Security Incident Response Plan

Comprehensive procedures and protocols for detecting, responding to, and recovering from security incidents and cyberattacks

Last Updated: September 2026

Plan Overview

POPS.GG (operated by CASH.BH LTD) maintains a comprehensive Security Incident Response Plan (SIRP) designed to ensure rapid detection, effective containment, and thorough remediation of security incidents. This plan establishes clear procedures, roles, and responsibilities for managing security events that could impact our systems, data, or customers.

Core Objectives

  • Rapid Detection: Identify security incidents quickly through automated monitoring and threat detection
  • Effective Containment: Isolate affected systems to prevent incident spread and minimize damage
  • Evidence Preservation: Maintain forensic integrity for investigation and potential legal proceedings
  • Swift Recovery: Restore normal operations with minimal business disruption
  • Continuous Improvement: Learn from incidents to strengthen security posture
  • Stakeholder Communication: Maintain transparent communication with affected parties and regulators

Incident Classification

Critical (P1) - Immediate Response Required

Response Time: As soon as practicable, target within 4 hours | Resolution Target: 24 hours

  • Active data breach with confirmed exfiltration of sensitive data
  • Ransomware attack with system encryption
  • Complete system compromise or takeover
  • Payment processing system breach
  • Ongoing DDoS attack affecting service availability
  • Unauthorized access to production databases
  • Zero-day exploit actively being used against our systems

High (P2) - Urgent Response Required

Response Time: As soon as practicable, target within 4 hours | Resolution Target: 48 hours

  • Suspected data breach requiring investigation
  • Malware infection on multiple systems
  • Successful phishing attack on employee accounts
  • Unauthorized access attempts with partial success
  • Significant vulnerability discovered in production systems
  • Insider threat indicators detected

Medium (P3) - Standard Response

Response Time: Within 4 hours | Resolution Target: 72 hours

  • Failed unauthorized access attempts (multiple)
  • Malware detected and quarantined by security tools
  • Policy violations with security implications
  • Suspicious network activity requiring investigation
  • Non-critical system vulnerabilities

Low (P4) - Informational

Response Time: Within 24 hours | Resolution Target: 7 days

  • Isolated failed login attempts
  • Security alerts requiring review but no immediate threat
  • Minor policy violations
  • Security awareness training opportunities

Incident Response Team

Incident Roles

Company Director

  • All incident roles are held by the company director, with external legal/forensic help engaged as needed
  • Incident coordination, technical analysis, containment, backup and recovery
  • Customer, regulator and law-enforcement communication
  • Post-incident review and documentation

External Assistance

  • External forensic and legal assistance is engaged on demand
  • Contractors may assist with technical recovery under the director’s instruction

Alerting

  • The director is alerted by automated monitoring (email/messaging)
  • Response as soon as practicable, target within 4 hours for critical incidents

Incident Response Phases

1Preparation

Ongoing activities to maintain readiness for security incidents.

  • Maintain and update incident response documentation
  • Plan walked through annually
  • Ensure security tools are properly configured and monitored
  • Maintain current contact information for external assistance and providers
  • Review and update incident response procedures
  • Maintain relationships with external resources (forensics, legal, PR)
  • Regular security awareness training for all staff

2Detection & Analysis

Timeline: As soon as practicable from initial alert, target within 4 hours

Detection Sources:

  • Server logs, fail2ban, CDN/WAF logs and automated monitoring alerts
  • User reports of suspicious activity
  • Third-party security notifications
  • Vulnerability scanning results

Initial Analysis Steps:

  • Verify the incident is legitimate (not false positive)
  • Determine incident severity and classify appropriately
  • Identify affected systems, data, and users
  • Assess scope and potential impact
  • Document all findings in incident tracking system
  • Begin evidence collection and preservation
  • Engage external assistance or contractors where needed

Evidence Preservation:

  • Take a server snapshot/backup before remediation
  • Preserve log files and network traffic captures
  • Document system state and configurations
  • Maintain chain of custody for all evidence
  • Secure evidence in encrypted, access-controlled storage

3Containment

Timeline: As soon as practicable after incident confirmation

Short-term Containment:

  • Isolate affected systems from network (network segmentation)
  • Block malicious IP addresses and domains at firewall
  • Disable compromised user accounts immediately
  • Revoke access tokens and API keys
  • Enable additional monitoring on related systems
  • Prevent lateral movement within infrastructure

Long-term Containment:

  • Apply temporary security patches or configuration changes
  • Rebuild compromised systems from clean backups
  • Implement enhanced monitoring and logging
  • Deploy additional security controls as needed
  • Maintain incident isolation while allowing investigation

Service Continuity:

  • Fail over to unaffected systems where possible
  • Activate business continuity procedures if needed
  • Maintain critical business operations during containment
  • Provide status updates to stakeholders

4Eradication

Timeline: 1-24 hours (varies by incident severity)

  • Remove malware, backdoors, and unauthorized access
  • Close vulnerabilities that allowed the incident
  • Apply security patches and updates
  • Strengthen security controls and configurations
  • Remove malicious accounts and reset all credentials
  • Verify complete removal of threat through scanning
  • Document all remediation actions taken

5Recovery

Timeline: 4-72 hours (varies by incident severity)

System Restoration:

