Incident Response & Staff Training
GDPR breach response runbook, on-call rotation, tabletop drill record and mandatory training curriculum.
7-phase breach response sequence
- 1
Detect
0–15SIEM auto-alert → on-call security engineer paged via PagerDuty. Triage severity using NIST SP 800-61.
- 2
Contain
15–60Isolate affected systems, revoke compromised credentials, rotate secrets in AWS Secrets Manager, snapshot evidence.
- 3
Assess
1–4hForensic team scopes data categories impacted, identifies data subjects, reviews access logs and IDS evidence.
- 4
Notify
4–72hDPO submits notification to lead supervisory authority (ICO) within 72h. Inform affected data subjects when high risk.
- 5
Eradicate
1–7dPatch root cause, redeploy clean infra, run validation scans, force-rotate user sessions and API tokens.
- 6
Recover
1–14dRestore from validated backups, monitor for re-occurrence, communicate restoration status via status page.
- 7
Review
14–30dPost-incident review (blameless), update runbook & training, regulatory follow-up, board-level reporting.