Everything here is general guidance, not professional advice. We research carefully and can still be wrong or out of date, so treat it as suggestions to check rather than instructions to follow, and accept that you act on it at your own risk. Full terms.

Prepare now

Twenty minutes now, or a very bad week later.

Almost every playbook here has the same shape: the recovery is hard and slow, and the thing that would have made it easy took about twenty minutes to set up beforehand. A backup that was already running. A second admin who was not on holiday. A recovery code written on paper.

None of it is difficult. It is just easy to postpone, because nothing bad has happened yet.

Your readiness

How much of this you have already done

Everyday life

0%

0 of 105 safeguards

Businesses

0%

0 of 360 safeguards

Nothing ticked off yet. Progress saves in this browser as you go, with no account needed.

Across 0 playbooks you have started. Only the row that matches you is worth chasing to 100%.

Quickest first

Start where it is cheapest

61 playbooks

For everyday life

Your devices, accounts, photos, and money.

Home internet stops workingPersonalYour home connection fails when you need it for work, school, payments, or communication.15 minutes15 minPersonal email account hackedPersonalSomeone else is in your email, which means they can reset the password on almost everything else you own.15 minutes15 minPhone number stolen in a SIM swapPersonalYour phone suddenly loses service because someone moved your number to another SIM or mobile provider.15 minutes15 minSocial media account hackedPersonalSomeone took over your Instagram, Facebook, X, or TikTok and is posting, messaging your friends, or holding it for ransom.15 minutes15 minCloud sync deletes files everywherePersonalA deletion, bad edit, or damaged folder is copied across every device connected to your cloud storage.20 minutes20 minHome router or Wi-Fi hackedPersonalSomeone may control the router that connects every phone, computer, camera, and smart device in your home.20 minutes20 minLocked out of your Google or Apple accountPersonalNobody attacked you. You simply cannot get back into the account that holds your photos, your email, and your two-factor codes.20 minutes20 minPhone lost or stolenPersonalYour phone is gone, and it is signed in to your email, your bank, your messages, and the codes that protect everything else.20 minutes20 minScammed or fraudulent bank chargePersonalMoney left your account that you did not authorise, or you were talked into sending it and have just realised.20 minutes20 minComputer will not start after an updatePersonalA Windows or macOS update leaves the computer stuck, restarting, or unable to reach the desktop.25 minutes25 minPhotos and files lost with no backupPersonalThe drive died, the phone went in the water, or the folder is simply gone, and there was never a copy.30 minutes30 min

For businesses

Production systems, customer data, vendors, and the team.

