Account Setup & Onboarding
Detailed walkthrough of the 6-step onboarding wizard.
Overview
When you first sign in to CrownSync Playbooks, you are guided through a six-step onboarding wizard that builds your organisation profile. This profile drives the personalisation engine — determining which playbook sections are shown, which regulatory templates are included, and how escalation paths and contact details are structured throughout the platform.
This page provides a detailed walkthrough of each step so you know exactly what to expect and how your answers affect your playbooks.
Step 1: Find Your Organisation
The first step asks you to identify your organisation. You have two options:
Companies House Lookup
If your organisation is registered at Companies House, you can search by company name or company number. CrownSync uses the Companies House API to retrieve your registered company name, company number, registered address, SIC codes, and incorporation date. This pre-populates your organisation record so you do not need to type these details manually.
SIC codes are used to suggest your sector in the next step. For example, a company with SIC code 64110 (Central banking) would be suggested for the Financial Services sector.
Warning
Manual Entry
If your organisation is not registered at Companies House — for example, NHS trusts, local authorities, charities registered only with the Charity Commission, sole traders, or overseas subsidiaries operating in the UK — you can enter your details manually. You will need to provide your organisation name, registered address, and a brief description of your organisation type.
Step 2: Confirm Your Sector
Your sector is one of the most important personalisation inputs. It determines which regulatory frameworks apply to your organisation and which playbook sections, communication templates, and reporting deadlines are shown.
Available sectors include:
- Financial Services— triggers FCA and PRA notification requirements, PCI DSS considerations, and financial sector-specific containment steps.
- Healthcare (NHS)— triggers DSPT compliance sections, DHSC and NHS England notification requirements, and patient-data-specific handling instructions.
- Legal— triggers SRA notification obligations and client confidentiality considerations.
- Government & Public Sector— triggers NCSC reporting, GovAssure alignment, and official classification handling.
- Education— triggers DfE and Jisc notification guidance and student data protection considerations.
- Retail & E-commerce— triggers PCI DSS sections and customer data breach notification templates.
- Technology— triggers NIS Regulations considerations for digital service providers.
- Manufacturing, Energy & Utilities, Professional Services, Other— each with appropriate regulatory mappings.
If Companies House SIC codes were retrieved in Step 1, the wizard suggests a sector based on those codes. You can accept the suggestion or choose a different sector if it does not accurately reflect your primary business.
Step 3: Technology Stack
This step asks about the security and IT tools your organisation uses. Your answers ensure that playbook instructions reference the correct products and interfaces rather than generic placeholders. Each field is optional — leave it blank if your organisation does not use a tool in that category.
SIEM (Security Information and Event Management)
Your SIEM is referenced in detection and analysis steps. If you use Microsoft Sentinel, Splunk, CrowdStrike Falcon LogScale, IBM QRadar, or another platform, select it here. Playbook instructions will include specific queries and alert references for your chosen SIEM.
EDR (Endpoint Detection and Response)
Your EDR tool is referenced in containment and eradication steps. Options include Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Sophos Intercept X, and others. Playbooks will reference the correct isolation and remediation actions for your endpoint platform.
Email Platform
Whether you use Microsoft 365, Google Workspace, or another provider, this affects how email-based incidents (phishing, BEC, account compromise) are investigated and remediated. Playbooks include platform-specific steps for message tracing, mailbox auditing, and transport rule configuration.
Cloud Provider
Select your primary cloud provider (Microsoft Azure, AWS, Google Cloud Platform, or other). Cloud compromise and data exfiltration playbooks reference your provider's specific security tools, logging services, and access management interfaces.
Identity Provider
Your identity provider (Microsoft Entra ID, Okta, Google Workspace, Ping Identity, etc.) is referenced in account compromise, credential theft, and access control playbook sections. Steps will reference the correct interface for resetting passwords, revoking sessions, and reviewing sign-in logs.
ITSM (IT Service Management)
If your organisation uses a service desk platform (ServiceNow, Jira Service Management, Freshservice, Zendesk, Hornbill, ManageEngine, or others), playbook steps reference it for ticket creation, escalation procedures, and change management. This also enables the integration features for automated ticket synchronisation.
Step 4: Organisation Context
This step captures broader organisational information that influences playbook content and escalation paths.
Organisation Size
Select your approximate employee count from the provided ranges (e.g., 1–50, 51–250, 251–1000, 1000+). Larger organisations typically have more complex incident response processes, more stakeholders to notify, and more detailed communication requirements. Playbooks adjust their escalation paths and role assignments accordingly.
IT Team Type
Indicate whether your IT function is managed in-house, fully outsourced to a managed service provider, or a hybrid arrangement. This affects who is responsible for technical containment and eradication steps in your playbooks. If outsourced, playbooks include steps for engaging your MSP and coordinating with their incident response procedures.
Data Protection Officer
Indicate whether your organisation has a designated Data Protection Officer (DPO). If you do, playbooks include DPO notification and consultation steps at the appropriate points — particularly around ICO reporting decisions and data subject notifications. If you do not have a DPO, these steps are adjusted to reference the senior person responsible for data protection.
Cyber Insurance
Indicate whether your organisation holds a cyber insurance policy. If you do, playbooks include early-stage steps to notify your insurer, as many policies require notification within specific timeframes. Insurer notification is also included in communication templates. If you do not hold a policy, these steps are omitted to keep your playbooks focused.
Step 5: Incident Command Structure
Choose the incident command model that best fits your organisation. This determines the roles, responsibilities, and escalation paths used throughout your playbooks.
Simple (Incident Lead)
Best for smaller organisations or those with less complex incident response requirements. A single incident lead coordinates the response, with support from IT and management as needed. Playbooks use straightforward escalation paths with minimal role differentiation.
Silver/Gold Command
Common in UK public sector organisations, NHS trusts, and larger enterprises. Silver Command handles the tactical response (containment, eradication, recovery), while Gold Command handles strategic decisions (external communications, regulatory notifications, business continuity). Playbooks clearly delineate which actions belong to each command level.
Full Incident Command System
For organisations with mature incident response capabilities that use multiple functional roles: Incident Commander, Operations Lead, Communications Lead, Legal/Compliance Lead, Technical Lead, and others. Playbooks assign specific actions to each role and include coordination checkpoints between them.
Information
Step 6: Review and Confirm
The final step presents a summary of everything you have entered across the previous five steps. Review each section carefully:
- Organisation name, company number, and registered address
- Selected sector and inferred regulatory requirements
- Technology stack selections
- Organisation size, IT team type, DPO status, and insurance status
- Chosen incident command model
If anything needs correcting, use the Back button to return to the relevant step. Once you are satisfied, click Confirm & Continue to complete onboarding.
What Happens After Onboarding
When you confirm your organisation profile, CrownSync Playbooks immediately processes your inputs and:
- Personalises all 42 playbooks— the personalisation engine evaluates each playbook section's conditions against your profile and shows only the sections, steps, templates, and deadlines that are relevant to your organisation.
- Populates your dashboard— your readiness score starts at zero and increases as you review and customise playbooks. The dashboard shows your personalised playbook library, quick actions, and activity feed.
- Pre-fills communication templates— your organisation name, company number, registered address, DPO details, and sector-specific regulatory references are populated into all communication templates.
- Sets up your audit log— from this point forward, every action on the platform is recorded in the immutable audit log for compliance evidence.
You are now ready to start exploring your playbooks. Head to the Quick Start Guide for recommended next steps, or jump straight into the playbook library to review your personalised content.
Tip
pb.crownsync.uk/dashboard for quick access. The dashboard is your central hub for all incident response activities.Was this page helpful?