# Incident Response Policy

| Version | Effective | Approved | Last reviewed | Owner |
|---|---|---|---|---|
| 1.4 | October 2, 2026 | October 2, 2026 | October 2, 2026 | Brian Johnson, President |

!!!info About This Document
This policy defines how 7 Minute Security LLC prepares for, detects, responds to, and recovers from security incidents, including incidents affecting our own systems and those involving client data.
!!!

## 1. Purpose

Security incidents are not a matter of if, but when, even for a cybersecurity firm. This policy defines how 7MinSec prepares for, identifies, contains, eradicates, recovers from, and learns from security incidents. It also defines our obligations to clients when their data or systems may be affected.

## 2. Scope

This policy applies to all security incidents affecting 7MinSec internal systems (productivity suite, file storage, report authoring platform, and endpoints), client data held by 7MinSec at any stage of the retention lifecycle defined in our [Data Inventory & Classification Policy](https://kb.7minsec.com/trust/data-inventory-classification-policy), client environments that 7MinSec personnel are actively working in, and subcontractors acting on behalf of 7MinSec.

## 3. What Constitutes an Incident

| Incident Type | Description |
|---|---|
| Data breach | Unauthorized access to or disclosure of client data or 7MinSec credentials |
| Malware infection | Ransomware, spyware, or other malicious code on any 7MinSec or subcontractor endpoint |
| Credential compromise | Confirmed or suspected theft of a 7MinSec or client credential |
| Unauthorized access | Access to 7MinSec or client systems by an unauthorized party |
| Lost or stolen device | Loss of any endpoint with access to 7MinSec or client data |
| Social engineering | Successful phishing or impersonation attack against 7MinSec personnel |
| Scope creep during testing | Unintentional access beyond authorized scope during a client engagement |

## 4. Incident Severity Levels

Every incident involves four kinds of work, and they are deliberately separated because they have different urgencies and different constraints.

**Reporting** is telling the President that something has happened. It is a phone call, it requires no investigation, and it comes first in every case. Every incident is reported immediately on discovery, regardless of how severe it appears.

**Triage** is the first assessment: what appears to have happened, what may be affected, and how serious it may prove to be. It begins the moment an incident is reported and determines which containment actions are appropriate. Every incident is treated as P1 until triage establishes a lower severity. The containment and investigation timeframes below run from that determination.

**Containment** is the set of immediate actions that limit the damage: revoking or rotating a compromised credential, suspending a subcontractor's access, isolating a device, and notifying an affected client. These can be carried out from anywhere, including from a client site.

**Investigation** is establishing what happened, how, and what else is affected. It requires focused time and is the step that may have to wait for a working engagement to reach a safe pause.

| Severity | Examples | Contain | Investigate |
|---|---|---|---|
| P1: Critical | Active breach, ransomware, confirmed client data exposure, lost device with unencrypted data | Within 4 hours | Within 24 hours |
| P2: High | Suspected credential compromise, unauthorized access attempt, malware detected and contained | Within 1 business day | Within 3 business days |
| P3: Low | Policy violation, phishing email received but not clicked, suspicious but unconfirmed activity | As prioritized | Within 5 business days |

7MinSec is a small firm and the President may be engaged on client work when an incident is reported. The reporting and containment commitments are set so they can be met regardless, and containment always takes precedence over engagement work. Investigation timeframes are maximums, not targets; in practice investigation begins as soon as the President is free.

## 5. Incident Response Phases

### 5.1 Preparation

- All personnel understand their obligation to report potential incidents immediately
- Security telemetry from 7MinSec-managed systems is centrally collected and monitored, providing alert-based detection in addition to personnel reporting
- Contact lists for clients and subcontractors are maintained and accessible offline
- Password manager emergency access is configured for credential recovery scenarios
- Backups are maintained (cloud and local) and tested periodically

### 5.2 Identification

Any 7MinSec team member who observes or suspects a security incident must immediately notify Brian Johnson (President) by phone or email, and in all cases within one hour of discovery. Report first, investigate second. Reporting is never delayed in order to establish whether an incident is real: an unconfirmed report made in one hour is worth more than a confirmed one made in a day.

