Security & Compliance

Incident Response Policy

How Skoolfly detects, contains, investigates and recovers from security incidents.

1. Policy Statement

Skoolfly maintains a structured approach to detecting, reporting, containing, investigating and recovering from security incidents. This policy defines incident types, severity levels, roles and response steps to minimise impact and prevent recurrence.

2. Purpose

The purpose of this policy is to enable a timely, coordinated response that protects data, systems and users, meets legal and contractual obligations, and improves security from lessons learned.

3. Scope

This policy applies to all security incidents affecting Skoolfly systems, data, personnel or third parties, including suspected or confirmed events involving personal data, accounts, infrastructure, applications, networks or physical security.

4. Definitions and Incident Types

Security incident: an event that jeopardises the confidentiality, integrity or availability of information or systems.

Personal data breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Account compromise: unauthorised access to a user or administrative account.

Malware or ransomware: infection of systems by malicious software.

Denial of service: disruption of availability through excessive traffic or abuse.

Misconfiguration or data exposure: accidental exposure of data or systems.

Insider misuse: inappropriate or unauthorised activity by personnel.

5. Incident Severity Levels

CriticalLikely or confirmed serious impact on data, systems or users; requires immediate response.
HighSignificant potential impact; response initiated without delay.
MediumLimited impact or contested breach; investigation within a defined period.
LowMinor or suspected event requiring assessment and documentation.

6. Roles and Responsibilities

Incident responderCoordinates detection, containment and investigation.
Security ownerOversees response, escalation and compliance with notification obligations.
Engineering / DevOpsTechnical containment, eradication and recovery actions.
CommunicationsManage internal and external communications, including school and user notices.
Legal / Data Protection OfficerAdvise on legal, regulatory and breach-notification requirements.
All personnelReport suspected incidents immediately through the defined channel.

7. Detection and Reporting

Suspected incidents are reported without delay, with as much detail as is known.

Users are expected to report anomalies rather than investigate alone.

Monitoring, alerts and user reports feed a single incident intake process.

No person is penalised for promptly reporting a suspected incident in good faith.

8. Response Phases

Responses follow a defined set of phases, applied proportionately to the severity of the incident.

Preparation: roles, tools and procedures are maintained and tested before incidents occur.

Identification: the incident is confirmed, scoped and classified.

Containment: immediate steps limit further damage or exposure.

Eradication: the cause is removed and affected systems secured.

Recovery: services are restored and verified to be working correctly.

Lessons learned: findings are reviewed and improvements implemented.

9. Communication and Disclosure

Communication about incidents is coordinated to ensure accuracy and consistency. Schools, users, clients and the public are informed where appropriate, in accordance with contractual and legal requirements, without providing information prematurely that could aid attackers or compromise the investigation.

10. Legal and Regulatory Notification

Where required, incidents are notified to regulators and affected individuals within applicable timeframes, in line with the Data Protection & Privacy Policy and applicable law. Notification decisions are documented.

11. Documentation

Significant incidents are documented, including timeline, root cause, impact, actions taken and preventive measures. Documentation is retained in accordance with the Data Retention Policy and treated as confidential.

12. Review

This policy is reviewed at least annually, after significant incidents, and when response tools, systems or obligations change materially.