Reporting
Suspected incidents are submitted through the designated security service with a clear description, affected systems and an initial severity assessment.
Assessment and Classification
The Security Authority validates the report and classifies operational impact, information exposure, affected authority and continuity risk.
Containment and Recovery
The responsible technical and administrative authorities coordinate containment, restoration and credential action according to the confirmed scope.
Post-Incident Record
Material incidents receive a documented outcome covering cause, response actions, recovery status and any required control improvements.