Service-Disabled Veteran-Owned Small Business UEI NQ7DY8MADL23 CAGE 5AAG0 Registered in SAM.gov
New Vision Security Secure by design. Transparent by choice.
Security

Incident Response

What happens when something goes wrong, and when you hear from us.

Draft for review. This page was prepared from company records and published practice. It has not been reviewed by counsel. Review and approve the wording before relying on it in a contract or a procurement response.

Approach

Our incident handling follows the phases set out in NIST guidance on computer security incident handling: preparation, detection and analysis, containment, eradication and recovery, and post-incident review.

Severity

LevelMeaningResponse begins
CriticalConfirmed unauthorised access to customer data, or platform-wide outageImmediately, around the clock
HighExploitable vulnerability in production, or partial loss of serviceSame business day
MediumContained issue with no evidence of data exposureWithin 2 business days
LowMinor defect with security relevanceNext planned release

Notification

If an incident affects customer data, we will notify affected customers directly. Notification will describe what happened, what data was involved, what we have done, and what if anything the customer should do.

Set a committed notification window. Contracts and several regulatory regimes expect a stated maximum, commonly 72 hours from confirmation. Choose the window you can actually meet and state it here, because a missed commitment is worse than a conservative one.

After the fact

Every incident at high severity or above gets a written review covering timeline, root cause, and the specific changes made so it does not recur. Customers materially affected may request it.

Reaching us urgently

Email info@newvisionsecurity.com with URGENT SECURITY in the subject line, or telephone (404) 999-7687.