Security Incident Response Plan
Comprehensive procedures and protocols for detecting, responding to, and recovering from security incidents and cyberattacks
Last Updated: September 2026
Plan Overview
POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Security Incident Response Plan (SIRP) designed to ensure rapid detection, effective containment, and thorough remediation of security incidents. This plan establishes clear procedures, roles, and responsibilities for managing security events that could impact our systems, data, or customers.
Core Objectives
- Rapid Detection: Identify security incidents quickly through automated monitoring and threat detection
- Effective Containment: Isolate affected systems to prevent incident spread and minimize damage
- Evidence Preservation: Maintain forensic integrity for investigation and potential legal proceedings
- Swift Recovery: Restore normal operations with minimal business disruption
- Continuous Improvement: Learn from incidents to strengthen security posture
- Stakeholder Communication: Maintain transparent communication with affected parties and regulators
Incident Classification
Critical (P1) - Immediate Response Required
Response Time: As soon as practicable, target within 4 hours | Resolution Target: 24 hours
- Active data breach with confirmed exfiltration of sensitive data
- Ransomware attack with system encryption
- Complete system compromise or takeover
- Payment processing system breach
- Ongoing DDoS attack affecting service availability
- Unauthorized access to production databases
- Zero-day exploit actively being used against our systems
High (P2) - Urgent Response Required
Response Time: As soon as practicable, target within 4 hours | Resolution Target: 48 hours
- Suspected data breach requiring investigation
- Malware infection on multiple systems
- Successful phishing attack on employee accounts
- Unauthorized access attempts with partial success
- Significant vulnerability discovered in production systems
- Insider threat indicators detected
Medium (P3) - Standard Response
Response Time: Within 4 hours | Resolution Target: 72 hours
- Failed unauthorized access attempts (multiple)
- Malware detected and quarantined by security tools
- Policy violations with security implications
- Suspicious network activity requiring investigation
- Non-critical system vulnerabilities
Low (P4) - Informational
Response Time: Within 24 hours | Resolution Target: 7 days
- Isolated failed login attempts
- Security alerts requiring review but no immediate threat
- Minor policy violations
- Security awareness training opportunities
Incident Response Team
Incident Roles
Company Director
- All incident roles are held by the company director, with external legal/forensic help engaged as needed
- Incident coordination, technical analysis, containment, backup and recovery
- Customer, regulator and law-enforcement communication
- Post-incident review and documentation
External Assistance
- External forensic and legal assistance is engaged on demand
- Contractors may assist with technical recovery under the director’s instruction
Alerting
- The director is alerted by automated monitoring (email/messaging)
- Response as soon as practicable, target within 4 hours for critical incidents
Incident Response Phases
1Preparation
Ongoing activities to maintain readiness for security incidents.
- Maintain and update incident response documentation
- Plan walked through annually
- Ensure security tools are properly configured and monitored
- Maintain current contact information for external assistance and providers
- Review and update incident response procedures
- Maintain relationships with external resources (forensics, legal, PR)
- Regular security awareness training for all staff
2Detection & Analysis
Timeline: As soon as practicable from initial alert, target within 4 hours
Detection Sources:
- Server logs, fail2ban, CDN/WAF logs and automated monitoring alerts
- User reports of suspicious activity
- Third-party security notifications
- Vulnerability scanning results
Initial Analysis Steps:
- Verify the incident is legitimate (not false positive)
- Determine incident severity and classify appropriately
- Identify affected systems, data, and users
- Assess scope and potential impact
- Document all findings in incident tracking system
- Begin evidence collection and preservation
- Engage external assistance or contractors where needed
Evidence Preservation:
- Take a server snapshot/backup before remediation
- Preserve log files and network traffic captures
- Document system state and configurations
- Maintain chain of custody for all evidence
- Secure evidence in encrypted, access-controlled storage
3Containment
Timeline: As soon as practicable after incident confirmation
Short-term Containment:
- Isolate affected systems from network (network segmentation)
- Block malicious IP addresses and domains at firewall
- Disable compromised user accounts immediately
- Revoke access tokens and API keys
- Enable additional monitoring on related systems
- Prevent lateral movement within infrastructure
Long-term Containment:
- Apply temporary security patches or configuration changes
- Rebuild compromised systems from clean backups
- Implement enhanced monitoring and logging
- Deploy additional security controls as needed
- Maintain incident isolation while allowing investigation
Service Continuity:
- Fail over to unaffected systems where possible
- Activate business continuity procedures if needed
- Maintain critical business operations during containment
- Provide status updates to stakeholders
4Eradication
Timeline: 1-24 hours (varies by incident severity)
- Remove malware, backdoors, and unauthorized access
- Close vulnerabilities that allowed the incident
- Apply security patches and updates
- Strengthen security controls and configurations
- Remove malicious accounts and reset all credentials
- Verify complete removal of threat through scanning
- Document all remediation actions taken
5Recovery
Timeline: 4-72 hours (varies by incident severity)
System Restoration:
- Restore systems from verified clean backups
- Validate data integrity before restoration
- Gradually return systems to production
- Monitor restored systems closely for reinfection
- Implement enhanced security monitoring
Validation:
- Perform security scans on all recovered systems
- Verify all security controls are functioning properly
- Confirm threat has been completely eliminated
- Test business operations for normal functionality
- Director sign-off before returning systems to service
Return to Operations:
- Gradual restoration of full service availability
- Extended monitoring period (minimum 72 hours)
- Communication of recovery status to stakeholders
- Documentation of recovery procedures and timelines
6Post-Incident Activity
Timeline: Within 7 days of incident resolution
Lessons Learned Meeting:
- Conduct meeting within 72 hours of incident closure
- Review incident timeline and response actions
- Identify what worked well and what needs improvement
- Document recommendations for process improvements
- Assign owners and timelines for improvement actions
Incident Report:
- Complete detailed incident report within 7 days
- Include root cause analysis and impact assessment
- Document all actions taken and their outcomes
- Calculate incident costs (downtime, remediation, etc.)
