Incident Response Protocol
Active1. Purpose & Scope
This document defines the standardized procedures for identifying, responding to, and recovering from security incidents affecting Aevum News operations. The protocol ensures minimal disruption to newsroom workflows, protects subscriber and editorial data, maintains platform availability, and upholds our commitment to journalistic integrity and reader trust.
Every employee, contractor, and agency partner must familiarize themselves with this protocol. Failure to follow established response procedures may result in escalated impact, compliance violations, and disciplinary action.
2. Incident Classification & Severity Levels
Incidents are categorized by impact severity to determine response priority, resource allocation, and communication cadence. Initial triage must occur within 15 minutes of detection.
| Severity | Definition | Response SLA | Examples |
|---|---|---|---|
| P1 - Critical | Complete service outage, active data breach, or severe editorial pipeline compromise | Immediate / 24-7 War Room | DDoS on live site, ransomware on CMS, PII exposure, content injection/tampering |
| P2 - High | Major feature degradation, partial data leak, or significant performance impact | 30 min / Dedicated IRT | Payment processing failure, CDN cache poisoning, API rate-limit breach |
| P3 - Medium | Localized impact, non-critical system anomaly, or minor data inconsistency | 2 hours / On-call rotation | Single editor account lockout, ad-blocker detection failure, delayed push notifications |
| P4 - Low | Cosmetic issue, theoretical vulnerability, or low-impact misconfiguration | 24 hours / Standard ticketing | Broken internal link, outdated dependency, minor UI rendering issue |
3. Incident Response Team (IRT) Roles
Clear role assignment prevents command fragmentation during high-stress events. The Incident Commander retains final authority over technical and communicative decisions.
- Incident Commander (IC): Owns the response timeline, makes escalation decisions, coordinates across departments, and approves external communications.
- Technical Lead: Directs engineers, architects containment strategies, oversees eradication, and validates system recovery.
- Communications Lead: Manages internal status updates, drafts reader/editorial notifications, and coordinates with Legal/PR.
- Scribe/Coordinator: Logs all actions, timestamps decisions, tracks SLA compliance, and maintains the incident timeline.
- Legal & Compliance: Advises on regulatory obligations (GDPR, CCPA, FTC), data breach disclosure requirements, and insurance notification.
4. Response Workflow
All incidents follow a structured five-phase lifecycle. Deviations require explicit IC approval and justification.
Preparation & Prevention
Ongoing maintenance of detection tools, access controls, backup verification, and threat intelligence feeds. Quarterly tabletop exercises simulate P1/P2 scenarios.
Detection & Triage
- Verify alert authenticity; rule out false positives
- Assign initial severity based on impact matrix
- Notify IC and provision incident channel
- Begin timeline documentation
Containment
- Isolate affected systems (network segmentation, service toggles, read-only modes)
- Preserve forensic artifacts before remediation
- Implement temporary workarounds for critical newsroom operations
Eradication & Recovery
- Remove root cause (malware, misconfig, compromised credentials)
- Restore from verified backups if data integrity is compromised
- Gradual service restoration with monitoring checkpoints
- Validate CMS publishing pipeline and subscriber notification flows
Post-Incident Review
- Conduct blameless post-mortem within 5 business days
- Document root cause, timeline gaps, and improvement actions
- Update runbooks, detection rules, and this protocol as needed
5. Communication Protocol
Transparent, timely communication prevents speculation and maintains trust. All external messaging requires Legal/PR sign-off.
Internal Channels
#incident-[id]Slack channel: Real-time technical coordination#status-allstaff: Summary updates every 60 minutes during active incidents- War Room Bridge: Conference call for P1/P2 with IRT + Exec Sponsor
External & Editorial Coordination
- Readers: Status page updates, in-banner notifications, and email digests for P1/P2 affecting content access
- Advertising Partners: Revenue impact notices within 4 hours of confirmed ad-tech disruption
- Editorial Desk: Direct liaison with Managing Editor to adjust publishing workflows, delay live blogs, or switch to offline drafting if CMS is impaired
6. Documentation & Reporting
Every incident must be documented using the standardized template hosted in the internal knowledge base. Required fields include:
- Incident ID, severity, and timestamps (detection, containment, resolution, recovery)
- Affected systems, data classes, and user impact metrics
- Technical root cause and contributing factors
- Actions taken during each phase
- SLA compliance status
- Corrective and preventive measures (CAPA)
Records are retained for 7 years per compliance requirements. Access is restricted to IRT members, Legal, and Auditors.
7. Training & Updates
This protocol is a living document. Effectiveness depends on continuous reinforcement and adaptation to emerging threats.
- Onboarding: Mandatory incident response module for all technical and editorial staff
- Drills: Quarterly tabletop exercises; bi-annual live simulation of P1 scenarios
- Review Cycle: Quarterly minor updates; annual comprehensive revision aligned with threat landscape shifts
- Change Log: All amendments tracked in version control with author, date, and justification
8. Contact & Escalation
| Role | Primary | Backup | Escalation Trigger |
|---|---|---|---|
| Incident Commander | CISO | VP Engineering | Any P1/P2 detection or unresolved P3 > 4hrs |
| Technical Lead | Lead SRE | Infrastructure Architect | System compromise, data exfiltration, or CMS failure |
| Communications Lead | Head of Comms | Director of PR | Reader-facing impact or media inquiry |
| Legal & Compliance | General Counsel | Data Privacy Officer | PII breach, regulatory scope, or insurance claim |
security@aevumnews.internal or the 24/7 hotline: +1 (800) 555-0199. Do not attempt independent remediation without IRT authorization.