Incident Response Policy

Version 2.0Effective 1 June 2026

10.1 Purpose

This policy outlines Keepr's procedures for detecting, responding to, and recovering from security incidents and data breaches.

10.2 Incident Classification

SeverityDescriptionResponse Time
CriticalData breach, system compromiseImmediate (< 1 hour)
HighUnauthorised access attempt, malware4 hours
MediumSecurity misconfiguration, suspicious activity24 hours
LowMinor security event, informational72 hours

10.3 Incident Response Procedure

  • Detection & Reporting: automated monitoring, user reports, third-party notifications, audits.
  • Initial Response: confirm validity, assess severity and scope, activate the response team, document.
  • Investigation: collect evidence and logs, analyse root cause, determine affected data/users.
  • Containment: isolate affected systems, stop the attack, prevent further damage, preserve evidence.
  • Eradication: remove attacker access, patch vulnerabilities, restore to a clean state, verify.
  • Recovery: restore from backups, bring systems online, monitor for re-infection.
  • Notification: notify affected users within 72 hours and authorities where required.
  • Post-Incident Review: document lessons learned, update procedures, implement preventive measures.

10.4 Communication Plan

Internal communication covers response-team activation, status updates, executive briefings, and debriefs. External communication covers user notification within 72 hours, authority notification where required, and transparent, factual information.

10.5 Roles & Responsibilities

RoleResponsibility
Incident CommanderOverall coordination and decision-making
Security LeadInvestigation and technical response
Communications LeadInternal and external communication
Legal LeadRegulatory compliance and notification
Operations LeadSystem restoration and recovery

10.6 Contact