Operational readiness
1. Define what event creates internal “awareness” and how it is timestamped.
2. Assign a primary reporting owner and deputy.
3. Map products with digital elements to versions, markets and responsible teams.
4. Create a 24-hour early-warning intake template.
5. Create separate 72-hour fields for vulnerability and severe-incident cases.
6. Track mitigation, security updates and user-facing remedial actions.
7. Prepare the later final-report evidence path: vulnerability cases and severe incidents have different follow-up timing/content.