Document research
The exact documents available will depend on the organization but here’s what I normally start with.
- Annual reports
- About us page from the website
- Org chart
- Strategy documents
- Policies, plans and procedures
- Contingency plans
- Training schedules and records
- Incident reports / after action reviews
- Previous risk assessments (note that I don’t review these until later I just want to get copies of these now)
- News stories about the company
Note, sometimes an organization will be reluctant to share sensitive documents, or documents may be too large to send. In these cases, I ask for a copy of the table of contents to give me a rough idea of what’s in place.