← Back to Home

Incident Response Policy

Last Updated: August 2026

This Incident Response Policy describes how Sixty67 Intelligence detects, responds to, and learns from security incidents.

Severity Classification

  • Critical: 30 min response, widespread outage or confirmed breach.
  • High: 2 hr response, major feature outage or data risk.
  • Medium: 4 hr response, limited impact or degraded performance.
  • Low: 24 hr response, minor issues with workaround available.

Response Process

  • 1. Detection: alerts from monitoring, user reports, or partner notifications.
  • 2. Assessment: classify severity and confirm scope.
  • 3. Containment: isolate affected systems and stop the spread.
  • 4. Notification: inform affected customers and regulators where required.
  • 5. Remediation: restore service and remove the root cause.
  • 6. Post-incident review: document lessons and improve controls.

Breach Notification Timeline

Where a personal data breach occurs, we notify affected individuals and regulators within 72 hours, as required by GDPR and PIPEDA.

Contact

To report a security incident, contact security@sixty67intelligence.com.