Product Overview

Created by Jean-Simon Gervais, Modified on Sun, 12 Jul at 12:10 AM by Jean-Simon Gervais

What is Breach Commander

Breach Commander is a unified incident orchestration platform where the story writes itself.

It bundles all the capabilities to bridge the needs and ease the pains of all practitioners dealing with incident management.

It is designed to help organizations coordinate, document, and manage cyber incidents, operational disruptions, crises, and tabletop exercises.

It provides a shared operational workspace where technical responders, business leaders, legal counsel, auditors, executives, insurers, and external specialists can work from the same structured case record.

Breach Commander supports the complete incident lifecycle:

  • Preparing response procedures before an incident
  • Coordinating decisions and activities during a crisis
  • Producing reports, evidence, analytics, and lessons learned afterward

The platform is designed to complement existing cybersecurity, ticketing, monitoring, and collaboration tools. Its primary purpose is to organize the people, decisions, actions, deadlines, evidence, and reporting required to manage an incident effectively.


Breach Commander provides:

✅ Dynamic digital workflows: Agile incident response playbook

✅ Real-time executive insights: Intuitive cockpit for decision-makers

✅ Risk-driven metrics: Comprehensive KPIs/KRIs

✅ Compliance at heart: Aligned with industry best practices and regulations

✅ Auditing and reporting made easy: Accountability at your fingertips

✅ Training and simulations: Equip your teams to handle the unexpected

What Breach Commander helps organizations manage

During a serious incident, relevant information is often distributed across emails, chat platforms, technical systems, documents, spreadsheets, and individual notes.

This fragmentation can make it difficult to determine:

  • Who is responsible for each action
  • Which decisions have been made
  • What remains incomplete
  • Which systems, data, or operations are affected
  • Whether regulatory, legal, insurance, or contractual deadlines are approaching
  • What information was available when a decision was made
  • Whether the organization followed diligent response procedures
  • How the incident should be explained to executives, auditors, regulators, insurers, or customers

Breach Commander brings these elements into a structured case-management environment.

Core capabilities

Case management

Each incident or exercise is managed as a case.

A case includes information such as:

  • Affected organization
  • Severity
  • Assigned operational roles
  • Business and technical impacts
  • Response activities based on dynamic playbooks
  • Timers and deadlines
  • Files and supporting evidence
  • Chat discussions
  • A timeline
  • A summary

The information is presented as interview questions for the assigned users, with supporting context easily available.

Role-based coordination

Breach Commander supports the assignment of operational responsibilities within a case.

Depending on the tenant configuration and product edition, roles may include:

  • Incident Commander
  • Business Lead
  • Technical Lead
  • Legal Counsel
  • Auditor
  • Non-operational viewers

Role assignments help clarify ownership while allowing participants from different disciplines to collaborate within the same case.

Permissions may be based on tenant access, organizational access, administrative privileges, and case-specific roles.

Structured playbooks

Playbooks provide predefined response activities for common incident and crisis scenarios.

They can help teams:

  • Follow an approved response process
  • Organize activities by phase
  • Assign responsibility
  • Record progress
  • Identify incomplete actions
  • Capture supporting information
  • Demonstrate that required procedures were considered

Playbooks may support general incident-response activities as well as specialized operational, regulatory, or industry requirements.

Organizations can also add ad hoc steps when a situation requires actions that are not already included in a playbook.

Impact tracking

Impacts can be recorded and updated throughout a case.

The impact form helps document the various aspects such as:

  • Impact type:
    • Confidentiality
    • Integrity
    • Availability
    • People
    • Environment
    • Reputation
  • Discovery timings
  • Affected environment, data and technologies
  • Affected users

Tracking impacts separately from response activities helps the incident team distinguish between what has happened and what is being done about it.

Timers and deadlines

Timers can be used to track operational, contractual, legal, insurance, regulatory, or internal deadlines.

A timer may represent:

  • Time remaining before a notification deadline
  • A service-level objective
  • A scheduled decision point
  • A follow-up commitment
  • A containment or recovery target

Timers provide visible time awareness during situations where delays may have operational or legal consequences.

They require an acknowledgement on expiry.

Case timeline

The case timeline consolidates important events into a chronological record.

Timeline entries may include:

  • Case creation and status changes
  • Playbook steps decisions or answers
  • Impact updates
  • Activities assignments

A reliable timeline helps teams reconstruct the incident, prepare reports, support reviews, and explain how the response developed over time.

Reporting

Breach Commander can consolidate case and audit information into reports in various formats.

Auditing and accountability

Administrative and operational changes can be recorded in the audit log.

The audit logs allows the creation of an auditable timeline where auditors can assess the validity and relevance of the decisions, with a score and comments.

The completed audits represent the auditor's perspective of how well a case was managed.

Analytics

Breach Commander can use structured case data to produce operational analytics.

Depending on the edition and tenant configuration, analytics may include information about:

  • Mean timings for detection, containment, and recovery
  • Case scores
  • Case volumes by severity
  • Affected market segments
  • Affected organizations type and revenue range
  • Impacts
  • Simulation/Exercise activity
  • Audit scores
  • Various historical trends

Analytics help organizations move beyond anecdotal lessons and identify recurring response strengths, gaps, delays, and improvement opportunities.

