Mega2580.Solutions
August 2020

Running incident response with a fully distributed team

By A. Tanaka · 5 min read

This year our team, and most of the teams we work with, went fully distributed. A lot of incident response process turned out to be quietly load-bearing on people being in the same room — the shared whiteboard, someone glancing over and noticing a wrong assumption, the informal handoff at the end of a shift.

We rebuilt around a few explicit habits instead of implicit ones: a single incident channel with a named incident commander from the first message, a running timeline that's actually written down instead of reconstructed afterward, and a deliberate handoff message any time responsibility moves between people.

None of this is complicated. It's also not automatic — every team we've helped through this transition had to make it a written process before it stuck, because the informal version genuinely doesn't survive distance.