How it works

From zero to ready,
without the consulting bill

Module by module, team by team, scenario by scenario — how IR Now builds an incident response program tailored to your organization.

STEP 01

Tell us about your org

A guided, multi-section profile — 37 fields covering your industry, tech stack, identity provider, compliance posture, and team. Every field quietly shapes the modules that follow.

  • Industry, team size, and the systems you actually run
  • Frameworks you report against (SOC 2, ISO 27001, PCI DSS)
  • Playbook references and on-call patterns
See how this maps to audit evidence →
irnow.net/courses/new · step 1 of 4
Organization profile28 / 37
Financial technology
51–200
AWS
SOC 2ISO 27001PCI DSS
STEP 02

Pick the scenarios

Choose from 14 incident types — one per course on Basic, up to seven on Pro. Each scenario becomes its own module with original copy, a decision tree, and a quiz tied to your incident response playbook.

  • Ransomware, BEC, data breach, cloud, insider, and more
  • Sub-questions sharpen each scenario for your context
  • Auto-filled from your org profile where it makes sense
irnow.net/courses/new · step 2 of 4
Incident catalog3 of 7 selected
Ransomware
Malware & extortion
Phishing, BEC & Social Engineering
People & email
Cloud Infrastructure
Cloud & infrastructure
Data Breach & Exfiltration
Data exposure
STEP 03

Pick who's being trained

Run a course organization-wide, or target one team — engineering, security, executives, legal, finance, and more. Per-team courses pick up that team's headcount, technical literacy, and primary comms tool to sharpen the role module.

  • Organization-wide for shared baseline training
  • Per-team for tailored role modules (Pro)
  • The same team profile carries across recurring cycles
irnow.net/courses/new · step 3 of 4
Organization-wide
All teams · no role-specific module
Software Engineering
Selected team
Headcount 12Literacy MixedComms Slack
Security Team
Available
STEP 04

AI tailors, you review

We email you when it's ready. Every module is built from expert IR frameworks, then personalized to your stack and playbooks. Review and edit any module before publishing.

  • Grounded in NIST, PICERL, and MITRE ATT&CK
  • Three layers: foundations · team-tailored · scenarios
  • Edit copy, swap modules, or regenerate before going live
irnow.net/courses/abc-123 · ready to review
What ransomware does to fintech · Foundations6 min
On-call engineer: first 15 minutes · Team8 min
Isolating an AWS workload · Scenario10 min
Notifying stakeholders & counsel · Foundations5 min
STEP 05

Train, measure, repeat

Learners work scenario-based modules and timed quizzes that test real judgment. You see readiness scores, gap analysis, and verifiable certificates — then schedule the next cycle to keep everyone sharp.

  • Scenario quizzes: multiple choice, ordering, spot-the-mistake
  • Readiness by team and individual + gap analysis
  • Recurring training auto-re-invites learners every cycle
irnow.net/reports
87%
Team readiness
94%
Certified
3
Open gaps
Containment92%
Detection78%
Recovery64%
Next auto-run · Aug 2026
Coverage

Incident scenarios covered

14 scenario modules — every one available on every plan. Tap any scenario to see what your team practices.

Every scenario module follows the same deep structure: detection signals → response priorities → your org's context → team scenario → role-specific actions → tool-specific steps.
Malware & extortion

Ransomware

On every plan

Malware encrypts systems and demands payment to restore access. Drills rapid isolation, recovery from backups, and the discipline to coordinate before paying anything.

Detection signals

  • Mass file-extension changes
  • Ransom notes appearing on hosts
  • Backup deletion or tampering

Response priorities

  • Isolate affected hosts fast
  • Preserve evidence & scope spread
  • Engage backups, legal & comms
Every learner also works through
What it isWhy it mattersDetection signalsResponse prioritiesYour org's contextTeam scenarioRole-specific actionsTool-specific stepsKey takeaways
Built for every team

Different teams, different training

10 role-specific modules — each team gets a track tailored to what they actually do during an incident. Tap any team for example sections; AI shapes the actual module to your org.

Leads the response

Security Team

The security team runs point on every incident, hunting threats, triaging forensics, and driving containment from detection to recovery.

Example sections Tailored per org
  • Role overview & responsibilities
  • Threat hunting during active incidents
  • Forensic triage
  • Containment strategy
  • Runbook & tooling maintenance
  • IR leadership

↑ Tap any team for example sections — IR Now tailors the actual content to your org

How a course is built

Three layers of training

Layer 1

Foundations

Shared fundamentals every learner completes. The common language and baseline of incident response.

Includes: fundamentals, communication, evidence handling, severity, readiness, and post-incident review.
Layer 2

Team-tailored

A role-specific track for each department. The team you select tells AI what to emphasize, who to coordinate with, and which tools they actually use.

Per-team context: each role module is shaped by the team's headcount, technical literacy, and primary comms tool.
Layer 3

Scenario deep-dives

Focused walkthroughs of individual incidents: detection, containment, and recovery in detail.

1 scenario per course on Basic, up to 7 on Pro and Enterprise.
Set expectations

What IR Now is — and isn't

IR Now is

  • Grounded in expert IR frameworks, tailored to your real systems and playbooks
  • Scenario-based, testing real decision-making
  • Continuously updated as threats evolve
  • Fast to deploy, live in hours, not weeks

IR Now isn't

  • Generic, off-the-shelf compliance training
  • A penetration testing or vulnerability scanning tool
  • A SIEM, detection, or monitoring tool
  • A one-time, set-and-forget course

See it built for your stack.

Request access and we'll generate a course from your organization's real profile.