Security Incident and Breach Response
What happens when something goes wrong, on what timescale, and who decides what.
Version 1.0 · Effective 6 August 2026 · Last updated 6 August 2026
Published rather than kept internal, because a customer assessing us as a supplier is entitled to know what we would do, and because publishing it makes it harder for us to quietly not follow it.
1. Severity
| Level | Example | Response begins |
|---|---|---|
| P1 — Critical | Confirmed unauthorised access to customer data; ransomware; credential compromise | Immediately, any hour |
| P2 — High | Vulnerability allowing cross-organisation access; suspected compromise | Within 4 hours |
| P3 — Moderate | Vulnerability with no evidence of exploitation; loss of a non-critical control | Within 1 working day |
| P4 — Low | Hardening opportunity; single-user issue with no data exposure | Within 5 working days |
2. The sequence
- 1.Detect — from monitoring, an alert, a customer, or a researcher.
- 2.Contain — revoke the credential, disable the route, suspend the account, isolate the component. Containment comes before diagnosis; a system still being exploited is not a puzzle to solve first.
- 3.Assess — what data, whose, how much, over what window. Preserve logs before anything is rebuilt.
- 4.Notify — affected customers within 24 hours of becoming aware, in writing, with what we know and what we do not yet know.
- 5.Eradicate and recover — remove the cause, rotate every credential that could have been exposed, restore from a clean backup where needed, verify before restoring service.
- 6.Review — a written account within 10 working days: what happened, why, what changed. Shared with affected customers.
3. Who notifies the regulator
For data we process on a customer's behalf, the customer is the controller. They decide whether to notify the ICO within 72 hours and whether to tell the individuals concerned. We notify them within 24 hours and give them what they need to decide. We do not make that decision for them and we do not delay telling them while we work out whether it is serious — they are entitled to form their own view.
For data we control — account, billing, marketing — we assess and notify the ICO ourselves within 72 hours where the threshold is met, and tell affected individuals where there is a high risk to them.
4. Ransomware and destructive attack
- Backups are held outside the primary platform account precisely so that an attacker who compromises that account cannot destroy the means of recovery.
- We do not pay ransoms.
- Recovery is from the last verified clean backup, with credentials rotated before the service returns.
- Customers are told the restore point, so they know what they may need to re-enter. A recovery that hides how much was lost is not a recovery.
5. Contact
hello@careshieldcompliance.co.uk, monitored on working days and escalated to the director for anything credible. Responsible disclosure is welcomed and we will not pursue a researcher who acts in good faith, avoids other customers' data, and gives us reasonable time to fix what they find.
Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.