Cyber Security Incident Response Procedure

Introduction
This Incident Response Procedure defines the steps HubBroker follows to detect, report, assess, contain, investigate, recover from and learn from actual or suspected information security incidents affecting HubBroker systems, services or customer data.
STEP 1: DETECT, REPORT AND ASSESS THE INCIDENT
Any actual or suspected security incident must be reported immediately through the designated incident-reporting channels. The incident will be assessed, classified by severity and escalated according to its potential impact on systems, services, personal data and customers.
STEP 2: NOTIFICATION AND ESCALATION
Where an incident affects customer data, affected customers will be notified without undue delay and in accordance with applicable contractual, DPA and SLA requirements.
Where HubBroker acts as a Data Processor, HubBroker will notify the relevant Data Controller without undue delay after becoming aware of a personal-data breach.
Where HubBroker acts as a Data Controller and the breach is reportable under GDPR Article 33, HubBroker will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
STEP 3: CONTAINMENT AND EVIDENCE PRESERVATION
HubBroker will take proportionate measures to contain the incident and prevent further unauthorised access or damage.
Where practical, relevant evidence will be preserved before destructive remediation actions are taken. This may include system logs, access logs, memory information, network activity, affected files and relevant system-state information.
Containment actions may include:
- isolating affected systems;
- blocking malicious network traffic;
- disabling or restricting compromised accounts;
- revoking sessions, tokens or API credentials;
- rotating affected credentials and keys;
- restricting affected integrations;
- applying temporary firewall or access-control rules; and
- switching to recovery infrastructure where required.
Where restoration is required, HubBroker will use approved backup and disaster-recovery procedures and validated recovery points appropriate to the affected system.
Compromised or potentially compromised credentials, authentication tokens, API keys, certificates and sessions will be revoked, reset or rotated according to the scope of the incident.
Containment and response timelines are determined according to incident severity, business impact, data sensitivity and ongoing threat activity. Critical incidents require immediate escalation and response.
STEP 4: INVESTIGATION AND IMPACT ASSESSMENT
HubBroker will investigate the incident to determine its root cause, attack vector, affected systems and accounts, duration, extent of unauthorised access, potential persistence, and any data that may have been accessed, altered, disclosed, destroyed or exfiltrated.
Where personal data is involved, an assessment will be made of the potential risk to the rights and freedoms of affected individuals and whether regulatory or data-subject notification obligations apply.
STEP 5: COMMUNICATION
HubBroker will provide affected customers and other relevant stakeholders with timely, accurate and appropriate information about confirmed incidents. Communications will be coordinated through designated responsible persons and will include information necessary to understand the impact, containment actions and any actions required from affected parties.
Additional updates will be provided as material facts become available.
STEP 6: ERADICATION, RECOVERY AND REMEDIATION
HubBroker will remove or mitigate the root cause of the incident and restore affected systems to a known secure state.
Remediation may include:
- removing malicious software or unauthorised components;
- patching identified vulnerabilities;
- changing firewall and access-control rules;
- rebuilding or restoring affected systems from validated backups;
- rotating compromised credentials or cryptographic material;
- disabling insecure or compromised integrations;
- strengthening monitoring and detection controls; and
- validating system security before returning systems to normal operation.
STEP 7: POST-INCIDENT REVIEW AND CONTINUAL IMPROVEMENT
Following significant incidents, HubBroker will conduct a documented post-incident review to identify the root cause, response effectiveness, lessons learned and corrective actions.
Corrective actions will be assigned to responsible owners, tracked through completion and used to improve relevant security controls, procedures, training and monitoring.
Category: Security Policy
Last date of update: 25.08.2026