Technophobia Logo
Incident Response & Breach Policy

Last updated: 14 September 2025

This policy sets out how Technophobia Ltd handles security incidents and personal data breaches. It supports our Information Security Policy and DPA.

1. Scope and goals
  • Applies to our people, systems, and client environments we manage.
  • Goals: fast detection, containment, recovery, and honest communication.
  • Personal data breaches follow UK data protection law and our DPA.
2. Definitions
  • Security incident: any event that harms confidentiality, integrity, or availability.
  • Personal data breach: accidental or unlawful loss, alteration, or unauthorised access to personal data.
3. Roles and responsibilities
  • Security Lead (Director): leads response, decides severity, handles regulators.
  • Incident Manager: runs the plan, logs actions, coordinates the team.
  • Technical Lead: investigates, contains, and fixes.
  • Comms Lead: drafts client and internal updates.
  • All staff: report suspected incidents immediately.
4. Severity levels and targets
LevelDefinitionFirst responseContainment target
P1 Active breach or outage; client impact; data at risk 30 mins 4 hours
P2 High-risk weakness or limited impact 2 hours 1 business day
P3 Minor issue or false positive 1 business day As scheduled

Times align with our SLA for supported systems.

5. Detection and reporting
  • Sources: monitoring alerts, access anomaly alerts, user reports, vendor advisories.
  • Report immediately by email or phone to the Security Lead and your project channel.
  • Do not delete evidence or reboot affected hosts unless told to by the Incident Manager.
6. Triage and assessment
  • Confirm the incident, set severity, assign roles, open an incident log.
  • Identify systems, data types, and time window. Preserve logs and snapshots.
  • Decide if personal data is involved and which clients are affected.
7. Containment
  • Rotate tokens and passwords; revoke suspicious sessions.
  • Isolate hosts, disable webhooks, or pause workflows where needed.
  • Apply vendor patches or configuration blocks.
8. Eradication and recovery
  • Remove malware or backdoors; clean configs and dependencies.
  • Restore from known-good backups; validate integrity and access logs.
  • Return services to normal; monitor closely for recurrence.
9. Notification and communication
  • Clients: notify affected clients promptly with facts, scope, and actions.
  • Personal data: if there is likely risk to people, notify the UK ICO within 72 hours of awareness and affected clients/users as required. We support controllers per the DPA.
  • Records: keep time-stamped notes, decisions, and evidence.

Client update template

  • Subject: Incident notice – [system], [date/time UTC]
  • Summary: what happened, when detected, and current status.
  • Impact: systems/data affected; who is impacted.
  • Actions taken: containment and recovery steps.
  • Next steps: monitoring, fixes, and any client actions.
  • Contact: name and phone for follow-up.
10. Evidence handling
  • Export logs, configs, and hashes to a secure folder with restricted access.
  • Record who accessed evidence and when.
  • Keep copies for at least 12 months or longer if required by contract or law.
11. Post-incident review
  • Within 10 business days, complete a short root cause analysis.
  • Agree actions: fixes, tests, docs, training, or supplier changes.
  • Share a summary with affected clients (P1/P2).
12. Testing and readiness
  • Run an incident drill at least yearly.
  • Test backup restores twice a year for hosted components.
  • Verify alerting works after major platform changes.
13. Third parties and clients
  • Track vendor advisories (e.g., n8n, WordPress, Stripe, Twilio, OpenAI).
  • If the cause is a third-party outage, keep clients updated and provide workarounds where possible.
  • For client-owned environments, follow their runbooks plus this policy as a minimum.
Contact and reporting

Report incidents immediately:

Technophobia Ltd · Company No. 14898332 · VAT GB 495 7043 58
13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom
hello@technophobia.uk · +44 1229 774591

Technophobia

n8n automation for small teams. UK-based. Fast turnarounds. Clear handovers.

Address
South Cumbria Skills Exchange
Millom
LA18 4JS
United Kingdom

Phone +44 01229 774591
Email hello@technophobia.uk

VAT registered • GDPR-aligned • Typical lead time: 1–2 business days