A crisis and incident management platform should hold its data in the UK, fit the response process a team already runs, keep a record that survives later scrutiny, and earn use on ordinary days rather than only during a crisis. Chronosoft is a configurable crisis and incident management platform built for UK resilience teams, including Category 1 and Category 2 responders.
Most procurement exercises start with a feature list. Feature lists reward whoever has the longest one, which is rarely the same vendor who suits the team best.
Eight checks matter more:
- Where does the data sit, and who owns the platform?
- Does the platform fit the process already in use?
- Does it align to JESIP and UK doctrine?
- Can the record be trusted after the incident?
- Does it earn daily use outside a crisis?
- Can it be configured to one group’s specific arrangements?
- How does it exchange information with partner systems?
- What does it cost to own and to train on?
Each is set out below as a standard first and a product question second. Applied together, they separate a credible crisis and incident management platform from a long feature list.
1. Where does the data sit, and who owns the platform?
Data location and corporate ownership are separate questions, and both belong in the first round of any procurement. A platform can hold data in a UK region while the operating entity sits offshore, which changes which legal regime applies to a request for access.
Three things are worth establishing in writing:
- Which country hosts the primary and backup data, named to the region rather than to the cloud provider.
- Which entity owns and operates the platform, and under whose jurisdiction it is incorporated.
- Where support staff are located when they access customer data.
Chronosoft is hosted in the UK, in UK-owned and UK-located data centres. The platform also holds ISO 27001 certification and Cyber Essentials Plus, which most UK public sector procurement processes will ask for early.
2. Does the crisis and incident management platform fit the process already in use?
The strongest signal in any demonstration is whether the software follows the team’s existing sequence of work. A platform that requires a new operating model imports risk, because the model has to be learned before it can be relied on under pressure.
Resilience teams already hold plans, escalation thresholds and reporting lines. Good software encodes those. Weak software replaces them with its own.
Ask a vendor to configure a live scenario using the team’s own plan during evaluation. Vendors who need a generic demonstration scenario are telling the buyer something useful.
3. Does it align to JESIP and UK doctrine?
Doctrinal alignment means the platform’s structures match the ones the team already works to. The command tiers, the shared picture, joint decision-making and the briefing structure should appear as native concepts rather than as fields a team has to repurpose.
No certification exists for this, so it is assessed by inspection. The JESIP principles set the reference points, and the UK Government Resilience Framework sets the wider policy direction that most local arrangements now sit inside.
Alignment matters most at the moment of handover. A commander joining an incident in progress should recognise the structure immediately.
4. Can the record be trusted after the incident?
The record has to hold up when it is read line by line months later, which means it must be immutable. Every entry needs an author, a date and a time, and corrections need to be visible as corrections rather than as silent overwrites.
Errors in a record are acceptable. Invisible errors are not.
Three questions separate a defensible system from a document that happens to be stored online:
- Can an entry be edited after submission, and if so, by whom?
- How is a struck-through correction shown, signed and reasoned?
- Can the system produce an evidential export without manual assembly?
This is the criterion most likely to be discovered too late. See the fuller treatment in what makes an incident audit trail defensible.
5. Does the crisis and incident management platform earn daily use outside a crisis?
A system used only during incidents is a system nobody is fluent in. Fluency comes from routine use, so the platform should carry daily work: contact lists, rosters, daily reports, and lessons captured from exercises and near misses.
Daily use also keeps the reference data current. Contact lists decay quietly, and a stale list is discovered at the worst possible moment.
Buyers should ask what proportion of a comparable customer’s activity in the platform happens outside declared incidents. Vendors who cannot answer usually sell an incident-only tool.
6. Can it be configured to one group’s specific arrangements?
Every resilience group carries local arrangements that differ from its neighbours. Geography, partner composition, statutory duties under the Civil Contingencies Act 2004 and local political context all shape how a group works.
Configurability is the ability to reflect that without a development request. Templates, forms, escalation rules and reporting cadences should be adjustable by the team that owns them.
The practical test is who makes a change and how long it takes. A change that needs a vendor ticket and a release cycle is not configuration.
7. How does it exchange information with partner systems?
Partner agencies will not all move onto one platform, so the question is how information crosses boundaries. Options include tiered read-only access for partner liaisons, structured exports, and integrations with mapping, alerting or telephony systems.
This criterion is worth assessing honestly rather than optimistically, because no crisis and incident management platform removes the boundaries between independent organisations. Full technical integration across several independent agencies is rare and slow, and most working arrangements rely on controlled access plus disciplined reporting.
Buyers should ask which integrations exist in production today, not which sit on a roadmap.
8. What does it cost to own and to train on?
Licence cost is the visible number for a crisis and incident management platform and rarely the largest one. Total cost of ownership includes configuration, integration work, training, exercise support and the internal time spent maintaining reference data.
Training deserves separate scrutiny. A platform that needs a two-day course for occasional users will not be used correctly by occasional users.