  • Restore systems from verified clean backups
  • Validate data integrity before restoration
  • Gradually return systems to production
  • Monitor restored systems closely for reinfection
  • Implement enhanced security monitoring

Validation:

  • Perform security scans on all recovered systems
  • Verify all security controls are functioning properly
  • Confirm threat has been completely eliminated
  • Test business operations for normal functionality
  • Director sign-off before returning systems to service

Return to Operations:

  • Gradual restoration of full service availability
  • Extended monitoring period (minimum 72 hours)
  • Communication of recovery status to stakeholders
  • Documentation of recovery procedures and timelines

6Post-Incident Activity

Timeline: Within 7 days of incident resolution

Lessons Learned Meeting:

  • Conduct meeting within 72 hours of incident closure
  • Review incident timeline and response actions
  • Identify what worked well and what needs improvement
  • Document recommendations for process improvements
  • Assign owners and timelines for improvement actions

Incident Report:

  • Complete detailed incident report within 7 days
  • Include root cause analysis and impact assessment
  • Document all actions taken and their outcomes
  • Calculate incident costs (downtime, remediation, etc.)
  • Provide recommendations for prevention
  • Report to executive leadership and board as appropriate

Process Improvements:

  • Update security controls based on findings
  • Revise incident response procedures if needed
  • Implement additional monitoring or detection capabilities
  • Conduct additional training for staff
  • Share relevant indicators with our hosting/CDN provider where useful

Communication Procedures

Internal Communications

Immediate:

  • The director is alerted by automated monitoring (email/messaging)

As soon as practicable:

  • External legal assistance engaged where needed

Within 4 hours:

  • Contractors involved in recovery
  • Support contacts (if customer impact)

External Communications

Customer Notifications:

  • Notify affected customers without undue delay, and within 72 hours where personal data is affected
  • Provide clear, non-technical explanation of incident
  • Explain steps taken to address the issue
  • Offer guidance on protective measures customers should take
  • Provide contact information for questions and support

Regulatory Notifications:

  • UK GDPR Breach: Notify ICO within 72 hours if personal data affected
  • Financial Regulators: As required by applicable regulations
  • Maintain documentation of all regulatory notifications

Law Enforcement:

  • Contact for criminal activity (hacking, fraud, theft)
  • Provide evidence and cooperate with investigations
  • Coordinate through external legal counsel where engaged

Third-Party Partners:

  • Cloud infrastructure providers notified as needed
  • External forensic and legal assistance is engaged on demand

Public Communications

  • All public statements are approved by the company director, with legal advice where engaged
  • Status page updated for service-affecting incidents
  • Public disclosure only when legally required or strategically beneficial
  • Media inquiries are handled by the company director
  • Maintain consistent messaging across all channels

Security Tools & Resources

Detection & Monitoring

  • Server logs, fail2ban, CDN/WAF logs and backups are the primary evidence sources
  • Automated monitoring and alerting
  • OS and dependency vulnerability updates

Forensics & Analysis

  • Server snapshots/backups taken before remediation
  • Standard open source log analysis tools
  • External forensic assistance engaged on demand

External Resources

  • External forensic and legal assistance is engaged on demand
  • Hosting and CDN provider support channels

Training & Testing Program

Regular Training

  • All Staff: Annual security awareness training including incident reporting
  • Director: Annual plan walkthrough and tool familiarization
  • Technical Staff: Specialized forensics and analysis training
  • New Hires: Incident response overview during onboarding

Testing Schedule

  • Annual: Plan walked through annually
  • Annual: Comprehensive plan review and update
  • All tests documented with lessons learned and improvements

Scenario Testing

Regular exercises based on realistic scenarios:

  • Ransomware attack and data encryption
  • Data breach with customer information exfiltration
  • DDoS attack affecting service availability
  • Insider threat with data theft
  • Supply chain attack through third-party software
  • Phishing campaign compromising employee accounts

Performance Metrics & KPIs

We track the following metrics to measure incident response effectiveness:

  • Mean Time to Detect (MTTD): Average time from incident occurrence to detection
  • Mean Time to Respond (MTTR): Average time from detection to initial response
  • Mean Time to Contain (MTTC): Average time from detection to containment
  • Mean Time to Recover (MTTR): Average time from containment to full recovery
  • Incident Volume: Number and severity of incidents over time
  • False Positive Rate: Percentage of alerts that are not actual incidents
  • Training Completion: Percentage of staff completing security training
  • Plan Walkthrough: Annual walkthrough completed and documented

Metrics reviewed by the company director after each incident and annually

Plan Maintenance & Updates

  • Plan reviewed and updated annually or after major incidents
  • Contact information verified at the annual review
  • Technology and infrastructure changes trigger immediate plan updates
  • Version control maintained for all plan documents
  • Regular review of industry best practices and emerging threats
  • Incorporation of lessons learned from walkthroughs and actual incidents

Contact Information

To Report a Security Incident:

Email: security@pops.gg (checked daily; automated alerts for critical events)

Urgent Reports: security@pops.gg (checked daily; automated alerts for critical events)

For general security questions or vulnerabilities, please contact our security team at the email above.

For questions regarding our Security Incident Response Plan:

Company Director (all incident roles)

CASH.BH LTD

71–75 Shelton Street, Covent Garden

London, WC2H 9JQ, United Kingdom

Email: compliance@pops.gg