> For the complete documentation index, see [llms.txt](https://incident-tracker.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://incident-tracker.gitbook.io/docs/support/security/incident-response.md).

# Incident Response

## Incident Response

This page outlines how Incident Tracker detects, responds to, and communicates security incidents, including potential data breaches.

Our incident response process is designed to ensure rapid containment, investigation, and communication—while minimizing risk to our customers and their data.

***

### Detection

We use a combination of tools and services to proactively monitor our systems:

* **Microsoft Defender for Cloud**: Monitors cloud workloads and alerts on suspicious activity.
* **UpGuard**: Continuously scans our external footprint for vulnerabilities and changes.
* **Internal logging & monitoring**: All user and system actions are logged, timestamped, and reviewed by our internal operations team.
* **Uptime Monitoring**: External availability and performance are tracked in real time.

All unusual activity is escalated to our internal Security Response Team.

***

### Response Process

If a potential breach or security incident is detected, our response follows a structured process:

1. **Initial Alert**\
   Anomalies or alerts are reviewed by our operations or support teams and escalated to the Security Response Team.
2. **Triage & Verification**\
   Our internal team, alongside external forensic experts (if needed), verifies whether a breach has occurred.
3. **Containment & Mitigation**\
   If a breach is confirmed, access to affected systems is immediately restricted, and data movement is halted.
4. **Root Cause Analysis**\
   A full investigation is conducted to determine how the event occurred and what systems or data were affected.
5. **Communication & Notification**
   * Customers affected by a confirmed breach will be notified within 72 hours or sooner, as required by law or contract.
   * Notifications will include what happened, what data was impacted, and steps taken.
6. **Remediation**\
   Permanent fixes are implemented, and systems are monitored for any reoccurrence.
7. **Postmortem**\
   A formal post-incident review is conducted and documented internally. Learnings are used to update policies, tools, and training.

***

### Who Manages Incidents?

Incident response is coordinated by McKula Inc.’s executive leadership, including:

* Director of Information Security (or delegate)
* Engineering and Infrastructure leads
* Legal and Communications team (for notifications)
* Customer Support (for direct assistance)

All staff are trained annually on incident identification, escalation, and customer communication protocols.

***

### Reporting a Security Issue

If you believe a security issue or data breach has occurred involving your Incident Tracker site:

* Email: <support@incident-tracker.com>
* Phone: 1-724-423-9290
* Website: [www.incident-tracker.com](https://www.incident-tracker.com)

Please include as much detail as possible (timestamps, affected user, nature of the issue).
