Summary
BeeTcore detects, classifies, contains, and resolves incidents affecting client platforms through a defined response process. Every incident is logged, owned, and prioritised by severity. Clients are kept informed from first notice to final review. Personal data breaches follow the data protection laws that apply, including the GDPR and the Nigeria Data Protection Act 2023. Every serious incident ends with a written review that strengthens the process.
1. Scope
An incident is any unplanned event that disrupts service, degrades performance, exposes data, or compromises the integrity of a platform in BeeTcore’s care. This strategy covers content management platforms and custom applications, with controls that follow each platform’s stack and project agreement, as set out in the Development Methodology SOP.
2. Detection
Incidents are identified through monitoring at every layer:
- Edge: Cloudflare traffic monitoring and security alerts, across every platform.
- Application (WordPress platforms): Wordfence and MalCare firewall and malware alerts.
- Application (custom builds): real-time error tracking, application performance monitoring, and alerts on vulnerable dependencies.
- Infrastructure: uptime monitoring, server and cloud resource alerts, and centralised logs that flag unusual activity, such as repeated failed logins or unexpected permission changes.
- External: provider notifications and client reports.
Alerts route to the responsible technical owner for immediate triage. Where a client runs its own security operations team or monitoring platform, BeeTcore’s alerts can feed into it.
3. Classification and prioritisation
Every incident is classified by severity when it is logged:
- Critical: platform unavailable, active compromise, or suspected data exposure.
- High: a major function unavailable, such as checkout or payments, or severe performance degradation.
- Medium: limited function affected, with a workaround available.
- Low: a minor defect with no material impact on service.
Critical incidents take priority over all other work. Response times for each severity level are confirmed in the project agreement.
4. Response process
- Acknowledge. Log the incident, classify it, and assign an owner.
- Contain. Where compromise is suspected, isolate the affected environment before investigating further. Containment takes priority over diagnosis.
- Assess. Determine scope, affected systems, and whether personal data is involved.
- Notify. Inform the client, as set out in Section 7.
- Eradicate. Remove the cause: malicious code, compromised accounts, or the exploited weakness.
- Recover. Restore service, from backup where restoration is faster than repair, within the recovery objectives set out in the Service Continuity and Disaster Recovery Strategy.
- Verify. Confirm that function is restored and the cause is closed, not just the symptom.
- Review. Complete the post-incident review, as set out in Section 9.
5. Escalation
Critical and High incidents are escalated to the Senior Delivery Lead as soon as they are classified. Specialist support is brought in where the incident requires it. An incident that threatens a platform’s recovery objectives is escalated to a declared disaster under the Service Continuity and Disaster Recovery Strategy.
6. Investigation
Once an incident is contained, a root cause investigation begins. Logs, affected files, and access records are preserved as evidence before any cleanup that would destroy them. Findings shape both the fix and the preventive measures that follow.
7. Client communication
The client is notified as soon as the scope of an incident is established, with what is known, what is being done, and when the next update will come. Updates continue until the incident is closed.
8. Personal data breaches
Breach handling follows the data protection laws that apply to the data and the people it belongs to, wherever they are. These include the EU and UK GDPR, the Nigeria Data Protection Act 2023, and applicable US state breach notification laws.
- Client platforms. Where BeeTcore processes personal data on a client’s behalf, the client, as data controller, is notified without undue delay and given the technical detail needed to meet their own regulatory obligations. Specific terms can be set in the client’s data processing agreement.
- BeeTcore as data controller. The relevant regulator is notified within the timeframe the applicable law sets, such as 72 hours under both the GDPR and the NDPA. Affected individuals are informed where the law requires it.
9. Post-incident review
Every Critical and High incident receives a written review covering the timeline, root cause, response, and preventive measures. Lessons learned feed into Continuous Service Improvement, and into updates to procedures, training, and tools. This strategy is reviewed annually and after any significant incident.
Frequently asked questions
How does BeeTcore detect security incidents?
Through monitoring at every layer: Cloudflare at the edge, Wordfence and MalCare on WordPress platforms, error tracking and performance monitoring on custom applications, uptime and log alerts on infrastructure, plus provider notifications and client reports.
How fast does BeeTcore respond to an incident?
Every incident is classified by severity, and Critical incidents take priority over all other work. Response times for each severity level are confirmed in the project agreement.
What happens if personal data is involved?
The client is notified without undue delay and given the detail needed for their own reporting. Where BeeTcore is the data controller, regulators and affected individuals are notified as the applicable law requires, such as within 72 hours under the GDPR and the NDPA.