GlassbreakGlassbreak

Answers

Plain-language answers about break-glass procedures, emergency access, and making sure the right people can reach what matters — whether that’s a team or a family.

What is the difference between SIG Lite and CAIQ?CAIQ is published free by the Cloud Security Alliance. SIG comes from Shared Assessments and needs a licence. What each covers and which one you will be sent.2026-08-23What is operational resilience?Operational resilience asks whether an important business service stays within its impact tolerance during severe but plausible disruption.2026-08-23How should an MSP respond when its RMM platform is compromised?A practical MSP response plan for isolating a compromised RMM while preserving independent access, client communications, evidence, and recovery control.2026-07-26What should you do in the first hour when your identity provider is down?A first-hour checklist for when Okta, Entra ID, or Google Workspace is down: triage outage vs. compromise, reach your team, use break-glass access safely.2026-07-24What counts as evidence that an incident-response plan has been tested?What counts as testing your incident-response plan, the evidence insurers and auditors accept, and a tabletop log template you can use this quarter.2026-07-24How should MFA exceptions be documented and reviewed for a cyber-insurance questionnaire?What underwriters want from an MFA-exception answer, a copy-pasteable exception register template, and how to keep break-glass access off the list entirely.2026-07-24How should an MSP store and manage break-glass credentials for client environments?A copy-pasteable policy and register template for MSPs holding client break-glass credentials: per-client tiering, quorum release, audit-ready evidence.2026-07-24What is an out-of-band communications plan for incident response, and what should it contain?How to coordinate an incident when email, Slack, and ticketing are compromised or down: what a credible out-of-band comms plan contains, with a template.2026-07-24How do you prepare for a cyber-insurance questionnaire?The privileged-access and incident-response questions cyber insurers actually ask, why they move premiums, and a worksheet for answering with evidence.2026-07-19What are DORA's incident reporting deadlines and communication duties?DORA's ICT incident reporting cascade — initial, intermediate, and final reports — plus client communication duties, with a copy-pasteable checklist.2026-07-19How do you write an ISO 27001 break-glass procedure?What ISO 27001 auditors look for in an emergency-access procedure under Annex A 8.2, with a complete copy-pasteable break-glass procedure template.2026-07-19How do you get ready for NIS2 incident handling and business continuity?NIS2 Article 21 incident handling and business continuity measures plus the Article 23 reporting cascade, with a practical readiness checklist template.2026-07-19What are break-glass account best practices?Core break-glass account practices: limit who can trigger it, require quorum approval, time-box access, log everything, and drill it.2026-07-17How does DORA affect emergency access to ICT systems?DORA requires EU financial entities to have response and recovery procedures for ICT incidents, including how staff reach critical systems under stress.2026-07-17How should a team store 2FA recovery codes?Team 2FA recovery codes belong in encrypted, access-controlled storage separate from the account they unlock — never a spreadsheet or chat message.2026-07-17How do you remove key-person risk from credentials?Remove key-person risk from credentials by replacing single-owner access with quorum-based recovery, per-team vaults, and offboarding that revokes instantly.2026-07-17What does NIS2 require for incident-response access?NIS2 Article 21(2) requires in-scope entities to have incident-handling measures and secured emergency-communication systems as part of their risk management.2026-07-17What happens when your password manager is down?When a password manager is down, locked, or its owner is unreachable, you fall back to whatever emergency-access path you set up in advance.2026-07-17What break-glass evidence do SOC 2 auditors expect?SOC 2 auditors typically expect break-glass evidence covering who can trigger access, what approval was required, what was reached, and when it ended.2026-07-17What is a dead man's switch for credentials?A dead man's switch for credentials releases access automatically if you stop checking in, so critical logins aren't lost if you become unavailable.2026-07-17For individualsWhat is quorum-based (Shamir) secret sharing?Quorum-based secret sharing splits a key into shares so a threshold of independent people must combine theirs to recover it, and nothing below it works.2026-07-17What is a break-glass procedure?A break-glass procedure is a controlled process for emergency access to critical secrets or systems when the normal access path is unavailable.2026-07-16

Stay Updated

Get product updates and security insights. No spam, unsubscribe anytime.

We respect your privacy. See our privacy policy.