The "Something's wrong" panic button
A guided response for a suspected breach: preserve evidence into a hashed, read-only bundle, contain the threat with preview and undo, and start the NIS2 clock.
The red Something's wrong button on Home is for the moment you suspect a real breach and are not sure what to do first. It walks you through three things, in order: say who or what this is about, preserve the evidence you already have before anything else changes, and then decide what to contain. It also starts an informational NIS2 24-hour/72-hour clock from the moment you say you first noticed, so you never lose track of it while you work.
Starting a guided response
Pick what this is about — a person with a Qorionix account, an external identity such as a Microsoft 365 account that has never signed in to Qorionix, or a device — and say in a sentence what made you suspicious. Then answer one more question: when did you first notice this? If it was earlier than right now, say so. That moment, not the moment you opened this page, is what starts the NIS2 clock.
Preserving evidence
Before you contain anything, pick the recent SIEM incidents that belong to this session. The server fetches each one itself from the record — it never trusts what your browser sends — and builds one snapshot containing their details, then computes a sha256 hash of that exact snapshot. The result is stored read-only: the database itself refuses any later attempt to edit or delete it, by anyone, including Qorionix's own systems. That is what makes the hash worth anything — a record that could quietly change afterwards would prove nothing.
You can preserve evidence more than once as a session develops; each capture is its own permanent, hashed snapshot.
Containment: preview, approve, undo
This step does not reinvent anything: it opens the same containment plan builder used everywhere else in the console (from a person's row in Access, from a device's row in Threats). You get a dry-run preview of every step — ending sessions, disabling the Microsoft 365 / Entra ID session where connected, isolating a device, queuing credential rotation — before anything runs. Nothing executes until you approve it, and most steps can be undone afterwards from the plan's own page. See Containment plans for what each step does and which can be undone, and Isolating a machine for what isolating a device costs.
The NIS2 clock
NIS2 Article 23 expects an early-warning notice within 24 hours of becoming aware of a significant incident, and a fuller notification within 72 hours. This page shows both deadlines computed from the moment you stated, and marks either as overdue in red once it passes. This is informational only — it is not itself a filing, and nothing is sent anywhere automatically.
Once you have built a containment plan for this session, its own status page can draft the NIS2 early-warning notice from the same facts — the plan, its steps and their timing — the same evidence-bound drafting described in Evidence-bound drafts. A human still reviews, edits and files it; nothing leaves the product on its own.
Who did what
Every session records who started it and when, who preserved which evidence, which containment plan (if any) belongs to it, and who closed it and why. Closing a session is a separate, explicit step — it only marks the session itself as resolved; a linked containment plan keeps its own independent status, and preserved evidence is never affected by closing the session it belongs to.
Who can use this
The panic button uses the same permission as building a containment plan (response:containment.execute). A role without it does not see the button at all on Home, rather than seeing it disabled — the same rule this console applies to every destructive, admin-only action.