Skip to content

Incident Management & Breach Response (Annex A.5.24)

1. Reporting an Incident

Any staff member discovering a suspected security event (lost laptop, phishing email clicked, unusual account behavior) must immediately report it: * Emergency Slack / Teams: #incident-response * Email Hotline: security@yourdomain.com


2. Response Lifecycle

[1. Detection & Triage] ➔ [2. Containment] ➔ [3. Eradication] ➔ [4. Recovery] ➔ [5. Post-Incident Review]
  1. Detection & Triage: Determine scope, affected systems, and data classification.
  2. Containment: Isolate affected endpoint from network; revoke active OAuth/M365 session tokens; rotate credentials.
  3. Eradication: Identify root cause, wipe/reimage machines, patch exploited vulnerabilities.
  4. Recovery: Restore verified clean data from immutable cloud backups; monitor system behavior.
  5. Post-Incident Review: Document timeline, lessons learned, and update risk registers within 5 business days.

3. Statutory Breach Notification (UK GDPR / ICO)

If personal data is compromised presenting a risk to individuals' rights and freedoms: * The Data Protection Officer (DPO) and Executive Management must be notified immediately. * Formal notification to the Information Commissioner's Office (ICO) must occur within 72 hours of becoming aware.