1. Enter detection time
Estimate the elapsed time from disruption to validated identification and initial triage.
2. Add containment work
Include time to block malicious sessions, isolate affected identities, and protect critical access paths.
3. Estimate reset effort
Enter the time needed for credential rotation, access reissuance, and privileged account recovery.
4. Add validation and restoration
Include testing, reconciliation, approval, and re-enablement of identity services.
5. Adjust for parallel work and uncertainty
Estimate how much work can run concurrently, then add a contingency buffer for delays and rework.