Trust

Incident response template

Replace bracketed fields and have security/counsel approve this plan.

Intake and severity

  • Severity 1: confirmed or strongly suspected unauthorized access, destructive loss, material cross-tenant exposure, or service-wide outage.
  • Severity 2: significant degradation or security weakness with credible exposure but no confirmed material access.
  • Severity 3: limited defect with a workaround and no expected confidentiality/integrity impact.

Report to [security contact]. The incident commander records detection time, systems/data/users affected, containment decisions, evidence preservation, and every notification.

Response sequence

  1. Validate and assign severity without destroying evidence.
  2. Contain credentials, sessions, network routes, or affected deployment.
  3. Preserve logs and snapshots under documented access control.
  4. Determine tenant/data scope; do not infer one customer's exposure from another's.
  5. Notify the institution within the contracted window after a reportable incident is confirmed, with known facts, mitigations, and next update time.
  6. Eradicate root cause, restore from a verified state, monitor for recurrence, and obtain customer approval where contractually required.
  7. Deliver a post-incident report with timeline, impact, root cause, corrective actions, and evidence of completion.

Run at least one tabletop and one restore exercise annually and after material architecture changes.

Next: accessibility