- Provide recommendations for prevention
- Report to executive leadership and board as appropriate
Process Improvements:
- Update security controls based on findings
- Revise incident response procedures if needed
- Implement additional monitoring or detection capabilities
- Conduct additional training for staff
- Share relevant indicators with our hosting/CDN provider where useful
Communication Procedures
Internal Communications
Immediate:
- The director is alerted by automated monitoring (email/messaging)
As soon as practicable:
- External legal assistance engaged where needed
Within 4 hours:
- Contractors involved in recovery
- Support contacts (if customer impact)
External Communications
Customer Notifications:
- Notify affected customers without undue delay, and within 72 hours where personal data is affected
- Provide clear, non-technical explanation of incident
- Explain steps taken to address the issue
- Offer guidance on protective measures customers should take
- Provide contact information for questions and support
Regulatory Notifications:
- UK GDPR Breach: Notify ICO within 72 hours if personal data affected
- Financial Regulators: As required by applicable regulations
- Maintain documentation of all regulatory notifications
Law Enforcement:
- Contact for criminal activity (hacking, fraud, theft)
- Provide evidence and cooperate with investigations
- Coordinate through external legal counsel where engaged
Third-Party Partners:
- Cloud infrastructure providers notified as needed
- External forensic and legal assistance is engaged on demand
Public Communications
- All public statements are approved by the company director, with legal advice where engaged
- Status page updated for service-affecting incidents
- Public disclosure only when legally required or strategically beneficial
- Media inquiries are handled by the company director
- Maintain consistent messaging across all channels
Security Tools & Resources
Detection & Monitoring
- Server logs, fail2ban, CDN/WAF logs and backups are the primary evidence sources
- Automated monitoring and alerting
- OS and dependency vulnerability updates
Forensics & Analysis
- Server snapshots/backups taken before remediation
- Standard open source log analysis tools
- External forensic assistance engaged on demand
External Resources
- External forensic and legal assistance is engaged on demand
- Hosting and CDN provider support channels
Training & Testing Program
Regular Training
- All Staff: Annual security awareness training including incident reporting
- Director: Annual plan walkthrough and tool familiarization
- Technical Staff: Specialized forensics and analysis training
- New Hires: Incident response overview during onboarding
Testing Schedule
- Annual: Plan walked through annually
- Annual: Comprehensive plan review and update
- All tests documented with lessons learned and improvements
Scenario Testing
Regular exercises based on realistic scenarios:
- Ransomware attack and data encryption
- Data breach with customer information exfiltration
- DDoS attack affecting service availability
- Insider threat with data theft
- Supply chain attack through third-party software
- Phishing campaign compromising employee accounts
Performance Metrics & KPIs
We track the following metrics to measure incident response effectiveness:
- Mean Time to Detect (MTTD): Average time from incident occurrence to detection
- Mean Time to Respond (MTTR): Average time from detection to initial response
- Mean Time to Contain (MTTC): Average time from detection to containment
- Mean Time to Recover (MTTR): Average time from containment to full recovery
- Incident Volume: Number and severity of incidents over time
- False Positive Rate: Percentage of alerts that are not actual incidents
- Training Completion: Percentage of staff completing security training
- Plan Walkthrough: Annual walkthrough completed and documented
Metrics reviewed by the company director after each incident and annually
Plan Maintenance & Updates
- Plan reviewed and updated annually or after major incidents
- Contact information verified at the annual review
- Technology and infrastructure changes trigger immediate plan updates
- Version control maintained for all plan documents
- Regular review of industry best practices and emerging threats
- Incorporation of lessons learned from walkthroughs and actual incidents
Contact Information
To Report a Security Incident:
Email: security@pops.gg (checked daily; automated alerts for critical events)
Urgent Reports: security@pops.gg (checked daily; automated alerts for critical events)
For general security questions or vulnerabilities, please contact our security team at the email above.
For questions regarding our Security Incident Response Plan:
Company Director (all incident roles)
CASH.BH LTD
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Email: compliance@pops.gg