Choose the incident
Start with the system, provider, or person that is creating the risk.
Everything here is general guidance, not professional advice. We research carefully and can still be wrong or out of date, so treat it as suggestions to check rather than instructions to follow, and accept that you act on it at your own risk. Full terms.
Practical playbooks for the moments that matter: a stolen phone, a hacked account, a production outage.
Quick start
Check these five things. If one is missing, open its playbook and fix it when you can.
Risk landscape
The library spans six areas, from personal devices and accounts to production systems. Use this map to find where the most recovery paths are waiting to be prepared.
Incident library
61 playbooks
Your devices, accounts, photos, and money. No IT department required.
A deletion, bad edit, or damaged folder is copied across every device connected to your cloud storage.
A Windows or macOS update leaves the computer stuck, restarting, or unable to reach the desktop.
Your home connection fails when you need it for work, school, payments, or communication.
Someone may control the router that connects every phone, computer, camera, and smart device in your home.
Nobody attacked you. You simply cannot get back into the account that holds your photos, your email, and your two-factor codes.
Someone else is in your email, which means they can reset the password on almost everything else you own.
Your phone is gone, and it is signed in to your email, your bank, your messages, and the codes that protect everything else.
Your phone suddenly loses service because someone moved your number to another SIM or mobile provider.
The drive died, the phone went in the water, or the folder is simply gone, and there was never a copy.
Money left your account that you did not authorise, or you were talked into sending it and have just realised.
Someone took over your Instagram, Facebook, X, or TikTok and is posting, messaging your friends, or holding it for ransom.
Production systems, customer data, vendors, and the people who keep them running.
An attacker may read mail, reset other accounts, impersonate the business, or redirect payments.
An attacker may control cloud identities, infrastructure, data, logs, or the account's billing and recovery settings.
Automated attackers are testing stolen username and password pairs against customer accounts.
An attacker may control an owner account, repositories, Actions, apps, or credentials connected to your GitHub organization.
A work laptop containing sessions, source code, customer data, or recovery credentials is missing.
The phone or security key used to approve critical logins is unavailable, damaged, or stolen.
An attacker may be able to publish malicious versions of packages your customers or systems install.
The vault containing business passwords, recovery codes, and secure notes is unavailable or cannot be unlocked.
A credential that can read data, spend money, send messages, or control production has been exposed.
Queued emails, imports, billing actions, webhooks, or other asynchronous work is delayed or frozen.
A provider limit prevents new requests, instances, storage, messages, builds, or other critical resources.
A cloud region or availability zone hosting critical workloads becomes unavailable or severely degraded.
A cron task or scheduler no longer runs backups, renewals, reports, cleanup, billing, or synchronization.
The application cannot obtain database connections, causing requests, jobs, and administrative access to stall.
A schema or data migration partially applies, blocks traffic, corrupts records, or leaves old and new code incompatible.
Malicious traffic exhausts bandwidth, connections, compute, or expensive application operations.
Incorrect nameservers or DNS records make the website, API, email, or verification services unreachable.
Your domain no longer resolves, has left your registrar account, or is registered to someone else.
A launch, mention, campaign, or attack sends far more legitimate traffic than the system was designed to handle.
Logs, metrics, traces, uptime checks, or alerts stop reporting while production continues to run.
A release causes errors, missing pages, failed checkouts, corrupt writes, or unexpected customer behavior.
Browsers or API clients reject your site because its HTTPS certificate is expired, invalid, or issued for the wrong name.
An attacker may have altered your site, stolen data, installed persistence, or gained access to connected systems.
A hidden, unfinished, risky, or destructive code path is activated for the wrong customers or environment.
Backups exist, but they are missing, corrupt, incomplete, encrypted, incompatible, or too slow to use.
An export, report, attachment, or support response exposes one customer's information to another.
Encrypted customer data, backups, or infrastructure cannot be decrypted because the required key is missing or inaccessible.
Customer information, credentials, internal documents, or private source code were pushed to a public repository.
Files intended for restricted access can be listed or downloaded without proper authorization.
Records, files, tables, or an entire production database were deleted or overwritten.
Production records still exist but values, relationships, indexes, or internal storage are no longer trustworthy.
Systems or data are encrypted, stolen, deleted, or held for payment by a malicious actor.
Passwords, tokens, payment details, personal data, or private content are being recorded in application or vendor logs.
A retry, webhook, race condition, import, or operator action creates duplicate customer charges.
Payment events are delayed, rejected, or ignored, leaving orders, subscriptions, and access out of sync.
Stripe is still collecting money, but payouts are delayed, paused, failed, or restricted.
Disputes rise sharply because of fraud, customer confusion, service failure, or an organized abuse campaign.
Cloud, AI, storage, bandwidth, or API spending rises far beyond the expected amount.
A contractor becomes unreachable while retaining access, knowledge, devices, code, data, or ownership of critical services.
Someone who no longer works with the business can still reach accounts, code, data, devices, or customer systems.
The only person with critical authority, access, or knowledge cannot work or communicate.
A key person departs before transferring ownership, context, credentials, work, or recurring responsibilities.
A mobile app or developer account is rejected, removed, or suspended, blocking new installs, updates, billing, or discovery.
Builds, tests, package publishing, or deployments cannot run through the normal automation provider.
A provider your product or operations depend on is unavailable, degraded, or losing data.
A provider announces closure, ends your product, terminates service, or gives a short migration deadline.
Your newsletter account is suspended, disabled, terminated, or inaccessible before an important send.
A library, container, plugin, action, SDK, or build dependency may contain malicious or unauthorized code.
Login links, receipts, alerts, invitations, and account messages are rejected, delayed, or sent to spam.
A third-party API changes behavior, authentication, fields, limits, or versions and breaks a critical workflow.
No playbooks match that search.
How it works
Start with the system, provider, or person that is creating the risk.
Use the readiness checklist beforehand or follow urgent actions in order.
Finish with observable checks that prove the business is actually recovered.