Legal document
Incident Response Plan
How Desklly detects, contains, investigates, and communicates security incidents and personal data breaches.
1. Objectives
Protect people first, contain and eradicate the incident, restore normal service, meet regulatory obligations, and learn from the event.
2. Definitions
Security incident: any event that compromises or threatens the confidentiality, integrity, or availability of Desklly systems or data. Personal data breach: a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
3. Detection
Incidents are detected via automated alerts, log monitoring, staff reports, customer reports, and third-party notifications. All personnel are trained to report suspected incidents to info@desklly.ai immediately.
4. Triage and severity
Sev-1: confirmed breach of personal data, or full service outage. Sev-2: partial outage or high-risk vulnerability. Sev-3: low-impact issue with a workaround. The on-call engineer triages within 15 minutes of alert.
5. Response team
The Incident Commander leads the response, supported by engineering, DPO, and (for Sev-1) legal and executive leadership. Roles and contact rotas are maintained in the internal runbook.
6. Containment and eradication
Immediate steps include isolating affected systems, rotating credentials, revoking sessions, and blocking hostile IPs. Root cause is investigated and eliminated before restoration.
7. Recovery
Systems are restored from clean state and monitored closely for recurrence. Data integrity is validated against backups where necessary.
8. Notification
For confirmed personal data breaches, Desklly will notify affected controllers within 24 hours of confirmation, with sufficient detail to enable them to meet the 72-hour ICO notification requirement under Article 33 UK GDPR. Where required, Desklly will support the controller in notifying data subjects without undue delay.
9. Post-incident review
A blameless post-incident review is held within 10 working days of a Sev-1 or Sev-2 incident. Actions are tracked to closure and lessons feed back into policy and training.
10. Testing
The plan is tested by tabletop exercise at least annually.
