Incident Response Policy

How 7 Minute Security prepares for, detects, responds to, and recovers from security incidents.
Version Effective Approved Last reviewed Owner
1.4 October 2, 2026 October 2, 2026 October 2, 2026 Brian Johnson, President

1. Purpose

Security incidents are not a matter of if, but when, even for a cybersecurity firm. This policy defines how 7MinSec prepares for, identifies, contains, eradicates, recovers from, and learns from security incidents. It also defines our obligations to clients when their data or systems may be affected.

2. Scope

This policy applies to all security incidents affecting 7MinSec internal systems (productivity suite, file storage, report authoring platform, and endpoints), client data held by 7MinSec at any stage of the retention lifecycle defined in our Data Inventory & Classification Policy, client environments that 7MinSec personnel are actively working in, and subcontractors acting on behalf of 7MinSec.

3. What Constitutes an Incident

Incident Type Description
Data breach Unauthorized access to or disclosure of client data or 7MinSec credentials
Malware infection Ransomware, spyware, or other malicious code on any 7MinSec or subcontractor endpoint
Credential compromise Confirmed or suspected theft of a 7MinSec or client credential
Unauthorized access Access to 7MinSec or client systems by an unauthorized party
Lost or stolen device Loss of any endpoint with access to 7MinSec or client data
Social engineering Successful phishing or impersonation attack against 7MinSec personnel
Scope creep during testing Unintentional access beyond authorized scope during a client engagement

4. Incident Severity Levels

Every incident involves four kinds of work, and they are deliberately separated because they have different urgencies and different constraints.

Reporting is telling the President that something has happened. It is a phone call, it requires no investigation, and it comes first in every case. Every incident is reported immediately on discovery, regardless of how severe it appears.

Triage is the first assessment: what appears to have happened, what may be affected, and how serious it may prove to be. It begins the moment an incident is reported and determines which containment actions are appropriate. Every incident is treated as P1 until triage establishes a lower severity. The containment and investigation timeframes below run from that determination.

Containment is the set of immediate actions that limit the damage: revoking or rotating a compromised credential, suspending a subcontractor's access, isolating a device, and notifying an affected client. These can be carried out from anywhere, including from a client site.

Investigation is establishing what happened, how, and what else is affected. It requires focused time and is the step that may have to wait for a working engagement to reach a safe pause.

Severity Examples Contain Investigate
P1: Critical Active breach, ransomware, confirmed client data exposure, lost device with unencrypted data Within 4 hours Within 24 hours
P2: High Suspected credential compromise, unauthorized access attempt, malware detected and contained Within 1 business day Within 3 business days
P3: Low Policy violation, phishing email received but not clicked, suspicious but unconfirmed activity As prioritized Within 5 business days

7MinSec is a small firm and the President may be engaged on client work when an incident is reported. The reporting and containment commitments are set so they can be met regardless, and containment always takes precedence over engagement work. Investigation timeframes are maximums, not targets; in practice investigation begins as soon as the President is free.

5. Incident Response Phases

5.1 Preparation

  • All personnel understand their obligation to report potential incidents immediately
  • Security telemetry from 7MinSec-managed systems is centrally collected and monitored, providing alert-based detection in addition to personnel reporting
  • Contact lists for clients and subcontractors are maintained and accessible offline
  • Password manager emergency access is configured for credential recovery scenarios
  • Backups are maintained (cloud and local) and tested periodically

5.2 Identification

Any 7MinSec team member who observes or suspects a security incident must immediately notify Brian Johnson (President) by phone or email, and in all cases within one hour of discovery. Report first, investigate second. Reporting is never delayed in order to establish whether an incident is real: an unconfirmed report made in one hour is worth more than a confirmed one made in a day.

