Legal & compliance centre

HLD Group

Incident response plan

Detecting, responding to, and recovering from security incidents.

Last updated: 24 July 2026

Version 3.0 · Review cycle: 180 days · View all frameworks

1. Purpose

This policy defines how HLD Group prepares for, detects, responds to, and recovers from information security incidents. A structured, practised incident response capability limits the damage of an incident, reduces recovery time and cost, and ensures legal and contractual obligations — including breach notification — are met.

2. Scope

This policy applies to all security incidents affecting HLD Group systems, data, personnel, or customers, and to all personnel and third parties who detect, report, or respond to them.

3. Definitions

  • Event — an observable occurrence in a system or network
  • Incident — an event that compromises, or threatens to compromise, the confidentiality, integrity, or availability of information
  • Severity — a rating of an incident’s impact and urgency that drives the response
  • Containment — actions to limit the spread and impact of an incident
  • Eradication and recovery — removing the cause and restoring affected systems to normal, trusted operation

4. Incident response lifecycle

Preparation

Maintain the response plan, tooling, contacts, and training, and conduct exercises so the team can respond effectively.

Detection and analysis

Identify and validate incidents through monitoring, alerts, and reports, and determine scope, severity, and impact.

Containment

Take short-term and long-term actions to limit damage while preserving evidence for investigation.

Eradication and recovery

Remove the cause, remediate affected systems, restore from clean sources, and validate before returning to service.

Post-incident activity

Conduct a root cause analysis and lessons-learned review, and drive improvements to controls and detection.

5. Reporting and escalation

  • All personnel must report suspected incidents immediately, and within one hour for anything material, through the designated channel
  • Incidents are triaged and assigned a severity that determines the response and escalation path
  • High-severity incidents are escalated to the CISO and leadership without delay
  • The crisis management structure in the Business Continuity Policy is activated for major incidents

6. Severity classification

  • Critical — severe impact on customers, data, or operations; immediate, all-hands response
  • High — significant impact or a confirmed breach; urgent response and leadership notification
  • Medium — limited impact, contained; prompt response within business processes
  • Low — minor or potential issue; handled through routine processes

7. Evidence handling and forensics

Evidence is preserved to support investigation, legal action, and regulatory reporting. Chain of custody is maintained for evidence that may be used in legal proceedings, and forensic analysis is performed by qualified personnel or engaged specialists using sound methods.

8. Breach notification interface

Where an incident involves personal or regulated data, the Breach Notification Policy is invoked in parallel to assess and meet notification obligations within statutory timeframes, including the GDPR 72-hour authority notification and the Australian Notifiable Data Breaches scheme.

9. Communication

  • Internal communications follow the incident and crisis playbooks
  • Customer notifications are made within contractual timeframes through agreed channels
  • External communications, including to regulators, media, and law enforcement, are coordinated and approved by leadership and legal counsel

10. Post-incident review and improvement

A post-incident review is completed for significant incidents, generally within 10 business days, to establish root cause and drive corrective and preventive action. Findings are tracked to closure and inform improvements to controls, detection, and this policy.

11. Testing and exercising

The incident response capability is exercised regularly, including tabletop simulations of realistic scenarios, so that the plan is proven rather than assumed. Exercise findings feed the improvement cycle.

12. Framework alignment

  • NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide)
  • ISO/IEC 27001:2022 Annex A controls 5.24 to 5.28 (information security incident management)
  • NIST SP 800-53 Rev. 5 control family IR (Incident Response)
  • SOC 2 Trust Services Criteria CC7.3, CC7.4, and CC7.5

13. Roles, exceptions, and review

The CISO owns the incident response capability; an incident commander leads each response; all personnel are responsible for reporting. Exceptions require documented CISO approval. This policy is reviewed at least annually and after every significant incident and exercise.

Related frameworks

For contractual attestations or audit packs, contact [email protected].