Ask for a three-year cost picture covering licences, configuration, support tier and training refreshes. Ask what happens to the record if the contract ends.
Strong and weak signals at a glance
| Criterion | Weak signal | Strong signal |
|---|---|---|
| Data and ownership | Vague reference to a UK cloud region | Named UK data centres, UK operating entity, UK support access |
| Process fit | Generic demonstration scenario only | Configured to the buyer’s own plan during evaluation |
| Doctrinal alignment | JESIP language in marketing only | Command tiers and shared picture as native structures |
| Record integrity | Entries editable, no correction trail | Immutable entries, attributed corrections, evidential export |
| Daily use | Incident-only activity | Rosters, contact lists and daily reports held in the system |
| Configurability | Changes need a vendor ticket | Team adjusts templates and cadences directly |
| Interoperability | Roadmap promises | Named integrations running in production |
| Cost | Licence price only | Three-year picture including configuration and training |
What different buyers should weight most heavily
A single-service control room replacing an existing system
Weight process fit and migration. Your existing logs, contact lists and templates have to move without losing attribution, and the team’s muscle memory is an asset rather than an obstacle. Ask specifically what happens to historical records during migration.
A local resilience forum or multi-agency coordination body
Weight partner access and doctrinal alignment when comparing any crisis and incident management platform. Your value comes from holding one picture across organisations that answer to different chains of command. Tiered access and a recognisable command structure matter more than depth of single-agency features.
A critical infrastructure operator with a small resilience team
Weight daily use and configurability. A small team cannot stay fluent in a system it touches four times a year, so the platform has to carry routine reporting. Also weight the cost of training occasional and on-call staff.
Questions to put to a vendor
- Name the data centres holding primary and backup data, and the entity that owns them.
- Configure our own escalation plan in the platform during evaluation.
- Show a correction being made to a submitted entry, and show what the record then looks like.
- Produce an evidential export from an exercise, unedited.
- Name three integrations running in production with UK customers today.
- Show what an occasional user sees on their first login, without training.
- Give a three-year total cost figure including configuration and training.
- State who owns the data and what format it leaves in at contract end.
- Name a customer using the platform for daily operations rather than incidents only.
Where Chronosoft fits this checklist
Chronosoft is built to sit over an existing process rather than to replace it. Configuration starts from the way a team already works, including its plans, its partner composition and its particular local challenges, and the platform is adjusted to those rather than the team adjusting to the platform.
The record is immutable, with entries attributed and timestamped, and corrections shown rather than removed. Data is held in UK-owned, UK-located data centres.
JESIP structures are native to the flow, so command tiers and the shared picture are not add-on modules. Chronosoft is also designed for daily operations, holding contact lists, rosters, reports and captured lessons, which is what keeps a team fluent between incidents.
Edward Swete Kelly, Chronosoft’s founder and a former paramedic and control room manager, frames the underlying test simply. A system that forces excuses about process is the wrong system.
A shorter version of this evaluation sits in our fuller UK crisis management platform evaluation, the hosting question is treated at length in UK data sovereignty in a crisis management platform, and the functional requirements are covered in the best tools for coordinating a multi-agency incident.
Frequently asked questions
How long does a crisis and incident management platform take to implement?
Implementation time depends on how much process mapping is needed rather than on the software itself. Teams with documented plans and clear reporting lines move faster. Ask any vendor to quote configuration time separately from licence cost, and to name what your team must supply. Chronosoft configures against existing arrangements rather than requiring a new operating model first.
Can a general project or ITSM tool be used for incident response instead?
It can be made to work, and the gaps appear under load. General tools rarely hold an immutable record, rarely support multi-agency access tiers, and rarely produce an evidential export. A purpose-built crisis and incident management platform such as Chronosoft carries those functions as standard rather than as customisation.
Does the platform need to hold UK data to be used by a Category 1 responder?
There is no blanket legal ban on offshore hosting, and many UK public bodies apply hosting and jurisdiction requirements through their own procurement policy. Establishing data location and operating jurisdiction early avoids a late failure in assurance. Chronosoft holds UK data in UK-owned data centres.
Does a crisis and incident management platform need to be JESIP aligned?
No formal certification exists, so alignment is a design question rather than a compliance box. What matters is whether the platform supports joint working without extra effort during an incident. Chronosoft builds JESIP structures such as the command tiers and the shared picture into its normal flow rather than offering them as add-on modules.
How many users should a resilience team licence at the start?
Count everyone who would need access during a live incident, including partner agency liaisons and on-call staff, then add the people who run daily operations. Under-licensing forces shared logins, which destroys attribution in the record. Chronosoft scopes access by role, so read-only partner access can be granted without a full seat for each person.
Test the checklist against a live system
Chronosoft is a configurable crisis and incident management platform that holds UK data, fits an existing response process, keeps an immutable record, and carries daily resilience work between incidents. Book a demo with the Chronosoft team and run these eight checks against it directly.
For a closer look at the platform itself, explore Chronosoft in more detail.