Incident response template
Replace bracketed fields and have security/counsel approve this plan.
Intake and severity
- Severity 1: confirmed or strongly suspected unauthorized access, destructive loss, material cross-tenant exposure, or service-wide outage.
- Severity 2: significant degradation or security weakness with credible exposure but no confirmed material access.
- Severity 3: limited defect with a workaround and no expected confidentiality/integrity impact.
Report to [security contact]. The incident commander records detection time, systems/data/users affected, containment decisions, evidence preservation, and every notification.
Response sequence
- Validate and assign severity without destroying evidence.
- Contain credentials, sessions, network routes, or affected deployment.
- Preserve logs and snapshots under documented access control.
- Determine tenant/data scope; do not infer one customer's exposure from another's.
- Notify the institution within the contracted window after a reportable incident is confirmed, with known facts, mitigations, and next update time.
- Eradicate root cause, restore from a verified state, monitor for recurrence, and obtain customer approval where contractually required.
- Deliver a post-incident report with timeline, impact, root cause, corrective actions, and evidence of completion.
Run at least one tabletop and one restore exercise annually and after material architecture changes.
Next: accessibility