Operational model

Breach Commander organizes information through several connected levels.

Tenant

A tenant is the primary Breach Commander environment for a customer or operational group.

Tenant administrators can manage settings such as:

  • Users
  • Organizations
  • Product options
  • AI configuration
  • Chat capabilities
  • Legal hold
  • Role requirements
  • Logging
  • Specialty playbooks
  • Tenant files

Tenant-wide settings can affect all organizations, users, and cases within the environment.

Organization

An organization represents a business, department, subsidiary, client, facility, or other entity that may be associated with users and cases.

A tenant may contain one or multiple organizations.

User

A user is an individual who has access to the tenant.

A user's effective access may depend on:

  • Tenant permissions
  • Organization membership
  • Administrative privileges
  • Case assignments
  • Operational roles
  • Product licensing

Case

A case is the operational workspace used to manage a specific incident, crisis, investigation, disruption, or exercise.

Cases contain the activities, impacts, decisions, evidence, discussions, timeline, and reporting information related to that event.

Incident lifecycle

Breach Commander can support activities before, during, and after an incident.

Before an incident

Organizations can prepare by:

  • Configuring users and organizations
  • Defining responsibilities
  • Preparing playbooks
  • Uploading reference documents
  • Establishing logging and reporting requirements
  • Conducting tabletop exercises
  • Reviewing response analytics

During an incident

Teams can use Breach Commander to:

  • Create and classify the case
  • Assign leadership roles
  • Apply playbooks
  • Record affected systems, data, and operations
  • Assign and track actions
  • Manage deadlines
  • Document decisions
  • Coordinate participants
  • Maintain the incident timeline
  • Produce status summaries

After an incident

Organizations can use the completed case record to:

  • Produce final reports
  • Support insurance or legal processes
  • Review audit information
  • Conduct lessons learned
  • Identify recurring response gaps
  • Track remediation
  • Improve playbooks
  • Strengthen future preparedness

Tabletop exercises

Breach Commander can also be used to manage tabletop exercises.

Exercise cases use the same operational structure as real incidents, allowing participants to practise:

  • Role assignments
  • Decision-making
  • Playbook execution
  • Impact assessment
  • Time-sensitive coordination
  • Executive reporting
  • Cross-functional collaboration

Exercise cases can be identified separately so that training activity does not distort real-incident analytics.

AI-assisted features

Some Breach Commander editions and tenant configurations may include AI-assisted capabilities.

These features may help users:

  • Summarize case aspects:
    • Decisions
    • Communications
    • Comments
    • Files
  • Identify relevant ad-hoc considerations
  • Support stakeholders with an AI agent dedicated to incident management support and counselling.

AI-generated content must be reviewed by an authorized user before it is relied upon.

AI assistance does not replace:

  • Incident leadership
  • Legal advice
  • Technical analysis
  • Regulatory interpretation
  • Insurance guidance
  • Executive judgment

Availability and behavior may depend on the AI provider selected by the tenant administrator.

Security and data protection

Breach Commander is intended to manage sensitive operational and incident information.

Customers should configure access according to the principles of least privilege and operational need.

Security-related capabilities may include:

  • Role-based access
  • Multifactor authentication
  • Encrypted communications
  • Protected file storage
  • Encrypted case exports
  • Audit logging
  • Secure logging integrations
  • Legal-hold controls
  • Tenant-level administrative settings

Customers remain responsible for determining which information should be entered into the platform and which users should be authorized to access it.

For more information, see the Breach Commander security and privacy documentation applicable to your environment.

Who uses Breach Commander?

Breach Commander is designed for participants involved in incident response, crisis management, resilience, governance, insurance, and assurance activities.

Typical users include:

  • Incident Commanders
  • Chief Information Security Officers
  • Security operations teams
  • Digital forensics and incident-response specialists
  • Business continuity leaders
  • Crisis-management teams
  • Executives
  • Legal Counsel
  • Privacy officers
  • Risk and compliance professionals
  • Internal auditors
  • Cyber insurers and claims professionals
  • Breach coaches
  • Managed service providers
  • External incident-response providers

Each participant may use different parts of the platform according to their responsibilities and permissions.

What Breach Commander does not replace

Breach Commander is an orchestration and case-management platform. It does not replace the specialist systems used to detect, investigate, contain, or recover from technical incidents.

It may operate alongside tools such as:

  • Security information and event management platforms
  • Endpoint detection and response systems
  • Ticketing systems
  • Forensic tools
  • Backup and recovery platforms
  • Threat-intelligence services
  • Email and collaboration platforms
  • Governance, risk, and compliance systems

Information from these systems can be referenced, summarized, attached, or integrated into the case-management process as appropriate.

Product editions

Breach Commander capabilities may vary by edition, subscription, tenant configuration, and assigned permissions.

The available editions may include:

  • Core
  • Standard
  • Pro
  • Enterprise or custom deployments

Some features described in the documentation may not be available in every environment.

Contact your tenant administrator or Breach Commander support when an expected feature is not visible.

Getting started

New users should begin with the following articles:

  1. Accept your invitation and activate your account
  2. Configure multifactor authentication
  3. Navigate the Breach Commander interface
  4. Understand roles and permissions
  5. Create your first case
  6. Managing a Case: Overview

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article