Incident Response
What happens when something goes wrong, and when you hear from us.
Approach
Our incident handling follows the phases set out in NIST guidance on computer security incident handling: preparation, detection and analysis, containment, eradication and recovery, and post-incident review.
Severity
| Level | Meaning | Response begins |
|---|---|---|
| Critical | Confirmed unauthorised access to customer data, or platform-wide outage | Immediately, around the clock |
| High | Exploitable vulnerability in production, or partial loss of service | Same business day |
| Medium | Contained issue with no evidence of data exposure | Within 2 business days |
| Low | Minor defect with security relevance | Next planned release |
Notification
If an incident affects customer data, we will notify affected customers directly. Notification will describe what happened, what data was involved, what we have done, and what if anything the customer should do.
After the fact
Every incident at high severity or above gets a written review covering timeline, root cause, and the specific changes made so it does not recur. Customers materially affected may request it.
Reaching us urgently
Email info@newvisionsecurity.com with URGENT SECURITY in the subject line, or telephone (404) 999-7687.