  • Collect initial details: what was observed, when, on which system, by whom
  • Preserve evidence and do not power off affected systems unless instructed
  • Document the time of discovery and all actions taken from that point forward

5.3 Containment

  • Isolate affected systems from the network immediately where possible
  • Revoke or rotate compromised credentials without delay
  • Suspend affected subcontractor access pending investigation
  • If client systems are involved, notify the client immediately (see Section 6)

5.4 Eradication

  • Identify and remove the root cause (malware, compromised account, misconfiguration, etc.)
  • Reimage or restore affected systems from clean backups where warranted
  • Confirm all indicators of compromise (IOCs) have been addressed before restoration

5.5 Recovery

  • Restore affected systems and validate normal operation
  • Re-enable access for legitimate users after credentials have been reset
  • Monitor restored systems closely for 30 days post-incident for signs of re-compromise

5.6 Post-Incident Review

As soon as possible after incident resolution, and in no case more than 10 business days, 7MinSec conducts a post-incident review documenting root cause, timeline, the effectiveness of the response, and corrective actions. The review is held while details are still fresh. Findings are recorded in the incident log and used to improve security posture.

6. Client Notification

If a security incident involves confirmed or reasonably suspected exposure of client data, 7MinSec will:

  • Notify the affected client(s) within 72 hours of confirming the incident
  • Provide a clear description of what happened, what data was involved, and what actions 7MinSec has taken
  • Maintain open communication with the client throughout the response and recovery process
  • Cooperate fully with any client-initiated investigation or regulatory notification process

7. Subcontractor Obligations

Subcontractors working on behalf of 7MinSec must report any suspected or confirmed incident to Brian Johnson immediately, not after investigation; cooperate fully with 7MinSec's incident response process; and not disclose incident details to any third party without explicit written approval from 7MinSec. These obligations are established and reaffirmed annually through the 7MinSec Subcontractor Security Acknowledgment form, on which every subcontractor attests to this policy and declares any security incident involving 7MinSec or client data since their last acknowledgment.

8. Incident Log

7MinSec maintains a confidential incident log that records all P1, P2, and P3 incidents including dates, descriptions, actions taken, and outcomes. This log is reviewed during annual policy review and used to identify recurring risks or control gaps.

9. Policy Review

This policy is reviewed annually or following any P1 or P2 incident. The current version is published in the 7MinSec Trust Center.

Change Log

This log records all changes made to this policy over time.

Version Date Author Description of Change
1.0 September 1, 2026 Brian Johnson Initial release.
1.1 September 23, 2026 Brian Johnson Replaced the single response-time column in Section 4 with three separate commitments, for reporting, containment, and investigation, because they are different kinds of work with different achievable timeframes. Reporting to the President remains within one hour of discovery for P1 and P2 incidents. Added alert-based detection to Section 5.1: security telemetry from managed systems is now centrally monitored, so incidents can be detected as well as reported. Removed references to Signal as a reporting channel, which was not in use, and consolidated the incident reporting contact details. Corrected Section 7 to state where subcontractor incident reporting obligations are actually established.
1.1.1 September 24, 2026 Brian Johnson Editorial pass ahead of publication: em dashes removed throughout, including from the severity labels, which now read P1: Critical and so on. No requirement or timeframe changed.
1.2 September 28, 2026 Brian Johnson Incorporated recommendations from an independent policy review. Reporting is now immediate for every incident regardless of apparent severity, replacing the tiered reporting timeframes, and the Report column has been removed from the severity table accordingly. Section 4 adds triage as an explicit phase between reporting and containment, and establishes that every incident is treated as P1 until triage proves otherwise. Section 5.6 shortens the post-incident review commitment from two weeks to as soon as possible and in no case more than 10 business days.
1.3 October 2, 2026 Brian Johnson Independent review of v1.2 completed with no further changes requested, and 7MinSec's own accuracy review completed with no findings. No change to this policy. Version aligned with the rest of the suite.
1.4 October 2, 2026 Brian Johnson No change to this policy. Version aligned with the rest of the suite.

Last reviewed: October 2, 2026