Skip to main content

Security Incident Response Plan

Procedures for identifying, responding to, and recovering from security incidents

24/7 Security Incident Hotline

Email: security-incident@bundlecreator.co

For immediate security concerns outside business hours, email with "URGENT:" in subject line for priority response.

1. Incident Classification

Severity 1: Critical

Priority: Immediate action required

  • Active data breach with ongoing exfiltration
  • Complete system compromise or ransomware
  • Loss of encryption keys affecting multiple users
  • Unauthorized access to unencrypted user data

Severity 2: High

Priority: Urgent attention needed

  • Suspected breach with no active threat
  • Vulnerability discovered in production
  • Authentication system compromise
  • DDoS attack affecting availability

Severity 3: Medium

Priority: Standard handling

  • Failed intrusion attempts
  • Minor service disruptions
  • Non-critical vulnerability reports
  • Suspicious user activity patterns

Severity 4: Low

Priority: Routine processing

  • Security improvement suggestions
  • False positive alerts
  • Non-security bugs with security implications

2. Incident Response Team

Core Response Team Roles

Incident Commander

Responsible for: Overall incident coordination

  • Declares incident severity
  • Coordinates response efforts
  • Makes critical decisions
  • External communications

Technical Lead

Responsible for: Technical investigation and remediation

  • System analysis and forensics
  • Containment strategies
  • Recovery operations
  • Evidence preservation

Legal & Compliance Lead

Responsible for: Legal and regulatory compliance

  • Regulatory notifications (ICO, etc.)
  • User notifications
  • Legal documentation
  • Law enforcement liaison

Communications Lead

Responsible for: Internal and external communications

  • User notifications
  • Status page updates
  • Internal updates
  • Media relations (if needed)

3. Incident Response Procedures

Phase 1: Detection & Analysis

  1. Verify the incident is real (not false positive)
  2. Determine severity level (1-4)
  3. Activate response team based on severity
  4. Begin incident documentation
  5. Preserve evidence (logs, screenshots, artifacts)
  6. Initial impact assessment

Phase 2: Containment

  1. Isolate affected systems
  2. Disable compromised accounts
  3. Block malicious IPs/domains
  4. Implement temporary fixes
  5. Backup affected systems before changes
  6. Document all containment actions

Phase 3: Eradication & Recovery

  1. Remove malicious code/accounts
  2. Patch vulnerabilities
  3. Reset affected credentials
  4. Restore from clean backups if needed
  5. Verify system integrity
  6. Monitor for re-infection

Phase 4: Post-Incident Activities

  1. Complete incident report
  2. Conduct lessons learned meeting
  3. Update security controls
  4. User notifications (if required)
  5. Regulatory notifications (as required by law)
  6. Update response procedures

4. Communication Protocols

Internal Communications

  • Incident Email: security-incident@bundlecreator.co
  • Documentation: All incidents logged in secure incident management system
  • Updates: Every 30 minutes during active incident
  • Documentation: Shared incident document

External Communications

User Notifications

  • Email to affected users promptly
  • Regular status page updates
  • In-app notifications for active users

Regulatory Notifications

  • ICO notification as required by GDPR (if personal data breach)
  • Template available in incident response toolkit
  • Legal team approval required

5. Evidence Preservation

Critical Evidence to Preserve

  • System logs: Application, security, access, error logs
  • Network data: Firewall logs, IDS/IPS alerts, packet captures
  • User activity: Authentication logs, API calls, data access
  • System state: Memory dumps, running processes, connections
  • Communications: Emails, chat logs, support tickets

Important: All evidence must be preserved with chain of custody documentation. Use write-once media where possible.

6. Testing and Training

Testing Schedule

  • Monthly: Communication test
  • Quarterly: Tabletop exercise
  • Bi-annually: Full simulation
  • Annually: Third-party assessment

Training Requirements

  • All staff: Security awareness
  • Tech team: Incident response procedures
  • Leadership: Crisis management
  • New hires: During onboarding

Quick Reference: First 15 Minutes

  1. Verify the incident is real
  2. Email security-incident@bundlecreator.co with initial details
  3. Begin incident documentation in management system
  4. DO NOT: Delete logs, reboot systems, or modify evidence

Document Version: 1.1

Last Updated: December 2025

Next Review: May 2026