Triage
Record source, time, scope, tenant, suspected risk and owner.
Jarvisby TheSEOThe process treats availability, confidentiality, integrity, privacy and unwanted AI behaviour as separate but linked risks.
P0, P1 and P2 say how bad something is. What they do not say is how fast we respond. That column is left open because there is no service level agreement yet and no test that could back such a number up. It gets filled in as soon as there is, and not before.
Record source, time, scope, tenant, suspected risk and owner.
Revoke access, pause a connector or isolate a component without losing evidence.
Inform the customer and the parties entitled to know, without needless speculation, on a fixed update rhythm.
Fix the cause, test the recovery, document the impact and follow through on the improvement actions.
P0 threatens several tenants, critical confidentiality or core availability. P1 has large customer impact or a likely personal data breach. P2 is limited and manageable. No response time hangs off those three levels that we would dare to call a promise: as long as it is not in a service level agreement and not backed by a test, a number here would say more than is true. What is settled is where the availability commitments stand.
As a processor, TheSEO supplies the customer with the information it has without undue delay, and internally aims to do so within twenty four hours of confirmation. That commitment sits in the chapter on personal data breaches of the data processing agreement. The controller decides on notification to its supervisory authority and to the people concerned, with support from us where that has been agreed. Which authority that is depends on where the controller sits, and it is the controller who makes that call, not us.
Wrong tool actions, prompt injection, source poisoning, systematic hallucination and an unexpected model change can be incidents too. They get reproducible evidence and an owner.
With a personal data breach the route runs in three steps. We are the processor and we hand over what we know. The decision to notify sits with the controller, so with the customer. The twenty four hours is an internal target, not a statutory deadline and not a service level agreement.