Important:
This document is a professional draft, not legal advice. It must be reviewed against elyXion’s final legal entity details, implemented controls, suppliers, customer contracts, and actual operating practices before publication.
1. Purpose
This policy establishes elyXion’s approach to security incidents affecting systems, services, identities, data, infrastructure or suppliers.
2. Response Lifecycle
- Detection and reporting
- Triage and classification
- Containment
- Investigation and evidence preservation
- Eradication or corrective action
- Recovery and validation
- Communication and notification
- Post-incident review
3. Prioritisation
Incidents are prioritised by business impact, data sensitivity, affected customers, exploitability, disruption, legal obligations and potential continued harm.
4. Data Breaches
Suspected Personal Data Breaches are assessed without undue delay. Where elyXion acts as processor, affected controllers are notified according to the DPA and applicable law.
5. Lessons Learned
Material incidents receive a review covering root cause, control gaps, corrective actions, ownership and follow-up.
Security concerns may be reported to support@elyxion.eu.
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
