caller: Our IT contractor, Idris, looked at the finance manager's mailbox this morning. There's a rule on it that sends any email with 'invoice' or 'payment' in it to an outside address and then deletes it, so she never saw the real invoice. He thinks it was set up about three weeks ago. He deleted the rule about an hour ago. Coordinator: Has her password been changed? Caller: Not yet. She's off today and he says he needs her to reset the two-step sign-in. And he says there are still sign-in alerts coming through on her account from a device we don't recognise, two since he deleted the rule. Coordinator: Understood. What does that mailbox hold? Caller: Everything, really. She sends clients' tax returns and payroll reports by email, and there are copies of passports and bank statements that clients send us for checks. Coordinator: Is the business able to work normally? Caller: Yes, everyone's working. It's just her account as far as we know. Coordinator: Have you reported it to the police? Caller: No, not yet. Should I? Coordinator: The breach coach will talk you through that. Is anything else planned on the systems today? Caller: Idris wants to wipe her laptop and reinstall it this afternoon, to be safe. Coordinator: Please ask him not to wipe or reinstall anything until the response firm has spoken to him. They need to preserve what is on the laptop and the mailbox first. Leave the laptop switched on and unplug it from the network. Caller: Okay, I'll ring him as soon as we're done. He's already started copying her files off it. Coordinator: Thank you. Has anyone contacted you asking for money, or threatening to publish anything? Caller: No, nothing like that. Coordinator: And do you have any idea whether client data has been sent anywhere? Caller: I don't know. If the rule was forwarding emails, then I suppose some client emails went out. That's what worries me most. Coordinator: That's understood. I'm passing this to the breach coach and the incident response firm now, and one of them will call you within the hour. Please keep your phone with you. Caller: Thank you.
  1. What kind of incident does the policyholder report?Payment fraud100%
  2. Does the text say the attacker may still have access, or the attack may still be going on?Yes97%
  3. Does the text say the business cannot operate normally because of the incident?No95%
  4. Does the text mention a ransom or extortion demand?No82%
  5. Does the text say money has already been paid to a fraudster or an attacker?Yes96%
  6. Does the incident involve information about identifiable people?Yes98%
  7. Does the text say affected systems have been, or are about to be, wiped, rebuilt, restored or reset?Yes96%
  8. Does the text say the police or a national cyber or fraud reporting service has been told?No83%
  9. How fast must the response partners act on this notice?Within the hour100%
  10. Is there enough in the text to tell what happened and what is affected?Yes96%

These are real answers stored from one run on this example.

The prism behind it

Triage cyber hotline calls, attacks in progress first10 questions

Fields

  • How the incident was reported (hotline call, email or portal form)
  • Call transcript, coordinator notes, email or form text

Context

We are a UK cyber insurer. Policyholders report incidents to our 24-hour hotline, by email or through the claims portal. Each notice is read here as soon as it arrives. The answers set how fast our response partners act: the breach coach, a panel law firm that leads the response, and the incident response firm that contains an attack and preserves the evidence. Nothing here decides cover. Nothing here advises on paying a ransom; the breach coach and lawyers do, and sanctions rules may apply. Legal deadlines are worked out in code from the time the policyholder became aware, and the breach coach advises on them. For example, the UK GDPR requires a controller to report a personal data breach to the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. Our first-call guidance to policyholders: do not pay or contact the attacker; do not wipe, rebuild or restore systems before the incident response firm has preserved evidence; disconnect affected machines from the network but leave them switched on; if money was sent, call the bank at once. Go only on what the text says about the incident. Do not infer anything from names or the way people speak.

Questions

  1. What kind of incident does the policyholder report? Choice

    When one incident has several parts, such as an email account taken over and then used to redirect a payment, choose the part that needs the fastest action, in this order: ransomware or extortion, payment fraud, data breach, account compromise, then the rest.

