DNZ Consulting LLC
Policies and compliance · NY registration 7798491
← All policies

Incident Response Policy

DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027

This policy states what DNZ Consulting LLC does when a security incident or a personal data breach happens.

1. Scope and ownership

This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.

The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.

2. What counts as an incident

3. Roles

RoleWhoResponsibility
Incident ManagerManaging MemberDeclares the incident. Runs the response. Makes every decision.
Security OfficerManaging MemberContains and investigates the incident. Collects evidence.
Data Protection OfficerManaging MemberDecides on regulator and customer notification. Answers data subjects.
CommunicationsManaging MemberWrites and sends every external message.

The company is small, so one person holds these roles. The company appoints a second responder in writing if it grows.

4. How to report an incident

5. Response steps

  1. Record. Write down the time, the reporter, and what they saw.
  2. Assess. Decide the severity within 4 hours. Decide whether personal data is involved.
  3. Contain. Isolate the system. Revoke the credential. Rotate the key. Block the account.
  4. Investigate. Find the cause and the scope. Identify every record that the incident touched.
  5. Notify. Follow section 6.
  6. Recover. Restore the service from a clean state. Confirm that the attacker is out.
  7. Review. Hold a review within 10 working days. Write the lessons. Change the controls.

6. Notification

7. Records

We record every incident, including the ones that need no notification. We keep the record for 5 years. The record holds the facts, the effect, and the action we took.

8. Testing

We walk through this plan one time each year with a test scenario. We record the result and we fix any gap.

9. Review

The Managing Member reviews this policy one time each year, and after every incident.