Abstract
This paper presents a method for evaluating an organization’s ability to manage security incidents. The method is based on resilient thinking, and describes how to identify, select and implement early-warning indicators for information security incident management.