Skip to main content

Cybersecurity Incident Escalation & Management Process

Legistify's cybersecurity incident escalation and management process outlines how security incidents are identified, reported, assessed, escalated, and resolved across the organisation.

M
Written by Mansi Rana

Legistify Services Private Limited

CYBERSECURITY INCIDENT ESCALATION & MANAGEMENT PROCESS

Document Name:

CYBERSECURITY INCIDENT ESCALATION & MANAGEMENT PROCESS

Classification:

Internal / Confidential

Document Owner:

CISO

Document Approver:

Top Management

Original Document Issue Date:

10/09/2023

Current Edition:

Version 4.0

Revision History:

S. No.

Description of Change

Date of Change

Version No.

1

Initial Release

10/09/2023

1.0

2

Second Release

10/09/2024

2.0

3

Third Release

10/09/2025

3.0

4

Fourth Release

10/09/2026

4.0

PART A — Cybersecurity Incident Escalation Process

Purpose of the Policy

This document establishes a formal process for identifying, reporting, assessing, escalating, and managing cybersecurity incidents within Legistify. Its objective is to ensure that security incidents are handled in a timely, consistent, and controlled manner, minimising potential impact to the organisation, its clients, and its data, while supporting compliance with applicable information security standards and contractual obligations.

Procedures

Scope

This process applies to all employees, contractors, and third parties operating on behalf of Legistify, and covers the following:

  • Employees and personnel with access to organisational systems

  • Endpoints (laptops, desktops, mobile devices)

  • Servers and cloud infrastructure

  • Applications, including internally developed and third-party software

  • Network devices and network infrastructure

  • User and system accounts

  • Organisational and customer data

  • Third-party and vendor services integrated with Legistify systems

Incident Reporting

All employees and relevant teams must promptly report any suspected or confirmed cybersecurity incident to the designated IT/Security team through the approved Zoho communication or ticketing channel. Timely reporting is critical to enabling effective assessment, containment, and resolution of potential threats.

Incident Severity & Escalation

Incidents are classified by severity to determine the appropriate escalation path and urgency of response, as outlined below:

Severity

Example

Escalation

Critical

Data breach, ransomware, privileged account compromise, major production compromise

Security/IT Lead → Senior Management → Executive Management

High

Unauthorised access, malware affecting critical systems, significant vulnerability exploitation

Security/IT Lead → Management

Medium

Suspicious activity, limited malware infection, policy violation

IT/Security Team → Relevant Team Lead

Low

Minor security event with limited/no impact

IT/Security Team

Escalation Process

Incidents progress through the following stages:

Detection → Reporting → Initial Assessment → Severity Classification → Containment → Escalation → Investigation → Recovery → Closure

Incidents are escalated immediately, regardless of initial classification, where any of the following conditions apply:

  • Significant business impact

  • Exposure of sensitive or confidential data

  • Privileged account compromise

  • Customer impact

  • Inability to contain the incident within expected timeframes

Roles & Responsibilities

  • Employees: Report suspected incidents immediately upon detection.

  • IT/Security Team: Triage, investigate, contain, and coordinate the incident response.

  • Management: Provide decisions and resources required for significant incidents.

  • Legal/Compliance: Assess legal, regulatory, contractual, and notification requirements where applicable.

Incident Documentation

All incidents must be documented to support accountability, root-cause analysis, and continuous improvement. Documentation must include, at a minimum: incident details, timeline of events, affected assets, collected evidence, actions taken, escalation history, root cause, and final resolution.

Incident Closure

An incident may be formally closed once the following have been completed: containment of the threat, recovery of affected systems and data, validation that normal operations have been restored, complete documentation of the incident, and implementation of any required corrective actions.

Review

This process is reviewed periodically, as well as following any significant security incident or major change to the organisation's environment, to ensure it remains effective and aligned with current risks and operational requirements.

PART B — Cybersecurity Incident Management Process

Purpose

This section defines the process by which Legistify identifies, logs, categorises, investigates, and resolves cybersecurity incidents. It ensures incidents are managed consistently from detection through closure, with clear ownership, documentation, and traceability, supporting the organisation's information security objectives and audit requirements, and complementing the Cyber Incident Escalation Process set out in Part A.

Scope

This process applies to all employees, contractors, and third parties, and covers all cybersecurity-related events affecting endpoints, servers, cloud infrastructure, applications, network devices, accounts, data, and third-party services.

Incident Classification

Incidents are classified by severity to guide response prioritisation, consistent with the severity framework in Part A:

Severity

Example

Target Response Time

Critical

Data breach, ransomware, privileged account compromise, major production compromise

Immediate (within 30 minutes of detection)

High

Unauthorised access, malware affecting critical systems, significant vulnerability exploitation

Within 1 hour

Medium

Suspicious activity, limited malware infection, policy violation

Within 4 hours (same business day)

Low

Minor security event with limited/no impact

Within 24 hours (1 business day)

Roles & Responsibilities

  • Employees: Report suspected incidents immediately through the approved channel.

  • IT/Security Team: Log, triage, investigate, contain, and resolve incidents; maintain the incident ticket.

  • Management: Provide decisions and resources required for significant incidents.

  • Legal/Compliance: Assess legal, regulatory, contractual, and notification requirements where applicable.

Incident Ticket Template

The following fields must be captured for every logged incident, at the appropriate stage of the lifecycle:

Ticket ID

Auto-generated / Manual Reference Number

Date & Time Reported

DD-MM-YYYY, HH:MM

Reported By

Name / Employee ID

Reporting Channel

Ticketing System / Email / Hotline

Incident Description

Brief description of the observed issue

Affected Assets / Systems

System, application, account, or device name

Incident Category

e.g., Malware, Unauthorised Access, Data Exposure, Phishing

Severity Classification

Critical / High / Medium / Low

Assigned To

IT/Security Team Member or Group

Initial Assessment Notes

Findings from preliminary triage

Containment Actions Taken

Steps performed to limit impact

Escalation Status

Escalated / Not Escalated — Escalated To

Investigation Summary

Root cause and findings

Resolution / Recovery Actions

Steps taken to resolve and restore

Ticket Status

Open / In Progress / Resolved / Closed

Closure Date

DD-MM-YYYY

Reviewed / Approved By

Name / Title

Documentation & Recordkeeping

Completed incident tickets, together with supporting evidence and communications, must be retained in accordance with the organisation's records retention requirements, and made available for internal review and external audit as required.

Review

This process, and the associated incident ticket template, are reviewed periodically and following any significant security incident or major change to the organisation's environment, to ensure continued effectiveness.

Policy Revision History

Date

Version

Author

Reviewer

Approver

Comments

10/09/2023

1.0

ISMS Manager

CIO

Legistify Services Pvt. Ltd. Management

Initial release of the Cybersecurity Incident Escalation & Management Process

10/09/2024

2.0

ISMS Manager

CIO

Legistify Services Pvt. Ltd. Management

Annual review completed; minor updates incorporated to reflect current incident management practices

10/09/2025

3.0

ISMS Manager

CIO

Legistify Services Pvt. Ltd. Management

Annual review completed; policy revised to align with updated organisational and security requirements

10/09/2026

4.0

ISMS Manager

CIO

Legistify Services Pvt. Ltd. Management

Annual review completed; policy updated to reflect changes in incident escalation and response standards

Did this answer your question?