Know who can make decisions

Confirm who owns the product, code, infrastructure, credentials, data, vendors, and incident response. Finding problems is not enough if nobody can approve the recovery work.

Get access to what matters

List what the team can actually inspect: repositories, environments, logs, analytics, deployment history, dependencies, and documentation. Missing access is a risk in its own right.

Fix urgent risk first

Separate anything that threatens customers, revenue, data, or daily operations from general code quality. Stabilise the important parts first, then plan the deeper improvements.

Leave the week with a plan

A useful first week ends with a shared view of the product, immediate actions, the biggest risks, and a small number of recovery options with clear owners.

The first week should replace anxiety with facts: what is at risk, what is accessible, who can decide, and what the team should do next.