- Collect initial details: what was observed, when, on which system, by whom
- Preserve evidence and do not power off affected systems unless instructed
- Document the time of discovery and all actions taken from that point forward

### 5.3 Containment

- Isolate affected systems from the network immediately where possible
- Revoke or rotate compromised credentials without delay
- Suspend affected subcontractor access pending investigation
- If client systems are involved, notify the client immediately (see Section 6)

### 5.4 Eradication

- Identify and remove the root cause (malware, compromised account, misconfiguration, etc.)
- Reimage or restore affected systems from clean backups where warranted
- Confirm all indicators of compromise (IOCs) have been addressed before restoration

### 5.5 Recovery

- Restore affected systems and validate normal operation
- Re-enable access for legitimate users after credentials have been reset
- Monitor restored systems closely for 30 days post-incident for signs of re-compromise

### 5.6 Post-Incident Review

As soon as possible after incident resolution, and in no case more than 10 business days, 7MinSec conducts a post-incident review documenting root cause, timeline, the effectiveness of the response, and corrective actions. The review is held while details are still fresh. Findings are recorded in the incident log and used to improve security posture.

## 6. Client Notification

If a security incident involves confirmed or reasonably suspected exposure of client data, 7MinSec will:

- Notify the affected client(s) within 72 hours of confirming the incident
- Provide a clear description of what happened, what data was involved, and what actions 7MinSec has taken
- Maintain open communication with the client throughout the response and recovery process
- Cooperate fully with any client-initiated investigation or regulatory notification process

!!!danger To Report a Security Incident
Contact Brian Johnson immediately. This applies to 7MinSec personnel, subcontractors, and clients alike.
Phone: 952-232-6176
Email: [security@7minsec.com](mailto:security@7minsec.com)
!!!

## 7. Subcontractor Obligations

Subcontractors working on behalf of 7MinSec must report any suspected or confirmed incident to Brian Johnson immediately, not after investigation; cooperate fully with 7MinSec's incident response process; and not disclose incident details to any third party without explicit written approval from 7MinSec. These obligations are established and reaffirmed annually through the 7MinSec Subcontractor Security Acknowledgment form, on which every subcontractor attests to this policy and declares any security incident involving 7MinSec or client data since their last acknowledgment.

## 8. Incident Log

7MinSec maintains a confidential incident log that records all P1, P2, and P3 incidents including dates, descriptions, actions taken, and outcomes. This log is reviewed during annual policy review and used to identify recurring risks or control gaps.

## 9. Policy Review

This policy is reviewed annually or following any P1 or P2 incident. The current version is published in the [7MinSec Trust Center](https://kb.7minsec.com/trust).

!!!info Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
!!!

## Change Log

This log records all changes made to this policy over time.

| Version | Date | Author | Description of Change |
|---|---|---|---|
| 1.0 | September 1, 2026 | Brian Johnson | Initial release. |
| 1.1 | September 23, 2026 | Brian Johnson | Replaced the single response-time column in Section 4 with three separate commitments, for reporting, containment, and investigation, because they are different kinds of work with different achievable timeframes. Reporting to the President remains within one hour of discovery for P1 and P2 incidents. Added alert-based detection to Section 5.1: security telemetry from managed systems is now centrally monitored, so incidents can be detected as well as reported. Removed references to Signal as a reporting channel, which was not in use, and consolidated the incident reporting contact details. Corrected Section 7 to state where subcontractor incident reporting obligations are actually established. |
| 1.1.1 | September 24, 2026 | Brian Johnson | Editorial pass ahead of publication: em dashes removed throughout, including from the severity labels, which now read P1: Critical and so on. No requirement or timeframe changed. |
| 1.2 | September 28, 2026 | Brian Johnson | Incorporated recommendations from an independent policy review. Reporting is now immediate for every incident regardless of apparent severity, replacing the tiered reporting timeframes, and the Report column has been removed from the severity table accordingly. Section 4 adds triage as an explicit phase between reporting and containment, and establishes that every incident is treated as P1 until triage proves otherwise. Section 5.6 shortens the post-incident review commitment from two weeks to as soon as possible and in no case more than 10 business days. |
| 1.3 | October 2, 2026 | Brian Johnson | Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. No change to this policy. Version aligned with the rest of the suite. |
| 1.4 | October 2, 2026 | Brian Johnson | No change to this policy. Version aligned with the rest of the suite. |

!!!info Document Feedback
To suggest changes to this policy or report an issue, contact: [security@7minsec.com](mailto:security@7minsec.com)
!!!

*Last reviewed: October 2, 2026*
