Information security

Security Incident Response Policy

v1.0
Reviewed Jun 2026 · next review Jun 2027

HALVED LIMITED

SECURITY INCIDENT RESPONSE POLICY

Version: 1.0 Effective Date: 4th June 2026 Last Review: 4th June 2026 Next Review: 4th June 2027

Owner: Andrew James, CEO

1. PURPOSE

This policy defines how Halved Limited responds to security incidents to minimise impact, recover quickly, and prevent future incidents.

2. SCOPE

This policy applies to all security incidents affecting:

3. WHAT IS A SECURITY INCIDENT?

A security incident includes:

4. INCIDENT RESPONSE PROCEDURE

Phase 1: IMMEDIATE ACTIONS (Within 15 Minutes)

Step 1: Report the Incident

Who to contact: Andrew James, CEO

How to report:

What to report:

Step 2: Initial Containment

CEO takes immediate action:

If account compromised:

If device lost/stolen:

If malware suspected:

Phase 2: INVESTIGATION (Within 1 Hour)

Step 3: Assess the Scope

CEO investigates:

Step 4: Document the Incident

Create incident record documenting:

Phase 3: REMEDIATION (Within 4 Hours)

Step 5: Remove Threat and Restore Access

For compromised accounts:

For lost/stolen devices:

For malware:

Step 6: Verify System Integrity

Phase 4: NOTIFICATION (Within 72 Hours if Required)

Step 7: Determine Notification Requirements

Internal notification:

External notification (if required by law):

When to notify authorities:

Phase 5: POST-INCIDENT REVIEW (Within 1 Week)

Step 8: Lessons Learned

CEO conducts review:

Step 9: Update Policies and Procedures

Based on lessons learned:

Step 10: Close Incident

Mark incident as resolved in incident log when:

5. INCIDENT SEVERITY LEVELS

Level 1: CRITICAL

Response time: Immediate (drop everything)

Level 2: HIGH

Response time: Within 1 hour

Level 3: MEDIUM

Response time: Within 4 hours

Level 4: LOW

Response time: Next business day

6. ESCALATION CONTACTS

Primary Contact:

Andrew James, CEO

Email: aj@halved.io

Phone: +971 585616250

Regulatory Reporting:

ICO (Data Protection): https://ico.org.uk/make-a-complaint/data-protection-complaints/

NCSC (Cyber Security): https://www.ncsc.gov.uk/section/about-ncsc/report-an-incident

7. INCIDENT LOG

All security incidents are logged in: Halved_Security_Incident_Log.xlsx

Minimum information recorded:

Retention: Incident logs retained for 7 years (GDPR compliance)

8. TRAINING AND AWARENESS

All team members receive security awareness training:

9. POLICY REVIEW

This policy is reviewed:

APPROVED BY:

Andrew James, CEO Halved Limited Date: 4th June 2026