Skip to main content
Vendo

Security Incident Response Plan

Last Updated: July 22, 2026

1. Purpose

This Security Incident Response Plan outlines Vendo's procedures for detecting, analyzing, containing, eradicating, and recovering from security incidents. It ensures a coordinated and effective response to minimize impact on our operations, customers, and data.

2. Scope

This plan covers all security incidents affecting Vendo's information systems, data, and infrastructure, including:

  • Unauthorized access to systems or data
  • Malware infections and ransomware attacks
  • Denial of service (DoS/DDoS) attacks
  • Insider threats
  • Supply chain compromises

3. Incident Classification

Security incidents are classified by severity:

  • Critical (P1): Active exploitation, data exfiltration, or a material service outage affecting customers. Highest-priority response.
  • High (P2): Confirmed security compromise with potential for data loss or service impact. Prompt prioritized response.
  • Medium (P3): Suspicious activity or vulnerability that could lead to a compromise. Response based on assessed risk and impact.
  • Low (P4): Minor security events with limited impact. Managed through normal operational processes.

4. Incident Response Phases

4.1 Preparation

  • Maintain and regularly update the incident response plan
  • Ensure incident response tools and resources are available
  • Maintain current contacts for people who may support a response

4.2 Detection and Analysis

  • Review available service, application, authentication, and infrastructure signals for indicators of compromise
  • Validate and classify the incident
  • Document initial findings and timeline

4.3 Containment

  • Implement short-term containment to stop immediate damage
  • Isolate affected systems while preserving evidence
  • Implement long-term containment to allow continued operations
  • Coordinate with affected teams and stakeholders

4.4 Eradication

  • Identify and eliminate the root cause of the incident
  • Remove malware, unauthorized access, or compromised components
  • Apply patches and security updates as needed
  • Verify that affected systems are clean

4.5 Recovery

  • Restore affected systems and services to normal operation
  • Verify that systems are functioning correctly
  • Monitor for signs of recurrence
  • Communicate recovery status to stakeholders

4.6 Post-Incident Review

  • Conduct a thorough post-incident analysis
  • Document lessons learned and recommendations
  • Update security controls, procedures, and training as needed
  • Share findings with relevant teams to prevent recurrence

5. Communication

During a security incident, Vendo will communicate with:

  • Internal teams: Via secure communication channels as defined in the response plan
  • Affected customers: In accordance with contractual obligations and applicable law
  • Regulatory authorities: As required by applicable data protection laws
  • Law enforcement: When criminal activity is suspected

6. Roles and Responsibilities

Vendo assigns response responsibilities according to the nature and severity of each incident. Assigned responsibilities may include:

  • Incident lead: Coordinates the response and key decisions
  • Technical lead: Performs or coordinates technical analysis, containment, remediation, and recovery
  • Communications and legal coordination: Manages appropriate internal, customer, legal, and regulatory communication with specialist support where needed

7. Contact

To report a security incident, please contact us immediately at support@vendodata.com