    • Ransomware or extortion Systems or files encrypted, or data stolen, with a demand to pay or a threat to publish.
    • Payment fraud Money paid, or about to be paid, to a fraudster through a fake invoice, changed bank details or an impersonated email.
    • Data breach Personal or confidential data exposed, sent to the wrong place or taken, with no demand and no payment involved.
    • Account compromise An email, cloud or other account taken over or misused, with no payment lost and no data known to be taken.
    • Lost or stolen device A laptop, phone, drive or other device holding business data lost or stolen.
    • Denial of service A website or service knocked offline by a flood of traffic.
    • Supplier incident An IT or service provider that holds or runs the policyholder's systems or data was attacked.
    • Claim against the policyholder A customer, regulator or other party seeks money or action from the policyholder over a past incident.
    • System failure An outage or fault with no sign of an attack.
    • Not a cyber incident A question about cover, a general enquiry, or a loss with no computer or data element.
  2. Does the text say the attacker may still have access, or the attack may still be going on? Yes / No

    Yes: The text says the attack is still spreading, the attacker still has or may still have access (for example a password not yet changed, or new alerts arriving), or the caller does not know whether it has stopped. No: The text says the attack is over and access has been removed, such as systems cut off and passwords changed, or describes no attack.

  3. Does the text say the business cannot operate normally because of the incident? Yes / No

    Yes: The text says key systems are down, work or trading has stopped, or appointments, orders or services are being cancelled. No: The business is working normally, or the text says nothing about it.

  4. Does the text mention a ransom or extortion demand? Yes / No

    Count a ransom note, a demand to pay, or a threat to publish or leak data unless the policyholder pays or makes contact. Yes: The text mentions a demand or threat of this kind. No: No demand or threat is mentioned.

  5. Does the text say money has already been paid to a fraudster or an attacker? Yes / No

    Yes: The text says money has already been paid out because of the incident, by the business or by one of its clients, including a payment the bank is now trying to recall. No: The text says no money has been paid, or a payment was stopped before it left, or mentions no payment.

  6. Does the incident involve information about identifiable people? Yes / No

    Count information about customers, staff or others held in the systems, accounts or devices the text says were accessed, encrypted, forwarded or taken, such as client files, payroll or patient records. Yes: The text says or shows that systems, accounts or devices holding details about identifiable people were affected. No: The text says no personal data was involved, or describes no affected system that holds it.

  7. Does the text say affected systems have been, or are about to be, wiped, rebuilt, restored or reset? Yes / No

    This goes to the incident response firm so it can preserve evidence first. Count a plan to do it even when the caller has been asked to wait. Removing a rule or blocking an account is not wiping. Yes: The text says a device, server or account has been or will soon be wiped, reinstalled, rebuilt, restored from backup or reset to factory settings. No: The text says nothing of this kind.

  8. Does the text say the police or a national cyber or fraud reporting service has been told? Yes / No

    Yes: The text says the incident has been reported to the police or to a national reporting service. No: The text says it has not been reported, or does not say.

  9. How fast must the response partners act on this notice? Scale

    Rate from what the text describes now, not from what might happen later.

    • Routine Next business day: the incident is over, contained, or a question with no loss happening now.
    • Same day Today: data may be exposed or an account was misused, but the attack has stopped and nothing is being lost now.
    • Within the hour An attack may still be under way, the business cannot operate, money has just been sent, or evidence is about to be wiped.
  10. Is there enough in the text to tell what happened and what is affected? Yes / No

    Yes: The text says what happened and which systems, accounts, data or payments are affected, clearly enough to call the right partner. No: The text is too short or vague to tell, such as "we think we have been hacked, please call".

Lens columns

incident_type, incident_type_probability, active_now, active_now_probability, operations_down, operations_down_probability, ransom_demand, ransom_demand_probability, funds_sent, funds_sent_probability, personal_data_involved, personal_data_involved_probability, evidence_at_risk, evidence_at_risk_probability, police_told, police_told_probability, urgency, urgency_average, enough_information, enough_information_probability

Run it on your own text

Add this prism in the app, change any question, and test it on a file of your own.

Ask for an invite