Incident Response Coordination
Run the war-room when ransomware hits. The producer's job, in a crisis.
What the day actually looks like.
Most days are preparation. Finalising tabletop agendas, updating runbooks, re-testing the on-call paging tree, sending weekly metrics emails. Then Friday 3:07pm: ransomware encrypts a Lagos branch's file shares. Within 15 minutes you've opened the war-room Zoom, paged the IR retainer (Mandiant/Unit 42), opened a dedicated Slack channel, started the timeline document, briefed the CEO's Chief of Staff in two paragraphs, and drafted holding statements. You don't analyse the malware. You run the bridge call.
Where the work lives.
What you actually need.
- NIST 800-61 lifecycle (read-level)
- SANS PICERL framework
- MITRE ATT&CK (read-level)
- EDR product names (Falcon, Defender, SentinelOne)
- Regulatory landscape (NDPA 72-hour rule, CBN RBCF, ISO 22301)
- Translating engineer-speak to exec-speaktransferable
Same skill as turning DOP-talk into a director's note.
- Calm under live-broadcast pressuretransferable
Running the bridge call IS live production.
- Post-mortem writingtransferable
Production debriefs, retitled.
- Chronology and storytellingtransferable
- Discretion
The shape of the journey.
- 1IR Coordinator / Cyber Crisis Analyst0-2 yr
- 2Senior IR Coordinator / Incident Manager2-5 yr
- 3IR Consultant4-8 yr
- 4IR Manager / CSIRT Lead6-11 yr
- 5Head of Cyber Crisis9-15 yr
- 6Deputy CISO / CISO13-22 yr
Note. Times reflect typical paths for someone with strong communication and 10-15 hrs/week of focused study.
What it pays.
Ranges are directional. Currency: USD · annual. Last updated: 2025.
The cert sequence that won't bankrupt you.
Security+
CompTIAVocabulary baseline.
PMP
PMIThe underrated cheat code. Coordinators ARE project managers.
EC-Council CIH
EC-CouncilIncident Handler cert. $500-700 range.
GIAC GCIH
SANS / GIACGold standard but never self-fund the SANS course.
ISO 22301 Lead Implementer
PECBBusiness continuity. Strong differentiator. $700-1.5k.
Working from Lagos, Abuja, or anywhere.
Lagos timezone overlaps neatly with London business hours and partial US East-coast hours. Ideal for international IR retainers.
The good, the gritty, and who this suits.
- +High-impact, high-visibility.
- +Clean path to CISO.
- +Portable across industries.
- +Producers have a head start.
- −On-call rotation.
- −Vicarious stress from real incidents.
- −'Neither technical enough nor management enough' identity battle early on.
If you've been the calmest person in the room when a shoot fell apart, you can do this.
Three to five hours that beat any cert.
Backdoors & Breaches: Live Tabletop Exercise Demo
Why watch. A live tabletop. The texture of the job.
How to Play Backdoors & Breaches
Why watch. Free card game you can run with friends. Best practice tool in the field.
Wisdom from the Cyber Security Battlefield
Why watch. Mark Goudie on real-world IR. Battle-tested.
Introduction to Cybersecurity Incident Response
Why watch. Clear framework intro.
Do this by Friday.
This weekend: order Black Hills' Backdoors & Breaches deck (or print free PDF). Run a 90-minute tabletop with friends. Document what you learned in a LinkedIn post.