Legistify Services Private Limited
CYBERSECURITY INCIDENT ESCALATION & MANAGEMENT PROCESS
Document Name: | CYBERSECURITY INCIDENT ESCALATION & MANAGEMENT PROCESS |
|
|
Classification: | Internal / Confidential |
|
|
Document Owner: | CISO |
|
|
Document Approver: | Top Management |
|
|
Original Document Issue Date: | 10/09/2023 |
|
|
Current Edition: | Version 4.0 |
|
|
Revision History: |
|
|
|
S. No. | Description of Change | Date of Change | Version No. |
1 | Initial Release | 10/09/2023 | 1.0 |
2 | Second Release | 10/09/2024 | 2.0 |
3 | Third Release | 10/09/2025 | 3.0 |
4 | Fourth Release | 10/09/2026 | 4.0 |
PART A — Cybersecurity Incident Escalation Process
Purpose of the Policy
This document establishes a formal process for identifying, reporting, assessing, escalating, and managing cybersecurity incidents within Legistify. Its objective is to ensure that security incidents are handled in a timely, consistent, and controlled manner, minimising potential impact to the organisation, its clients, and its data, while supporting compliance with applicable information security standards and contractual obligations.
Procedures
Scope
This process applies to all employees, contractors, and third parties operating on behalf of Legistify, and covers the following:
Employees and personnel with access to organisational systems
Endpoints (laptops, desktops, mobile devices)
Servers and cloud infrastructure
Applications, including internally developed and third-party software
Network devices and network infrastructure
User and system accounts
Organisational and customer data
Third-party and vendor services integrated with Legistify systems
Incident Reporting
All employees and relevant teams must promptly report any suspected or confirmed cybersecurity incident to the designated IT/Security team through the approved Zoho communication or ticketing channel. Timely reporting is critical to enabling effective assessment, containment, and resolution of potential threats.
Incident Severity & Escalation
Incidents are classified by severity to determine the appropriate escalation path and urgency of response, as outlined below:
Severity | Example | Escalation |
Critical | Data breach, ransomware, privileged account compromise, major production compromise | Security/IT Lead → Senior Management → Executive Management |
High | Unauthorised access, malware affecting critical systems, significant vulnerability exploitation | Security/IT Lead → Management |
Medium | Suspicious activity, limited malware infection, policy violation | IT/Security Team → Relevant Team Lead |
Low | Minor security event with limited/no impact | IT/Security Team |
Escalation Process
Incidents progress through the following stages:
Detection → Reporting → Initial Assessment → Severity Classification → Containment → Escalation → Investigation → Recovery → Closure
Incidents are escalated immediately, regardless of initial classification, where any of the following conditions apply:
Significant business impact
Exposure of sensitive or confidential data
Privileged account compromise
Customer impact
Inability to contain the incident within expected timeframes
Roles & Responsibilities
Employees: Report suspected incidents immediately upon detection.
IT/Security Team: Triage, investigate, contain, and coordinate the incident response.
Management: Provide decisions and resources required for significant incidents.
Legal/Compliance: Assess legal, regulatory, contractual, and notification requirements where applicable.
Incident Documentation
All incidents must be documented to support accountability, root-cause analysis, and continuous improvement. Documentation must include, at a minimum: incident details, timeline of events, affected assets, collected evidence, actions taken, escalation history, root cause, and final resolution.
Incident Closure
An incident may be formally closed once the following have been completed: containment of the threat, recovery of affected systems and data, validation that normal operations have been restored, complete documentation of the incident, and implementation of any required corrective actions.
Review
This process is reviewed periodically, as well as following any significant security incident or major change to the organisation's environment, to ensure it remains effective and aligned with current risks and operational requirements.
PART B — Cybersecurity Incident Management Process
Purpose
This section defines the process by which Legistify identifies, logs, categorises, investigates, and resolves cybersecurity incidents. It ensures incidents are managed consistently from detection through closure, with clear ownership, documentation, and traceability, supporting the organisation's information security objectives and audit requirements, and complementing the Cyber Incident Escalation Process set out in Part A.
Scope
This process applies to all employees, contractors, and third parties, and covers all cybersecurity-related events affecting endpoints, servers, cloud infrastructure, applications, network devices, accounts, data, and third-party services.
Incident Classification
Incidents are classified by severity to guide response prioritisation, consistent with the severity framework in Part A:
Severity | Example | Target Response Time |
Critical | Data breach, ransomware, privileged account compromise, major production compromise | Immediate (within 30 minutes of detection) |
High | Unauthorised access, malware affecting critical systems, significant vulnerability exploitation | Within 1 hour |
Medium | Suspicious activity, limited malware infection, policy violation | Within 4 hours (same business day) |
Low | Minor security event with limited/no impact | Within 24 hours (1 business day) |
Roles & Responsibilities
Employees: Report suspected incidents immediately through the approved channel.
IT/Security Team: Log, triage, investigate, contain, and resolve incidents; maintain the incident ticket.
Management: Provide decisions and resources required for significant incidents.
Legal/Compliance: Assess legal, regulatory, contractual, and notification requirements where applicable.
Incident Ticket Template
The following fields must be captured for every logged incident, at the appropriate stage of the lifecycle:
Ticket ID | Auto-generated / Manual Reference Number |
Date & Time Reported | DD-MM-YYYY, HH:MM |
Reported By | Name / Employee ID |
Reporting Channel | Ticketing System / Email / Hotline |
Incident Description | Brief description of the observed issue |
Affected Assets / Systems | System, application, account, or device name |
Incident Category | e.g., Malware, Unauthorised Access, Data Exposure, Phishing |
Severity Classification | Critical / High / Medium / Low |
Assigned To | IT/Security Team Member or Group |
Initial Assessment Notes | Findings from preliminary triage |
Containment Actions Taken | Steps performed to limit impact |
Escalation Status | Escalated / Not Escalated — Escalated To |
Investigation Summary | Root cause and findings |
Resolution / Recovery Actions | Steps taken to resolve and restore |
Ticket Status | Open / In Progress / Resolved / Closed |
Closure Date | DD-MM-YYYY |
Reviewed / Approved By | Name / Title |
Documentation & Recordkeeping
Completed incident tickets, together with supporting evidence and communications, must be retained in accordance with the organisation's records retention requirements, and made available for internal review and external audit as required.
Review
This process, and the associated incident ticket template, are reviewed periodically and following any significant security incident or major change to the organisation's environment, to ensure continued effectiveness.
Policy Revision History
Date | Version | Author | Reviewer | Approver | Comments |
10/09/2023 | 1.0 | ISMS Manager | CIO | Legistify Services Pvt. Ltd. Management | Initial release of the Cybersecurity Incident Escalation & Management Process |
10/09/2024 | 2.0 | ISMS Manager | CIO | Legistify Services Pvt. Ltd. Management | Annual review completed; minor updates incorporated to reflect current incident management practices |
10/09/2025 | 3.0 | ISMS Manager | CIO | Legistify Services Pvt. Ltd. Management | Annual review completed; policy revised to align with updated organisational and security requirements |
10/09/2026 | 4.0 | ISMS Manager | CIO | Legistify Services Pvt. Ltd. Management | Annual review completed; policy updated to reflect changes in incident escalation and response standards |
