← Policies & standards

Incident Response Plan

Updated for AI, agent, prompt and cloud incidents

Version: 1.1 Updated: 06 August 2026

1. Purpose

This plan defines how TFG prepares for, detects, contains, eradicates, recovers from and learns from information-security, cyber, privacy and AI-related incidents. It supports UK GDPR, the Data Protection Act 2018 and ISO 27001-aligned incident management.

2. Incident types

Unauthorised access, malware, ransomware, data loss, account compromise or service outage.

Client or personal information disclosed through a prompt, output, connector, log or knowledge source.

Prompt injection, jailbreak, unsafe content, unauthorised tool execution or agent action.

Excessive permissions, misconfigured retrieval, cross-client exposure or unintended source access.

Model/provider incident, unexpected retention, sub-processor change or service compromise.

Incorrect high-impact output acted upon without required human approval.

3. Severity

Severity

Definition

Examples

P1 Critical

Severe legal, client, safety, confidentiality, integrity or availability impact.

Confirmed sensitive-data exposure; material cross-client disclosure; ransomware; uncontrolled high-impact agent action.

P2 Major

Serious incident with potential escalation or material service/client impact.

Unauthorised access; high-risk prompt leakage; agent misconfiguration; malware detected early.

P3 Minor

Limited incident requiring remediation.

Low-impact inappropriate output; contained misconfiguration; suspicious activity.

P4 Informational

No confirmed impact; monitor or record.

Threat intelligence; blocked policy violation; unsuccessful attack.

4. Roles

Role

Responsibility

SOC / Simplify IT

Monitoring, investigation, containment, recovery and evidence preservation.

Operations Director / ISMS Lead

Incident coordination, severity, personal-data assessment, client/regulatory decision support and incident log.

AI / Product Owner

Disable affected agent or connector; preserve prompts, configuration, sources and evaluations; support root-cause analysis.

Security / Privacy / Legal

Assess contractual, privacy and notification obligations.

Board

Risk acceptance, strategic decisions and business continuity.

All personnel

Report suspected incidents immediately and preserve evidence.

5. Response process

Prepare

Maintain contacts, logging, backups, access controls, training, playbooks and tested shutdown routes.

Detect and triage

Log the report; identify systems, data, users, prompts, sources, connectors and actions; classify severity and preserve evidence.

Contain

Disable compromised accounts, agents, connectors or tools; revoke tokens; isolate systems; suspend data flows; block malicious activity.

Eradicate

Remove malicious content or code, correct permissions and configuration, rotate secrets, patch vulnerabilities and remove unsafe grounding data.

Recover

Restore in a controlled manner, retest permissions and safety controls, increase monitoring and communicate with authorised stakeholders.

Review

Complete root-cause analysis, lessons learned, client/regulatory review, corrective actions and policy/model updates.

6. Notification

The Operations Director and Privacy/Legal support assess whether the incident is a personal-data breach and whether notification duties apply. Where the statutory threshold is met, the ICO notification deadline is 72 hours after awareness. Contractual client notification requirements may be different and must be checked.

7. AI evidence checklist

Prompt and response; timestamp; user and agent identity.

System instructions, model/version, tools and connectors.

Sources retrieved and permission context.

Actions attempted or completed.

Relevant logs, screenshots, correlation IDs and configuration versions.