The Clean Opinion
Tools/Cyber · Free · About 3 min

Breach Aftermath Control Checklist

After an incident, the second wave is questions — from customers, the insurer, the board, the auditor, and sometimes lenders. Each one asks for specific controls and specific evidence. Answer eight questions about the incident and get the checklist, the evidence list, and a question-prep section for each party.

Runs in your browser. Nothing you type is sent anywhere unless you choose to export it. Privacy

'Not yet known' is a valid answer. The checklist adds the steps for finding out.
ERP, billing, payroll, banking, or the identity provider in front of them.
A filing, a customer notice, or a press statement.
Select all that apply. Leave blank if no one has asked yet.
Tickets, configuration exports, test records — things a third party could rely on.
Answer at least three questions. Anything you leave blank is treated as not yet known.
Your control checklist, evidence list, and a question-prep section for each stakeholder will appear here. Nothing leaves your browser.

This checklist is control-readiness preparation for the questions that follow an incident. It is not legal advice, not incident-response counsel, and not an audit opinion. If you are in an active incident, your counsel and your incident-response provider come first; use this once the immediate response is under control. Audits and attestations are performed by Alpha Secure LLP, a licensed CPA firm. Disclosure.