Incident response
What happens when something goes wrong.
Every production system will eventually experience an incident. The question is whether the response is coordinated or chaotic. Our incident response process is documented, rehearsed, and contractually committed to the timelines below.
Within 15 minutes
Detection & initial triage
Automated monitoring detects anomaly. On-call engineer is paged. Severity is classified (P0-P3). Client primary contact is notified for P0 and P1 incidents.
Within 1 hour
Incident declared & team assembled
Incident commander assigned. War room opened. Client stakeholders briefed. Preliminary impact assessment completed. Runbook activated where applicable.
Ongoing
Containment & resolution
Mitigation actions taken. Status updates issued every 30 minutes to client during active incident. All actions logged with timestamps. Rollback executed if safer than forward fix.
Within 48 hours
Post-incident report
Root cause analysis delivered. Timeline of events documented. Corrective actions identified and assigned. Regulatory notification assessed (HIPAA 72hr, GDPR 72hr where applicable).
Data breach notification
Where an incident involves a personal data breach, VARP follows mandatory notification timelines: GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware. HIPAA requires notification of affected individuals within 60 days and HHS within 60 days of discovery. We will notify the client immediately upon confirmation of a breach and will assist with all required regulatory notifications.