Security Incident Response Plan
Last Updated: July 22, 2026
1. Purpose
This Security Incident Response Plan outlines Vendo's procedures for detecting, analyzing, containing, eradicating, and recovering from security incidents. It ensures a coordinated and effective response to minimize impact on our operations, customers, and data.
2. Scope
This plan covers all security incidents affecting Vendo's information systems, data, and infrastructure, including:
- Unauthorized access to systems or data
- Malware infections and ransomware attacks
- Denial of service (DoS/DDoS) attacks
- Insider threats
- Supply chain compromises
3. Incident Classification
Security incidents are classified by severity:
- Critical (P1): Active exploitation, data exfiltration, or a material service outage affecting customers. Highest-priority response.
- High (P2): Confirmed security compromise with potential for data loss or service impact. Prompt prioritized response.
- Medium (P3): Suspicious activity or vulnerability that could lead to a compromise. Response based on assessed risk and impact.
- Low (P4): Minor security events with limited impact. Managed through normal operational processes.
4. Incident Response Phases
4.1 Preparation
- Maintain and regularly update the incident response plan
- Ensure incident response tools and resources are available
- Maintain current contacts for people who may support a response
4.2 Detection and Analysis
- Review available service, application, authentication, and infrastructure signals for indicators of compromise
- Validate and classify the incident
- Document initial findings and timeline
4.3 Containment
- Implement short-term containment to stop immediate damage
- Isolate affected systems while preserving evidence
- Implement long-term containment to allow continued operations
- Coordinate with affected teams and stakeholders
4.4 Eradication
- Identify and eliminate the root cause of the incident
- Remove malware, unauthorized access, or compromised components
- Apply patches and security updates as needed
- Verify that affected systems are clean
4.5 Recovery
- Restore affected systems and services to normal operation
- Verify that systems are functioning correctly
- Monitor for signs of recurrence
- Communicate recovery status to stakeholders
4.6 Post-Incident Review
- Conduct a thorough post-incident analysis
- Document lessons learned and recommendations
- Update security controls, procedures, and training as needed
- Share findings with relevant teams to prevent recurrence
5. Communication
During a security incident, Vendo will communicate with:
- Internal teams: Via secure communication channels as defined in the response plan
- Affected customers: In accordance with contractual obligations and applicable law
- Regulatory authorities: As required by applicable data protection laws
- Law enforcement: When criminal activity is suspected
6. Roles and Responsibilities
Vendo assigns response responsibilities according to the nature and severity of each incident. Assigned responsibilities may include:
- Incident lead: Coordinates the response and key decisions
- Technical lead: Performs or coordinates technical analysis, containment, remediation, and recovery
- Communications and legal coordination: Manages appropriate internal, customer, legal, and regulatory communication with specialist support where needed
7. Contact
To report a security incident, please contact us immediately at support@vendodata.com