Legal document

Incident Response Plan

How Desklly detects, contains, investigates, and communicates security incidents and personal data breaches.

Version 1.0Last updated 7 July 2026Governing law England & Wales

1. Objectives

Protect people first, contain and eradicate the incident, restore normal service, meet regulatory obligations, and learn from the event.

2. Definitions

Security incident: any event that compromises or threatens the confidentiality, integrity, or availability of Desklly systems or data. Personal data breach: a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

3. Detection

Incidents are detected via automated alerts, log monitoring, staff reports, customer reports, and third-party notifications. All personnel are trained to report suspected incidents to info@desklly.ai immediately.

4. Triage and severity

Sev-1: confirmed breach of personal data, or full service outage. Sev-2: partial outage or high-risk vulnerability. Sev-3: low-impact issue with a workaround. The on-call engineer triages within 15 minutes of alert.

5. Response team

The Incident Commander leads the response, supported by engineering, DPO, and (for Sev-1) legal and executive leadership. Roles and contact rotas are maintained in the internal runbook.

6. Containment and eradication

Immediate steps include isolating affected systems, rotating credentials, revoking sessions, and blocking hostile IPs. Root cause is investigated and eliminated before restoration.

7. Recovery

Systems are restored from clean state and monitored closely for recurrence. Data integrity is validated against backups where necessary.

8. Notification

For confirmed personal data breaches, Desklly will notify affected controllers within 24 hours of confirmation, with sufficient detail to enable them to meet the 72-hour ICO notification requirement under Article 33 UK GDPR. Where required, Desklly will support the controller in notifying data subjects without undue delay.

9. Post-incident review

A blameless post-incident review is held within 10 working days of a Sev-1 or Sev-2 incident. Actions are tracked to closure and lessons feed back into policy and training.

10. Testing

The plan is tested by tabletop exercise at least annually.