Security Incidents & Data Breach Management Policy and Procedure
Security Incidents & Data Breach Management Policy and Procedure
14 April 2025
Incident Management Plan
Introduction
This plan sets out the procedures for identifying, responding to, mitigating and recovering from cyber security incidents affecting monecopote.com. The aim is to ensure the platform operates smoothly in accordance with current laws and regulations and to protect it from cyber threats.
Baticlick is committed to exercising due care and attention to (i) taking preventive measures against cyber incidents, (ii) dealing with them appropriately when they occur, (iii) providing information to staff and other relevant parties (users, sellers, customers, partners, contractors, suppliers, authorities) as necessary, and (iv) restoring access and operations as soon as possible.
Incident categories
Potential threats include:
DDoS Attacks – Disrupting website availability.
Malware Infections – Injecting malicious code into the platform.
Unauthorised Access – Data breaches or account takeovers.
Payment Fraud – Fake transactions affecting users.
Phishing/Social Engineering – Attacks on administrators or users.
Preventive measures Factors to be considered in this context include:
Regular security audits – Carry out periodic penetration testing.
Strong access controls – Use MFA and role-based permissions.
Data encryption – Secure sensitive information.
Web Application Firewall (WAF) – Protect against attacks.
Backup and disaster recovery – Ensure that daily backups are stored securely.
Incident detection and reporting shall be carried out as follows:
Monitoring of traffic and logs by an external service provider
Users can use a contact form to report suspicious activity
Automated alerts for unusual traffic or login attempts
Incident response steps
When an incident is detected, it is crucial to follow a structured approach to contain and mitigate the threat effectively. The following five-phase response process will be implemented:
- Identification & Classification (to determine whether an incident has occurred and assess its severity.)
Initial detection through system monitoring and the review of user reports on suspicious activities (e.g. unauthorised logins, fraudulent transactions)
Log and analyse data by collecting logs from affected systems, including access logs, error logs and network traffic, and by identifying attack vectors (e.g. phishing, malware, SQL injection).
Classify the incident: Low severity for minor security issues (e.g., failed login attempts); medium severity for incidents with potential impact (e.g., small-scale malware infection); high severity for active threats affecting users or business operations; critical severity for major security breaches (e.g., data leaks, ransomware attacks)
Activate the response team by notifying the incident response lead and IT security
2. Containment (to lto limit the spread and damage caused by the incident whilst preserving forensic evidence.
Short-term actions:
Network containment (Block malicious IP addresses or impose geographical restrictions on access where necessary; isolate affected systems from the main network)
Account containment (Disable compromised user and admin accounts; enforce password resets for affected users)
Containment measures (Temporarily disable affected website functions (e.g., payment gateway, order processing); update firewall rules to block malicious traffic.).
Long-term actions:
Secure backups (Check that recent backups are intact; if necessary, redirect traffic to a backup server)
Preserve evidence (Make copies of the relevant system logs for forensic analysis; document all actions taken during containment)
3. Eradication and recovery (to eliminate the root cause of the incident and restore normal operations.).
Eradication Steps:
Identify the attack vector (analyse logs, malware signatures and attack patterns; determine whether the cause was human error, a system vulnerability or an external attack)
Address vulnerabilities (apply software updates, security patches and configuration fixes; strengthen firewall, authentication and API security)
Malware removal (run antivirus/malware scans on affected systems; delete or quarantine infected files)
Recovery Steps:
Restore services (reinstall affected applications if necessary; restore data from backups, ensuring there is no reinfection by malware)
Monitor for any remaining threats (carry out post-recovery penetration testing; step up log monitoring for unusual behaviour)
4. Communication & notification (to ensure timely and transparent communication with stakeholders)
Internal communication (inform management, IT and legal teams; hold a status update meeting with the response team)
External communication (notify affected users; advise users to reset their passwords and enable two-factor authentication; if legally required, report breaches to data protection authorities; inform third-party vendors if their services were affected)
5. Post-incident review and lessons learnt (to improve security measures to prevent future incidents)
Shares:
Conduct an incident review (analyse logs, attack vectors and the effectiveness of the response; identify gaps in detection, containment and recovery processes)
Document findings (draw up a detailed report including a root cause analysis and action points; recommend improvements to security policies)
Strengthen security controls (update firewall rules, IDS/IPS settings and access controls; provide further training for staff to recognise cyber threats)
Contact & Response Team
Incident response lead: Gaëtan Bio
IT security contact: Gaëtan Bio
Legal and compliance contact: Gaëtan Bio
Appendix 2: Incident Response Instructions for IT Systems
Dos
Immediately isolate the affected system to prevent further problems. Use telephone communication rather than email. Save all logs, such as firewall and system logs. Create backup copies of any damaged files and store them securely. Determine the affected system’s location within the network. List all systems connected to the affected system. Identify the programmes running on the system, the impact of the issue, and the acceptable downtime. If the system is seized as evidence, ensure services continue by using backups or a redundant system.
DON’Ts
Do not discuss the matter with anyone other than your manager or designated contacts. Do not delete or alter any files on the affected system. Do not contact the person under suspicion. Do not carry out any forensic analysis.
Appendix 3: Overview of Privacy Risk Ratings
| Factor | RISK RATING | ||
| LOW | MEDIUM | HIGH | |
| Nature of personal information | Publicly available personal information not linked to any other information | Personal information specific to the organisation that is neither medical nor financial in nature | Medical, psychological, counselling or financial information, or a unique public body identification number number |
| Relationships | Accidental disclosure to a contractor who reported the breach and confirmed that the information had been destroyed or returned | Accidental disclosure to a a stranger who reported the breach and confirmed destruction or return of the information | Disclosure to an individual with whom there is some relationship to or with the knowledge of the affected individual(s), particularly disclosures to interested family members, neighbours or colleagues |
| Theft | |||
| Cause of the breach | A technical error that has now been resolved | Accidental loss or disclosure | Intentional breach. Cause unknown. Technical error – if not resolved |
| Scope | Very few people affected | An identified and limited group of affected individuals | Large group or the entire scope of the group not identified (over 100) |
| Containment efforts | The data was properly encrypted The portable storage device was wiped remotely, and there is evidence that the device was not accessed prior to being wiped Hard copy files or devices were recovered almost immediately, and all files appear to be intact and/or unread | The portable storage device was remotely wiped within hours of being lost, but there is no evidence to confirm that the device was not accessed prior to being wiped Hard copy files or devices were recovered, but enough time had elapsed between the loss and recovery that the data might have has been accessed | The data was not encrypted Data, files or devices have not been recovered Data at risk of further disclosure, particularly through the mass media or online |
| Foreseeable harm resulting from the breach | No foreseeable harm resulting from the breach | Loss of business or employment opportunities, personal injury, humiliation, damage to reputation or relationships, social or relational harm Loss of trust in My Eco Best Friend Loss of My Eco Best Friend’s assets Loss of My Eco Best Friend’s contracts or business Financial exposure |