vStream Digital Media

Incident Management Policy

Last updated: 03/02/25

1. Definitions

TermDefinition
Security IncidentAny event that could compromise the confidentiality, integrity, or availability of vStream information assets, including data breaches, unauthorised access, system compromises, malware infections, denial of service attacks, and significant security policy violations.
Data BreachA security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Incident Response TeamThe team responsible for managing security incidents, typically including the CTO, CPO, backend developers, and Account Director for customer communication.
ContainmentActions taken to prevent an incident from spreading or causing additional damage while investigation and remediation activities are underway.
Root Cause AnalysisSystematic investigation to identify the fundamental cause of an incident, distinguishing from symptoms or contributing factors.
Post-Incident ReviewA structured review conducted after incident resolution to document lessons learned, identify process improvements, and prevent recurrence.

2. Policy Statement

vStream Digital Media is committed to rapid, effective response to security incidents affecting our systems, applications, or customer data. This policy establishes procedures for detecting, reporting, assessing, responding to, and learning from security incidents to minimise impact on business operations, customer services (particularly ShineVR healthcare applications), and data protection obligations.

All employees, contractors, and third parties must immediately report suspected security incidents through established channels. Failure to report incidents or attempts to conceal incidents may result in disciplinary action.

This policy works in conjunction with the comprehensive Incident Response Plan which provides detailed technical procedures, escalation paths, and response playbooks for specific incident types.

3. Purpose

The purpose of this policy is to:

4. Scope

This policy applies to security incidents affecting:

5. Incident Severity Classification

All security incidents are classified into three priority levels based on impact and urgency:

5.1 P1 - Critical Incidents

Definition: Incidents with severe impact requiring immediate action.

Initial Response Time: 15 minutes

Examples:

5.2 P2 - High Priority Incidents

Definition: Incidents with significant impact requiring urgent attention.

Initial Response Time: 2 hours

Examples:

5.3 P3 - Low Priority Incidents

Definition: Incidents with limited impact requiring standard response.

Initial Response Time: 24 hours (next business day)

Examples:

6. Incident Response Procedure

6.1 Detection and Reporting

Security incidents may be detected through:

Reporting Channels:

6.2 Initial Assessment

Upon receiving an incident report, the CTO or designated responder performs initial assessment:

6.3 Containment

Immediate actions to prevent incident escalation:

6.4 Investigation

Detailed analysis to understand incident scope and root cause:

6.5 Eradication

Remove the threat and address vulnerabilities:

6.6 Recovery

Restore systems to normal operations:

6.7 Post-Incident Review

Mandatory for all P1 and P2 incidents, optional for P3:

7. Escalation and Communication

7.1 24/7 Escalation Contacts

For P1 critical incidents requiring immediate response:

RoleNameResponsibilityContact
Incident Commander (CTO)Andrés PittOverall incident leadership, technical decision-making authority, resource allocation, regulatory liaisonandres@vstream.ie
(086) 788 6570
Business Lead (CPO)Andrew JenkinsonBusiness impact assessment, service continuity decisions, customer experience coordinationandrew@vstream.ie
(087) 948 0090
Customer Communications Lead (Account Director)Sabina BocciniCustomer communications, stakeholder management, external relationship coordinationsabina@vstream.ie

Note: These contacts are available 24 hours a day, 7 days a week for P1 incidents. Response times are measured from first contact.

7.2 Customer Communication

For incidents affecting customer services or data:

8. GDPR Data Breach Notification

For incidents involving personal data breaches, vStream complies with GDPR notification requirements:

8.1 Data Protection Commission Notification

8.2 Data Subject Notification

When breach likely to result in high risk to individuals:

8.3 Data Controller Notification

As a Data Processor for customers:

9. Incident Documentation

All security incidents must be documented with:

10. Training and Testing

10.1 Security Awareness Training

10.2 Incident Response Testing

11. Roles and Responsibilities

11.1 Chief Technology Officer / Data Protection Officer

11.2 Backend Developers

11.3 Account Director

11.4 All Employees

12. Related Policies and Documents

13. Contact Information

24/7 Security Incident Hotline — Andrés Pitt (CTO / DPO) Phone: (086) 788 6570  ·  Email: andres@vstream.ie

Company Address vStream Digital Media, 37 Leeson Close, Dublin 2, D02 H344, Ireland
Website: vStream.ie