{"id":12671,"date":"2025-01-07T09:08:45","date_gmt":"2025-01-07T09:08:45","guid":{"rendered":"https:\/\/baticlick.com\/?page_id=12671"},"modified":"2025-05-23T10:44:20","modified_gmt":"2025-05-23T10:44:20","slug":"incidents-databreach","status":"publish","type":"page","link":"https:\/\/baticlick.com\/en\/incidents-databreach\/","title":{"rendered":"Incidents &amp; Data Breaches"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"12671\" class=\"elementor elementor-12671\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-cb5fc76 e-con-full e-flex e-con e-parent\" data-id=\"cb5fc76\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-69c0673 e-flex e-con-boxed e-con e-parent\" data-id=\"69c0673\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ddc5fb1 elementor-widget elementor-widget-heading\" data-id=\"ddc5fb1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Security Incidents &amp; Data Breach Management Policy and Procedure\n\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7cd6605 e-flex e-con-boxed e-con e-parent\" data-id=\"7cd6605\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-5511694 e-con-full e-flex e-con e-child\" data-id=\"5511694\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d09f0bf elementor-widget elementor-widget-image\" data-id=\"d09f0bf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"612\" height=\"408\" src=\"https:\/\/baticlick.com\/wp-content\/uploads\/2025\/01\/istockphoto-185258639-612x612-1.jpg\" class=\"attachment-large size-large wp-image-12649\" alt=\"\" srcset=\"https:\/\/baticlick.com\/wp-content\/uploads\/2025\/01\/istockphoto-185258639-612x612-1.jpg 612w, https:\/\/baticlick.com\/wp-content\/uploads\/2025\/01\/istockphoto-185258639-612x612-1-600x400.jpg 600w, https:\/\/baticlick.com\/wp-content\/uploads\/2025\/01\/istockphoto-185258639-612x612-1-300x200.jpg 300w, https:\/\/baticlick.com\/wp-content\/uploads\/2025\/01\/istockphoto-185258639-612x612-1-18x12.jpg 18w\" sizes=\"(max-width: 612px) 100vw, 612px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d54bcf3 elementor-widget elementor-widget-text-editor\" data-id=\"d54bcf3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Security Incidents &amp; Data Breach Management Policy and Procedure<\/p><p>14 April 2025<\/p><p><strong>Incident Management Plan<\/strong><\/p><p><strong>Introduction<\/strong><\/p><p>This plan sets out the procedures for identifying, responding to, mitigating and recovering from cyber security incidents affecting <strong>monecopote.com<\/strong>. The aim is to ensure the platform operates smoothly in accordance with current laws and regulations and to protect it from cyber threats.<\/p><p>Baticlick is committed to exercising due care and attention to (i) taking preventive measures against cyber incidents, (ii) dealing with them appropriately when they occur, (iii) providing information to staff and other relevant parties (users, sellers, customers, partners, contractors, suppliers, authorities) as necessary, and (iv) restoring access and operations as soon as possible.<\/p><p><strong> Incident categories<\/strong><\/p><p>Potential threats include:<\/p><p>DDoS Attacks \u2013 Disrupting website availability.<\/p><p>Malware Infections \u2013 Injecting malicious code into the platform.<\/p><p>Unauthorised Access \u2013 Data breaches or account takeovers.<\/p><p>Payment Fraud \u2013 Fake transactions affecting users.<\/p><p>Phishing\/Social Engineering \u2013 Attacks on administrators or users.<\/p><p><strong> Preventive measures <\/strong>Factors to be considered in this context include:<\/p><p>Regular security audits \u2013 Carry out periodic penetration testing.<\/p><p>Strong access controls \u2013 Use MFA and role-based permissions.<\/p><p>Data encryption \u2013 Secure sensitive information.<\/p><p>Web Application Firewall (WAF) \u2013 Protect against attacks.<\/p><p>Backup and disaster recovery \u2013 Ensure that daily backups are stored securely.