Incident response
What happens in the first 72 hours. Read it before, not during.
72 hours is the legal deadline to notify the supervisory authority of a breach. It starts when you become aware of the breach.
1. Who to call, immediately
- Incident lead (Segua.ai owner): first person activated, decides and coordinates. Reachable 24/7.
- Backup lead: second person with the same emergency credentials, if the first does not answer within 30 minutes.
- DPO or privacy advisor: involved within 4 hours of any suspicion involving personal data.
- Legal counsel: involved if end-customer data is affected or a regulator notification is needed.
- Vendors: hosting platform and AI provider, for logs and technical confirmation.
- Fill in real names and numbers in this section before going to production: a runbook without contacts is useless.
2. First 2 hours, containment
- Open a dedicated channel and a timeline document: every action with a UTC timestamp. Needed later for the notification.
- Revoke sessions: rotate admin account passwords and sign out all other sessions.
- Rotate keys: service API keys, database keys and AI service keys. A suspected key is a compromised key.
- Disable the affected endpoint or feature rather than leaving it open during the investigation.
- Freeze the logs: the activity log and AI call log are append-only and must not be edited or cleaned up.
- Delete nothing: compromised data is evidence. Isolate, do not destroy.
3. Within 24 hours, assessment
- What was touched: which tables, which projects, which users, which time window.
- Data categories: documents, transcripts (transcribed speech is personal data), emails, credentials.
- Number of data subjects, including meeting participants who are not Segua.ai users.
- Risk to people: confidentiality of business decisions, name exposure, identity theft potential.
- If risk to individuals' rights is excluded with written reasoning, notification to the supervisory authority is not required, but the assessment must be kept.
4. Within 72 hours, regulator notification
- The clock starts when you become aware of the breach, not when you fully understand it.
- Notify the competent data protection supervisory authority through its dedicated online procedure.
- Minimum content: nature of the breach, categories and approximate number of data subjects and records, contact point, likely consequences, measures taken or proposed.
- If you do not yet have all the information, notify anyway and follow up later: partial is better than late.
- Where Segua.ai acts as processor for a client, inform the controller without undue delay; the controller notifies the authority.
5. Communication to users
- Required when the breach is likely to result in a high risk to the rights and freedoms of individuals.
- Plain language: what happened, when, which data, what we are doing, what they should do (change password, enable 2FA), who to contact.
- No minimising and no blame-shifting to vendors.
- One voice: communication goes out from the incident lead only, not from individuals.
6. Afterwards, closure
- Blameless post-mortem within 7 days: technical root cause, how it was found, how long it lasted.
- Corrective actions with an owner and a date, verified at closure.
- Update the OWASP ASVS worklist and the ZAP scan, and record the incident in the breach register required by Art. 33(5) GDPR, even if not notified.
Internal runbook, not legal advice: have your DPO review it before making it binding.
