Print the first 60 minutes before you need them
When something breaks, nobody wants to search a shared drive for “the plan”. A printed page by the phones — who to call, in which order, what not to touch — is what small teams actually use.
- Runs entirely in your browser
- Works offline
- No upload
- No sign-up
- No watermark
Loading the tool…
How it works
- Type the contacts (IT lead, provider, insurer, bank), tick your platforms and note where the backups are.
- Choose the scenarios you want on the card.
- Print it or save as PDF; keep a copy near the phones and one at home for the person on call.
Why nothing is uploaded
Every operation on this page is done by code running inside your browser tab, using the same engine that renders web pages. The file is read from disk into your tab’s memory, transformed there, and written back out as a download. It is never sent anywhere — not to us, not to a third party.
Verify it yourself
- Open your browser’s developer tools (F12) and select the Network tab.
- Load your file and run the tool.
- The only requests you will see fetch the tool’s own code — and, for a few heavy tools, their open-source engine from a public CDN — plus one small page-view ping to loreatec.jp (page address and title, nothing more). None of them carry your file.
Frequently asked questions
Where do the steps come from?
From the public incident-handling guidance everyone in the field uses — NIST SP 800-61 and JPCERT/CC and IPA materials — condensed to what a small team can do in the first hour without specialists. It is deliberately a checklist, not a manual: the goal is a calm first hour, after which your provider or insurer takes over.
Why does the card say “do not turn the machine off”?
Because memory holds evidence — running processes, encryption keys, connections — that disappears at power-off and that responders need. Disconnecting from the network stops the spread just as well. The exception is a machine actively wiping data in front of you; then power matters less than the data.
What is the Japanese notification note?
In Japan, a leak of personal data generally requires a prompt preliminary report to the Personal Information Protection Commission (the guideline is within 3–5 days), a final report within 30 days (60 for malicious leaks) and notification of the individuals. Deadlines are why the card exists: they are easy to miss in the chaos. Confirm current rules on ppc.go.jp; elsewhere check your local law (GDPR: 72 hours).
Are my contacts stored anywhere?
Only in this browser, and only if you tick “remember”. The card is generated locally; printing uses your browser’s own dialog. Nothing is uploaded — which is rather the point for a document listing your insurer’s policy number.