We're sorry but this app doesn't work properly without JavaScript enabled. Please enable it to continue.

This lesson's interactive features are locked, please to keep using them

Incident Reporting

During an incident, you need to report what you've confirmed. Depending on the severity and impact, that may mean reporting to leadership, customers, regulators, or all three.

As a developer, your job is to get clear, accurate information to the right people so they can decide who needs to hear what. Usually that means quickly escalating confirmed facts and unknowns through your incident process. Do not guess or speculate.

Notification Duties

Some incidents create legal, regulatory, contractual, or breach-notification duties. For example, under GDPR Article 33, controllers must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to people's rights and freedoms.

This course is not legal advice! Follow your company's policies and involve its legal or compliance team.

If you'd like to read more, check out the OWASP SCS Incident Response Handbook or NIST SP 800-61 Rev. 3.