Incident Response Policy
About This Document
This policy defines how 7 Minute Security LLC prepares for, detects, responds to, and recovers from security incidents, including incidents affecting our own systems and those involving client data.
1. Purpose
Security incidents are not a matter of if, but when, even for a cybersecurity firm. This policy defines how 7MinSec prepares for, identifies, contains, eradicates, recovers from, and learns from security incidents. It also defines our obligations to clients when their data or systems may be affected.
2. Scope
This policy applies to all security incidents affecting 7MinSec internal systems (productivity suite, file storage, report authoring platform, and endpoints), client data held by 7MinSec at any stage of the retention lifecycle defined in our Data Inventory & Classification Policy, client environments that 7MinSec personnel are actively working in, and subcontractors acting on behalf of 7MinSec.
3. What Constitutes an Incident
4. Incident Severity Levels
Every incident involves four kinds of work, and they are deliberately separated because they have different urgencies and different constraints.
Reporting is telling the President that something has happened. It is a phone call, it requires no investigation, and it comes first in every case. Every incident is reported immediately on discovery, regardless of how severe it appears.
Triage is the first assessment: what appears to have happened, what may be affected, and how serious it may prove to be. It begins the moment an incident is reported and determines which containment actions are appropriate. Every incident is treated as P1 until triage establishes a lower severity. The containment and investigation timeframes below run from that determination.
Containment is the set of immediate actions that limit the damage: revoking or rotating a compromised credential, suspending a subcontractor's access, isolating a device, and notifying an affected client. These can be carried out from anywhere, including from a client site.
Investigation is establishing what happened, how, and what else is affected. It requires focused time and is the step that may have to wait for a working engagement to reach a safe pause.
7MinSec is a small firm and the President may be engaged on client work when an incident is reported. The reporting and containment commitments are set so they can be met regardless, and containment always takes precedence over engagement work. Investigation timeframes are maximums, not targets; in practice investigation begins as soon as the President is free.
5. Incident Response Phases
5.1 Preparation
- All personnel understand their obligation to report potential incidents immediately
- Security telemetry from 7MinSec-managed systems is centrally collected and monitored, providing alert-based detection in addition to personnel reporting
- Contact lists for clients and subcontractors are maintained and accessible offline
- Password manager emergency access is configured for credential recovery scenarios
- Backups are maintained (cloud and local) and tested periodically
5.2 Identification
Any 7MinSec team member who observes or suspects a security incident must immediately notify Brian Johnson (President) by phone or email, and in all cases within one hour of discovery. Report first, investigate second. Reporting is never delayed in order to establish whether an incident is real: an unconfirmed report made in one hour is worth more than a confirmed one made in a day.
- Collect initial details: what was observed, when, on which system, by whom
- Preserve evidence and do not power off affected systems unless instructed
- Document the time of discovery and all actions taken from that point forward
5.3 Containment
- Isolate affected systems from the network immediately where possible
- Revoke or rotate compromised credentials without delay
- Suspend affected subcontractor access pending investigation
- If client systems are involved, notify the client immediately (see Section 6)
5.4 Eradication
- Identify and remove the root cause (malware, compromised account, misconfiguration, etc.)
- Reimage or restore affected systems from clean backups where warranted
- Confirm all indicators of compromise (IOCs) have been addressed before restoration
5.5 Recovery
- Restore affected systems and validate normal operation
- Re-enable access for legitimate users after credentials have been reset
- Monitor restored systems closely for 30 days post-incident for signs of re-compromise
5.6 Post-Incident Review
As soon as possible after incident resolution, and in no case more than 10 business days, 7MinSec conducts a post-incident review documenting root cause, timeline, the effectiveness of the response, and corrective actions. The review is held while details are still fresh. Findings are recorded in the incident log and used to improve security posture.
6. Client Notification
If a security incident involves confirmed or reasonably suspected exposure of client data, 7MinSec will:
- Notify the affected client(s) within 72 hours of confirming the incident
- Provide a clear description of what happened, what data was involved, and what actions 7MinSec has taken
- Maintain open communication with the client throughout the response and recovery process
- Cooperate fully with any client-initiated investigation or regulatory notification process
To Report a Security Incident
Contact Brian Johnson immediately. This applies to 7MinSec personnel, subcontractors, and clients alike. Phone: 952-232-6176 Email: security@7minsec.com
7. Subcontractor Obligations
Subcontractors working on behalf of 7MinSec must report any suspected or confirmed incident to Brian Johnson immediately, not after investigation; cooperate fully with 7MinSec's incident response process; and not disclose incident details to any third party without explicit written approval from 7MinSec. These obligations are established and reaffirmed annually through the 7MinSec Subcontractor Security Acknowledgment form, on which every subcontractor attests to this policy and declares any security incident involving 7MinSec or client data since their last acknowledgment.
8. Incident Log
7MinSec maintains a confidential incident log that records all P1, P2, and P3 incidents including dates, descriptions, actions taken, and outcomes. This log is reviewed during annual policy review and used to identify recurring risks or control gaps.
9. Policy Review
This policy is reviewed annually or following any P1 or P2 incident. The current version is published in the 7MinSec Trust Center.
Policy Approval
The signed master copy of this policy is maintained in Word format and is available to customers and partners on request.
Change Log
This log records all changes made to this policy over time.
Document Feedback
To suggest changes to this policy or report an issue, contact: security@7minsec.com
Last reviewed: October 2, 2026