MFA device lost or brokenThe phone or security key used to approve critical logins is unavailable, damaged, or stolen.20 minutes20 minTLS certificate expiredBrowsers or API clients reject your site because its HTTPS certificate is expired, invalid, or issued for the wrong name.20 minutes20 minCritical scheduled job silently stopsA cron task or scheduler no longer runs backups, renewals, reports, cleanup, billing, or synchronization.25 minutes25 minDomain expired or lostYour domain no longer resolves, has left your registrar account, or is registered to someone else.25 minutes25 minLaptop lost or stolenA work laptop containing sessions, source code, customer data, or recovery credentials is missing.25 minutes25 minPassword manager locked outThe vault containing business passwords, recovery codes, and secure notes is unavailable or cannot be unlocked.25 minutes25 minWrong feature flag enabled in productionA hidden, unfinished, risky, or destructive code path is activated for the wrong customers or environment.25 minutes25 minCloud quota exhaustedA provider limit prevents new requests, instances, storage, messages, builds, or other critical resources.30 minutes30 minDatabase connections exhaustedThe application cannot obtain database connections, causing requests, jobs, and administrative access to stall.30 minutes30 minDNS change takes the business offlineIncorrect nameservers or DNS records make the website, API, email, or verification services unreachable.30 minutes30 minMonitoring and alerts go blindLogs, metrics, traces, uptime checks, or alerts stop reporting while production continues to run.30 minutes30 minNewsletter provider closes the accountYour newsletter account is suspended, disabled, terminated, or inaccessible before an important send.30 minutes30 minProduction deploy breaks the siteA release causes errors, missing pages, failed checkouts, corrupt writes, or unexpected customer behavior.30 minutes30 minStripe payouts frozenStripe is still collecting money, but payouts are delayed, paused, failed, or restricted.30 minutes30 minBackground jobs stop processingQueued emails, imports, billing actions, webhooks, or other asynchronous work is delayed or frozen.35 minutes35 minCI/CD provider outage blocks releasesBuilds, tests, package publishing, or deployments cannot run through the normal automation provider.35 minutes35 minContractor disappearsA contractor becomes unreachable while retaining access, knowledge, devices, code, data, or ownership of critical services.35 minutes35 minCritical SaaS provider outageA provider your product or operations depend on is unavailable, degraded, or losing data.35 minutes35 minCustomers charged twiceA retry, webhook, race condition, import, or operator action creates duplicate customer charges.35 minutes35 minFormer team member still has accessSomeone who no longer works with the business can still reach accounts, code, data, devices, or customer systems.35 minutes35 minPayment webhooks stop processingPayment events are delayed, rejected, or ignored, leaving orders, subscriptions, and access out of sync.35 minutes35 minPrivate storage bucket becomes publicFiles intended for restricted access can be listed or downloaded without proper authorization.35 minutes35 minProduction API key leakedA credential that can read data, spend money, send messages, or control production has been exposed.35 minutes35 minSensitive data appears in logsPasswords, tokens, payment details, personal data, or private content are being recorded in application or vendor logs.35 minutes35 minTransactional email stops arrivingLogin links, receipts, alerts, invitations, and account messages are rejected, delayed, or sent to spam.35 minutes35 minUnexpected cloud billCloud, AI, storage, bandwidth, or API spending rises far beyond the expected amount.35 minutes35 minVendor API changes without warningA third-party API changes behavior, authentication, fields, limits, or versions and breaks a critical workflow.35 minutes35 minBusiness email compromisedAn attacker may read mail, reset other accounts, impersonate the business, or redirect payments.40 minutes40 minPrivate data appears in a public repositoryCustomer information, credentials, internal documents, or private source code were pushed to a public repository.40 minutes40 minSudden wave of chargebacksDisputes rise sharply because of fraud, customer confusion, service failure, or an organized abuse campaign.40 minutes40 minTeam member leaves without a handoverA key person departs before transferring ownership, context, credentials, work, or recurring responsibilities.40 minutes40 minApp removed from an app storeA mobile app or developer account is rejected, removed, or suspended, blocking new installs, updates, billing, or discovery.45 minutes45 minCritical vendor shuts downA provider announces closure, ends your product, terminates service, or gives a short migration deadline.45 minutes45 minCustomer accounts under credential-stuffing attackAutomated attackers are testing stolen username and password pairs against customer accounts.45 minutes45 minDatabase migration fails mid-releaseA schema or data migration partially applies, blocks traffic, corrupts records, or leaves old and new code incompatible.45 minutes45 minDDoS attack overwhelms the serviceMalicious traffic exhausts bandwidth, connections, compute, or expensive application operations.45 minutes45 minEncryption key lost or unusableEncrypted customer data, backups, or infrastructure cannot be decrypted because the required key is missing or inaccessible.45 minutes45 minGitHub organization compromisedAn attacker may control an owner account, repositories, Actions, apps, or credentials connected to your GitHub organization.45 minutes45 minLaunch produces 20× expected trafficA launch, mention, campaign, or attack sends far more legitimate traffic than the system was designed to handle.45 minutes45 minPackage registry account compromisedAn attacker may be able to publish malicious versions of packages your customers or systems install.45 minutes45 minProduction data deletedRecords, files, tables, or an entire production database were deleted or overwritten.45 minutes45 minBackups will not restoreBackups exist, but they are missing, corrupt, incomplete, encrypted, incompatible, or too slow to use.50 minutes50 minFounder unavailable for two weeksThe only person with critical authority, access, or knowledge cannot work or communicate.50 minutes50 minProduction database corruptedProduction records still exist but values, relationships, indexes, or internal storage are no longer trustworthy.50 minutes50 minSoftware dependency compromisedA library, container, plugin, action, SDK, or build dependency may contain malicious or unauthorized code.50 minutes50 minCloud account compromisedAn attacker may control cloud identities, infrastructure, data, logs, or the account's billing and recovery settings.60 minutes60 minCloud region outageA cloud region or availability zone hosting critical workloads becomes unavailable or severely degraded.60 minutes60 minRansomware or destructive malwareSystems or data are encrypted, stolen, deleted, or held for payment by a malicious actor.60 minutes60 minWebsite hackedAn attacker may have altered your site, stolen data, installed persistence, or gained access to connected systems.60 minutes60 minCustomer receives another customer's dataAn export, report, attachment, or support response exposes one customer's information to another.90 minutes90 min

No playbooks match that search.