Security Incident & Breach Notification Standard
Confirmed breach affecting customer data: initial customer notification within 12 hours of confirmation. Material customer-impacting incidents are notified without undue delay; initial notice is not held back while every fact is investigated.
Purpose
This standard defines how PCL One escalates, communicates and follows through on security incidents that materially affect a customer’s data or contracted service. It separates the operational incident process from any statutory notification duty the customer may have as controller or public body.
Notification commitment
| Event | Baseline initial notice | How it is applied |
|---|---|---|
| Confirmed security breach affecting customer data | Within 12 hours of confirmation | Preliminary notice may be issued before the full forensic picture is known. |
| Material incident affecting customer data or service | Without undue delay; target within 24 hours of confirmation of material customer impact | Used where impact is confirmed but breach classification or full scope is still being established. |
| Personal-data breach subject to a contractual/statutory maximum | The shorter of the applicable legal/contractual timeline or the timeline above | Any stricter customer or regulator requirement prevails. |
What the initial notice contains
- Known nature of the incident and when it was detected or confirmed.
- Affected service, environment and categories of customer data known at the time.
- Known or reasonably suspected scope and customer impact.
- Containment and recovery actions already taken or underway.
- Any immediate action requested from the customer.
- The next planned update point and the agreed customer contact channel.
Incident lifecycle
| Stage | Control |
|---|---|
| Detect & triage | Validate the alert, classify severity, preserve evidence and assign accountable incident ownership. |
| Contain | Limit further exposure or service impact using proportionate technical and access controls. |
| Investigate | Determine affected systems, data categories, timeline, root cause indicators and whether the event is reportable. |
| Notify | Contact designated customer contacts using the baseline above. Do not wait for perfect information. |
| Recover | Restore safe service, validate integrity and monitor for recurrence. |
| Close & improve | Provide post-incident findings when available, including corrective and preventive actions and tracked remediation. |
Customer coordination
- Customer notification is sent to the designated security, privacy and service contacts recorded for the engagement.
- PCL One provides information reasonably available to support the customer’s own regulator, data-subject, insurance or executive reporting obligations.
- Where an underlying hosting or subprocessor incident is involved, PCL One coordinates the provider response and remains the customer-facing escalation point for the contracted service.
Assurance records
- Incident timeline and ticket record
- Customer notification copies and status updates
- Relevant access/audit logs and evidence-preservation record
- Root-cause and corrective-action report for material incidents
- Incident-response exercise or test records, where appropriate and subject to confidentiality
Applicability
This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.