<\/p><p><strong> Incident detection and reporting<\/strong> shall be carried out as follows:<\/p><p>Monitoring of traffic and logs by an external service provider<\/p><p>Users can use a contact form to report suspicious activity<\/p><p>Automated alerts for unusual traffic or login attempts<\/p><p><strong> Incident response steps<\/strong><\/p><p>When an incident is detected, it is crucial to follow a structured approach to contain and mitigate the threat effectively. The following five-phase response process will be implemented:<\/p><ol><li><u>Identification &amp; Classification <\/u>(to determine whether an incident has occurred and assess its severity.)<\/li><\/ol><p>Initial detection through system monitoring and the review of user reports on suspicious activities (e.g. unauthorised logins, fraudulent transactions)<\/p><p>Log and analyse data by collecting logs from affected systems, including access logs, error logs and network traffic, and by identifying attack vectors (e.g. phishing, malware, SQL injection).<\/p><p>Classify the incident: Low severity for minor security issues (e.g., failed login attempts); medium severity for incidents with potential impact (e.g., small-scale malware infection); high severity for active threats affecting users or business operations; critical severity for major security breaches (e.g., data leaks, ransomware attacks)<\/p><p>Activate the response team by notifying the incident response lead and IT security<\/p><p><u>2. Containment (to l<\/u>to limit the spread and damage caused by the incident whilst preserving forensic evidence.<\/p><p><em>Short-term actions:<\/em><\/p><p>Network containment (Block malicious IP addresses or impose geographical restrictions on access where necessary; isolate affected systems from the main network)<\/p><p>Account containment (Disable compromised user and admin accounts; enforce password resets for affected users)<\/p><p>Containment measures (Temporarily disable affected website functions (e.g., payment gateway, order processing); update firewall rules to block malicious traffic.).<\/p><p><em>Long-term actions:<\/em><\/p><p>Secure backups (Check that recent backups are intact; if necessary, redirect traffic to a backup server)<\/p><p>Preserve evidence (Make copies of the relevant system logs for forensic analysis; document all actions taken during containment)<\/p><p><u>3. Eradication and recovery<\/u> (to eliminate the root cause of the incident and restore normal operations.).<\/p><p><em>Eradication Steps:<\/em><\/p><p>Identify the attack vector (analyse logs, malware signatures and attack patterns; determine whether the cause was human error, a system vulnerability or an external attack)<\/p><p>Address vulnerabilities (apply software updates, security patches and configuration fixes; strengthen firewall, authentication and API security)<\/p><p>Malware removal (run antivirus\/malware scans on affected systems; delete or quarantine infected files)<\/p><p><em>Recovery Steps<\/em>:<\/p><p>Restore services (reinstall affected applications if necessary; restore data from backups, ensuring there is no reinfection by malware)<\/p><p>Monitor for any remaining threats (carry out post-recovery penetration testing; step up log monitoring for unusual behaviour)<\/p><p><u>4. Communication &amp; notification<\/u> (to ensure timely and transparent communication with stakeholders)<\/p><p>Internal communication (inform management, IT and legal teams; hold a status update meeting with the response team)<\/p><p>External communication (notify affected users; advise users to reset their passwords and enable two-factor authentication; if legally required, report breaches to data protection authorities; inform third-party vendors if their services were affected)<\/p><p><u>5. Post-incident review and lessons learnt<\/u> (to improve security measures to prevent future incidents)<\/p><p><em>Shares<\/em>:<\/p><p>Conduct an incident review (analyse logs, attack vectors and the effectiveness of the response; identify gaps in detection, containment and recovery processes)<\/p><p>Document findings (draw up a detailed report including a root cause analysis and action points; recommend improvements to security policies)<\/p><p>Strengthen security controls (update firewall