CUBE OneCare operates a structured incident response process designed to minimize impact and provide transparency. All incidents are tracked through a formal lifecycle with defined SLAs and post-incident review.
Automated monitoring detects anomalies via security event ingestion, rate abuse detection, and domain mismatch alerts.
Severity classification (critical/high/medium/low) determines response SLA and notification scope.
Lead responder assigned. Incident status transitions: open → acknowledged → mitigating.
Root cause identified and mitigated. Status transitions to resolved with timeline documentation.
Lessons learned documented. Incident closed after review. Preventive controls updated.
| Severity | Initial Response | Target Resolution | Examples |
|---|---|---|---|
| Critical | 15 minutes | 4 hours | Data breach, complete service outage |
| High | 1 hour | 8 hours | Partial outage, security vulnerability exploited |
| Medium | 4 hours | 24 hours | Performance degradation, non-critical bug |
| Low | 1 business day | 5 business days | Minor issue, feature request |
For Critical and High severity incidents affecting customer data or service availability, CUBE OneCare will: