Incident Response Coordination
Run the war-room when ransomware hits. The producer's job, in a crisis.
What the day actually looks like.
Most days are preparation — finalising tabletop agendas, updating runbooks, re-testing the on-call paging tree, sending weekly metrics emails. Then Friday 3:07pm: ransomware encrypts a Lagos branch's file shares. Within 15 minutes you've opened the war-room Zoom, paged the IR retainer (Mandiant/Unit 42), opened a dedicated Slack channel, started the timeline document, briefed the CEO's Chief of Staff in two paragraphs, and drafted holding statements. You don't analyse the malware — you run the bridge call.
Where the work lives.
What you actually need.
- NIST 800-61 lifecycle (read-level)
- SANS PICERL framework
- MITRE ATT&CK (read-level)
- EDR product names (Falcon, Defender, SentinelOne)
- Regulatory landscape (NDPA 72-hour rule, CBN RBCF, ISO 22301)
- Translating engineer-speak to exec-speaktransferable
Same skill as turning DOP-talk into a director's note.
- Calm under live-broadcast pressuretransferable
Running the bridge call IS live production.
- Post-mortem writingtransferable
Production debriefs, retitled.
- Chronology and storytellingtransferable
- Discretion
The shape of the journey.
- 1IR Coordinator / Cyber Crisis Analyst0–2 yr
- 2Senior IR Coordinator / Incident Manager2–5 yr
- 3IR Consultant4–8 yr
- 4IR Manager / CSIRT Lead6–11 yr
- 5Head of Cyber Crisis9–15 yr
- 6Deputy CISO / CISO13–22 yr
Note. Times reflect typical paths for someone with strong communication and 10–15 hrs/week of focused study.
What it pays.
Ranges are directional. Currency: USD · annual. Last updated: 2025.
The cert sequence that won't bankrupt you.
Security+
CompTIAVocabulary baseline.
PMP
PMIThe underrated cheat code — coordinators ARE project managers.
EC-Council CIH
EC-CouncilIncident Handler cert. $500–700 range.
GIAC GCIH
SANS / GIACGold standard but never self-fund the SANS course.
ISO 22301 Lead Implementer
PECBBusiness continuity. Strong differentiator. $700–1.5k.
Working from Lagos, Abuja, or anywhere.
Lagos timezone overlaps neatly with London business hours and partial US East-coast hours. Ideal for international IR retainers.
The good, the gritty, and who this suits.
- +High-impact, high-visibility.
- +Clean path to CISO.
- +Portable across industries.
- +Producers genuinely have a head start.
- −On-call rotation.
- −Vicarious stress from real incidents.
- −'Neither technical enough nor management enough' identity battle early on.
If you've been the calmest person in the room when a shoot fell apart, you can do this.
Three to five hours that beat any cert.
Backdoors & Breaches: Live Tabletop Exercise Demo
Why watch. Watch a live tabletop exercise — what your job actually feels like.
How to Play Backdoors & Breaches
Why watch. Free card game you can run with friends. Best practice tool in the field.
Wisdom from the Cyber Security Battlefield
Why watch. Mark Goudie on real-world IR — battle-tested.
Introduction to Cybersecurity Incident Response
Why watch. Clear framework intro.
Do this by Friday.
This weekend: order Black Hills' Backdoors & Breaches deck (or print free PDF). Run a 90-minute tabletop with friends. Document what you learned in a LinkedIn post.