Incident Response Plan
Effective date: April 11, 2026 · Owner: Head of Security · Reviewed at least annually and after every major incident.
Purpose
This plan defines how Himaya detects, contains, investigates, remediates, and communicates security incidents in order to minimize harm to customers, protect data, and restore normal operations quickly.
What is an incident?
A security incident is any event that compromises, or credibly threatens to compromise, the confidentiality, integrity, or availability of Himaya systems or customer data, such as unauthorized access, data exposure, malware, account compromise, or a tenant-isolation failure.
Severity levels
SEV-1 (Critical): confirmed compromise of customer data or a platform-wide outage. SEV-2 (High): significant but contained security impact. SEV-3 (Moderate): limited impact with no confirmed data exposure. SEV-4 (Low): a minor or potential issue under investigation.
Roles
An Incident Commander coordinates the response and owns decisions; a Security Lead directs investigation and containment; engineering responders execute technical fixes; a Communications Lead manages internal and customer messaging; and an executive sponsor is engaged for high-severity incidents.
Response lifecycle
Every incident follows the same path: detection and reporting, triage and declaration, containment, eradication of the root cause, recovery and validation, and a blameless post-incident review whose action items are tracked to completion.
Communication and notification
Internal stakeholders are updated on a cadence set by severity. Affected customers are notified without undue delay when their data or service is materially affected, and regulatory notifications are made within required timeframes in coordination with legal counsel.
Evidence and testing
All actions, decisions, and findings are recorded with timestamps and retained per legal and contractual obligations. The plan is exercised periodically through tabletop exercises to validate readiness.
Review
This plan is reviewed at least annually and after every major incident, and updated as the platform and regulatory landscape evolve.
