Incident response
An incident is managed in hours, not meetings: qualify, contain, notify within 72 hours, inform. Each step is timestamped in the register.
Response process
T+0
Qualifier
Log the incident here: nature, scope, number of people affected. The detection timestamp starts the 72-hour countdown.
T+2 h
Confiner
Revoke exposed API keys, suspend compromised accounts, isolate the affected module. In Sanctuary mode, encrypted files remain unreadable without the local key.
T+24 h
Assess the risk
Determine if the incident poses a risk to the rights and freedoms of individuals. Document the decision, even when it concludes that no notification is required.
T+72 h
Notify the authority
Notify the competent supervisory authority in your jurisdiction. Switching to "Notified" status timestamps this step in the register.
Après
Informer & corriger
Inform the individuals concerned if the risk is high, publish corrective measures, and close the incident with the action plan.
Incident log
Join or create an organisation to use this feature.