rules, IDS\/IPS settings and access controls; provide further training for staff to recognise cyber threats)<\/p><p><strong>\u00a0<\/strong><\/p><p><strong style=\"color: var(--rz-text-color); font-family: var(--rz-font-family-primary);\">Contact &amp; Response Team<\/strong><\/p><p>Incident response lead: Ga\u00ebtan Bio<\/p><p>IT security contact: Ga\u00ebtan Bio<\/p><p>Legal and compliance contact: Ga\u00ebtan Bio<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cae35d elementor-widget elementor-widget-text-editor\" data-id=\"0cae35d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u00a0<\/p><p><strong>Appendix 2: Incident Response Instructions for IT Systems<\/strong><\/p><p><strong>Dos<\/strong><br \/>Immediately isolate the affected system to prevent further problems. Use telephone communication rather than email. Save all logs, such as firewall and system logs. Create backup copies of any damaged files and store them securely. Determine the affected system\u2019s location within the network. List all systems connected to the affected system. Identify the programmes running on the system, the impact of the issue, and the acceptable downtime. If the system is seized as evidence, ensure services continue by using backups or a redundant system.<\/p><p><strong>DON\u2019Ts<\/strong><br \/>Do not discuss the matter with anyone other than your manager or designated contacts. Do not delete or alter any files on the affected system. Do not contact the person under suspicion. Do not carry out any forensic analysis.<\/p><p><strong>Appendix 3: Overview of Privacy Risk Ratings<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dea066b elementor-widget elementor-widget-text-editor\" data-id=\"dea066b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u00a0<\/p><table><tbody><tr><td rowspan=\"2\" width=\"150\">Factor<\/td><td colspan=\"3\" width=\"454\">RISK RATING<\/td><\/tr><tr><td width=\"149\">LOW<\/td><td width=\"154\">MEDIUM<\/td><td width=\"151\">HIGH<\/td><\/tr><tr><td width=\"150\">Nature of personal information<\/td><td width=\"149\">Publicly available personal information not linked to any other information<\/td><td width=\"154\">Personal information specific to the organisation that is neither medical nor financial in nature<\/td><td width=\"151\"><p>Medical, psychological, counselling or financial information, or a unique public body identification number<\/p><p>number<\/p><\/td><\/tr><tr><td width=\"150\">Relationships<\/td><td width=\"149\">Accidental disclosure to a contractor who reported the breach and confirmed that the information had been destroyed or returned<\/td><td width=\"154\"><p>Accidental disclosure to a<\/p><p>a stranger who reported the breach and confirmed<\/p><p>destruction or return of the information<\/p><\/td><td width=\"151\"><p>Disclosure to an individual with whom there is some relationship<\/p><p>to or with the knowledge of the affected individual(s), particularly disclosures to interested family members, neighbours or colleagues<\/p><\/td><\/tr><tr><td width=\"10\">\u00a0<\/td><td width=\"149\">\u00a0<\/td><td width=\"154\">\u00a0<\/td><td width=\"151\">Theft<\/td><\/tr><tr><td width=\"150\">Cause of the breach<\/td><td width=\"149\">A technical error that has now been resolved<\/td><td width=\"154\">Accidental loss or disclosure<\/td><td width=\"151\"><p>Intentional breach. Cause unknown. Technical error \u2013 if not resolved<\/p><\/td><\/tr><tr><td width=\"150\">Scope<\/td><td width=\"149\">Very few people affected<\/td><td width=\"154\">An identified and limited group of affected individuals<\/td><td width=\"151\"><p>Large group or the entire scope of the group not identified<\/p><p>(over 100)<\/p><\/td><\/tr><\/tbody><\/table><table><tbody><tr><td width=\"150\">Containment efforts<\/td><td width=\"149\"><p>The data was properly encrypted<\/p><p>The portable storage device was wiped remotely, and there is evidence that the device was not accessed prior to being wiped<\/p><p>Hard copy files or devices were recovered almost immediately, and all files appear to be intact and\/or unread<\/p><\/td><td