Security & trust

Incident Response

A coordinated process for reporting, investigating and responding to security concerns.

Response responsibilities

Named technical leadership and deputy escalation provide ownership for incident handling. The response responsibilities cover assessing the report, coordinating technical work and managing the communication needed for the affected services.

The process brings together containment, investigation and recovery, with escalation based on severity and impact. Customer contacts and service arrangements help identify who needs to be involved in a service-specific response.

  • Defined leadership provides a route for decisions and escalation.
  • Technical response and communication responsibilities are coordinated.
  • Deputy arrangements support continuity when the primary contact is unavailable.

Report and respond

Contact our team to report a suspected security issue or operational concern. Give the affected service or feature, the approximate time, the behaviour observed and any safe steps that help explain the problem.

The incident process assesses severity, affected systems and information, then coordinates the appropriate response. Use the initial contact to arrange a suitable channel for sensitive evidence or detailed investigation material.

  • Describe the impact on users or service operations.
  • Include safe reproduction steps or a minimal test example where possible.
  • Keep credentials and personal information out of the initial message.
Contact our team

Contain, investigate and restore

Incident procedures guide containment of the affected systems and investigation of the information involved. Depending on the issue, actions can include restricting access, revoking credentials and coordinating recovery work.

Recovery includes verifying the restored service before returning to normal operation. Customer and regulatory communication requirements are considered alongside the applicable processing and service arrangements.

  • Contain the issue according to its severity and affected resources.
  • Investigate the cause and the information or operations involved.
  • Verify recovery and coordinate the required communication.
Explore continuity and recovery planning

Learning from incidents

Incident records and corrective actions help us address the causes of a problem after the immediate response. Follow-up review considers what happened, how the response worked and what should change.

Learning can feed into security controls, working procedures, training and continuity planning. Assigning and tracking corrective actions helps turn the review into improvements that can be checked later.

  • Record the issue, response decisions and relevant outcomes.
  • Investigate causes and identify preventive or corrective changes.
  • Track follow-up work through the management system.
Explore ongoing risk review
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.