Skip to content

Resilience & Incident Response

Incident Management

How we detect, report, assess, respond to, and learn from information security incidents.

Last reviewed: July 2026

Security incidents can degrade service, expose sensitive data, or cause outages, and they require quick human intervention to prevent disruption or restore normal operations. This page explains how we handle and manage information security incidents.

Our approach

Security incidents are irregular and anomalous conditions that cause, or may lead to, service degradation, loss of sensitive data, outages, or any other form of reduced operational status. We maintain an incident management procedure that defines the responsibilities and steps needed to ensure quick, effective, consistent, and orderly responses. We appoint responsible personnel to:

  • Investigate and coordinate reported security incidents and security weaknesses.
  • Track the closure of incidents along with corrective and preventive actions.

Reporting incidents

We establish appropriate channels so that information security incidents can be reported as quickly as possible.

  • All security incidents are recorded in an information security incident database.
  • The steps for reporting an incident are communicated to all employees and contractors, and reporting procedures are kept easily accessible for reference.
  • We operate a monitoring mechanism for proactive detection of intrusions, attacks, and fraud.

Assessment and response

Every reported incident is assessed and classified according to defined classification criteria.

  • Assessments and classifications are retained for future reference, which helps us identify recurring issues and avoid false positives.
  • We follow a response plan and strategy that covers the full incident cycle, from identification through root cause analysis to resolution, and includes identifying corrective action where appropriate.
  • Where follow-up action after an incident involves legal proceedings (civil or criminal), we collect, retain, and present evidence in line with the rules of evidence in the relevant jurisdiction.

Learning from incidents

We analyze information security incidents and share findings with the appropriate parties periodically. Knowledge gained from resolving incidents is used to reduce the likelihood of similar incidents in the future and to help limit their impact.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]