Incident response procedure

A practical response sequence, not an unsupported time promise.

This operational draft defines the response stages for suspected security, privacy or availability incidents. Contacts, decision authority, severity criteria and contractual notification terms must be completed before production use.

Draft for pilot review. This owner-authored template is not legal advice, has not been represented as lawyer-approved, and must be reviewed and completed for the contracting entity and jurisdiction before execution.
DocumentedRequires customer configuration
  1. 01

    Detect and report

    Record the time, source, affected service and known symptoms. Preserve relevant records. Security contact: To be completed before execution.

  2. 02

    Triage

    Assign an incident lead, classify suspected confidentiality, integrity, availability and worker-safety impact, and restrict information to those who need it.

  3. 03

    Contain

    Limit affected access, credentials, functions or integrations while preserving evidence. Avoid actions that increase risk to a reporter.

  4. 04

    Investigate

    Establish what happened, what data and organisations may be affected, the likely period, access path and confidence level. Separate confirmed facts from hypotheses.

  5. 05

    Assess impact

    Consider worker-identification or retaliation risk, customer operational impact, data-subject impact and applicable contractual or legal duties.

  6. 06

    Recover

    Remove the cause where possible, restore service in a controlled way, validate access and monitor for recurrence.

  7. 07

    Communicate

    Notify affected customer contacts based on the executed agreement and applicable law. Timing and regulator/data-subject duties remain subject to legal assessment; this draft promises no fixed hour count.

  8. 08

    Document and review

    Keep an incident record, decisions, evidence, communications and corrective actions. Complete a post-incident review and track agreed improvements.

Minimum incident record

Reporter and discovery route; timestamps; systems and organisations in scope; data categories; confirmed facts; decisions; containment and recovery; communications; legal assessment; corrective actions and owners.

Still to be completed

Security contact, customer escalation contacts, severity matrix, response roles, approved communication channel, notification window and jurisdiction-specific obligations. No 24/7 monitoring or response service is claimed.