Incident Response Plan

Revised · policies/INCIDENT-RESPONSE.md ↗ · 0fa48e326878 ↗

Our CEO leads every incident. Anyone can report one through our security.txt.

Steps

  1. Triage: confirm it, decide if it's a breach, and start a dated log
  2. Contain: preserve logs, then revoke credentials, block access, or take the affected service offline
  3. Recover: fix the cause, restore from backup if needed, and confirm it's gone
  4. Review: within two weeks, write up what happened and what we changed

Notification

A breach is any unauthorized access to, or loss, change, or disclosure of, customer data, or any compromise of production.

  • Customers: within 24 hours of discovering a breach
  • Regulators: as the law requires—within 72 hours under GDPR
  • Affected people: without undue delay, when the risk to them is high
  • The public: our review, minus anything that identifies a customer

Testing

We rehearse this plan yearly with a tabletop exercise and keep the notes.