width=\"154\"><p>The portable storage device was remotely wiped within hours of being lost, but there is no evidence to confirm that the device was not accessed prior to being wiped<\/p><p>Hard copy files or devices were recovered, but enough time had elapsed between the loss and<\/p><p>recovery that the data might have<\/p><p>has been accessed<\/p><\/td><td width=\"151\"><p>The data was not encrypted<\/p><p>Data, files or devices have not been recovered<\/p><p>Data at risk of further disclosure, particularly through the mass media or online<\/p><\/td><\/tr><tr><td width=\"150\">Foreseeable harm resulting from the breach<\/td><td width=\"149\">No foreseeable harm resulting from the breach<\/td><td width=\"154\"><p>Loss of business or employment opportunities, personal injury, humiliation, damage to reputation or relationships, social or relational harm<\/p><p>Loss of trust in My Eco Best Friend Loss of My Eco Best Friend\u2019s assets Loss of My Eco Best Friend\u2019s contracts or business Financial exposure<\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c80bb7 elementor-align-center elementor-widget elementor-widget-button\" data-id=\"7c80bb7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/baticlick.com\/en\/terms-and-conditions\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">More on Baticlick\u2019s Terms and Conditions<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3bf7b2b e-con-full e-flex e-con e-parent\" data-id=\"3bf7b2b\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;shape_divider_bottom&quot;:&quot;mountains&quot;}\">\n\t\t\t\t<div class=\"elementor-shape elementor-shape-bottom\" aria-hidden=\"true\" data-negative=\"false\">\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewbox=\"0 0 1000 100\" preserveaspectratio=\"none\">\n\t<path class=\"elementor-shape-fill\" opacity=\"0.33\" d=\"M473,67.3c-203.9,88.3-263.1-34-320.3,0C66,119.1,0,59.7,0,59.7V0h1000v59.7 c0,0-62.1,26.1-94.9,29.3c-32.8,3.3-62.8-12.3-75.8-22.1C806,49.6,745.3,8.7,694.9,4.7S492.4,59,473,67.3z\"\/>\n\t<path class=\"elementor-shape-fill\" opacity=\"0.66\" d=\"M734,67.3c-45.5,0-77.2-23.2-129.1-39.1c-28.6-8.7-150.3-10.1-254,39.1 s-91.7-34.4-149.2,0C115.7,118.3,0,39.8,0,39.8V0h1000v36.5c0,0-28.2-18.5-92.1-18.5C810.2,18.1,775.7,67.3,734,67.3z\"\/>\n\t<path class=\"elementor-shape-fill\" d=\"M766.1,28.9c-200-57.5-266,65.5-395.1,19.5C242,1.8,242,5.4,184.8,20.6C128,35.8,132.3,44.9,89.9,52.5C28.6,63.7,0,0,0,0 h1000c0,0-9.9,40.9-83.6,48.1S829.6,47,766.1,28.9z\"\/>\n<\/svg>\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c6f21a8 e-con-full e-flex e-con e-child\" data-id=\"c6f21a8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3423bb9 e-con-full e-flex e-con e-child\" data-id=\"3423bb9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1d6f99d e-con-full e-flex e-con e-child\" data-id=\"1d6f99d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1092127 e-flex e-con-boxed e-con e-child\" data-id=\"1092127\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a3b1bed e-con-full e-flex e-con e-parent\" data-id=\"a3b1bed\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Security Incidents &#038; Data Breach Management Policy and Procedure Security Incidents &amp; Data Breach Management Policy and Procedure April 14, 2025 Incident Management Plan Introduction This plan outlines the procedures for identifying, responding to, mitigating, and recovering from cybersecurity incidents affecting monecopote.com. The goal is to ensure the well-functioning of the platform in compliance with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-12671","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/pages\/12671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/comments?post=12671"}],"version-history":[{"count":46,"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/pages\/12671\/revisions"}],"predecessor-version":[{"id":14443,"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/pages\/12671\/revisions\/14443"}],"wp:attachment":[{"href":"https:\/\/baticlick.com\/en\/wp-json\/wp\/v2\/media?parent=12671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}