ALTA Security Incident Response SOP ALTA Standard Operating Procedure Security Breach / Cybersecurity Incident Response
- Purpose
This Standard Operating Procedure (SOP) defines the steps IT personnel must follow to identify, contain, eradicate, and recover from a cybersecurity incident or security breach affecting an ALTA staff member's account/device or ALTA infrastructure. The goal is to minimize damage, preserve evidence, restore normal operations quickly, and meet any regulatory or contractual notification obligations.
- Scope
This SOP applies to any suspected or confirmed security event, including but not limited to: Compromised user credentials (email, VPN, SSO, or application accounts) Phishing, smishing, or social-engineering attacks targeting staff Malware, ransomware, or virus infections on endpoints or servers Lost or stolen company devices (laptops, phones, tokens) Unauthorized access to systems, applications, or data Denial-of-service (DoS/DDoS) attacks against ALTA infrastructure Data leakage or suspected exfiltration of sensitive/confidential information Suspicious network activity, anomalous logins, or unauthorized configuration changes
- Incident Severity Classification
Applies To All IT Personnel Review Cycle Annually / As Needed Audience ALTA Team Members Version 1.0 Document Owner IT Department Effective Date May 1, 2026 Severity Definition Example Note: Severity may be re-classified as new information emerges during investigation. When in doubt, classify higher and escalate — it is easier to downgrade later than to recover from a delayed response.
- Roles & Responsibilities
Critical Active compromise of production systems, ransomware, or confirmed data breach involving sensitive/customer data. Ransomware encrypting file servers; confirmed exfiltration of customer PII. High Confirmed unauthorized access or malware on a single system with potential to spread. Compromised admin credentials; malware detected on a domain controller. Medium Isolated incident affecting a single user/device with limited blast radius. Employee clicked a phishing link; single laptop infected with adware. Low Suspicious activity with no confirmed compromise. Reported phishing email that was not opened/acted upon. Reporting Employee Immediately reports suspected incidents to IT/Help Desk; preserves evidence (does not delete emails, reboot, or attempt selfremediation). IT Support / First Responder Receives the report, performs initial triage, classifies severity, and escalates to the Incident Response (IR) Lead. Role Responsibility
- Immediate Reporting Requirements
CRITICAL: Any ALTA staff member who suspects of a security incident must report it immediately to IT Support — do not wait to confirm the issue yourself. Early reporting significantly limits damage.
5.1 How to Report Submit an urgent ticket via the IT Service Portal or itsupport@alta.org marked "Security Incident – Short Description"
5.2 What the Employee Should Do Immediately Disconnect the affected device from the network (unplug Ethernet or disable Wi-Fi) but do NOT power it off Do not attempt to delete files, emails, or run antivirus scans before IT is engaged Do not communicate with a suspected attacker (e.g., replying to a phishing email or ransom note) Write down what happened, when, and any error messages or suspicious activity observed (Include this information in the ticket) Directs containment and eradication efforts, coordinates the IR team, and makes escalation/notification decisions. Performs forensic analysis, malware removal, system hardening, and root-cause investigation. Director of IT & Security Approves major decisions (e.g., taking systems offline), authorizes external communications, and engages legal/compliance as needed. Legal / Compliance Determines regulatory notification obligations (e.g., breach of notification laws) and manages communications with affected parties or authorities.
- Incident Response Procedure
6.1 Phase 1 — Identification & Triage
- Log the incident in the IT Security ticketing system with a unique incident ID, timestamp, and reporting party.
- Talk to the reporting employee (or review system alerts) to gather: what happened, when it was noticed, systems/accounts involved, and any actions already taken.
- Classify the incident's severity per Section 3.
- Notify the Director of IT & Security immediately about High or Critical severity incidents. (Via Call or Email)
6.2 Phase 2 — Containment Containment goals are to stop the incident from spreading while preserving evidence for investigation.
- For a compromised account: immediately disable the account and force a password reset; revoke active sessions and refresh tokens.
- For a compromised device: isolate it from the network (disable network port/Wi-Fi via switch or MDM); do not wipe or reimage yet.
- For malware/ransomware: isolate affected systems from the network and shared drives to prevent lateral spread; disable affected user/service accounts. Notify Director of IT & Security and designDATA immediately.
- For a lost/stolen device: Contact designDATA to put a remote wipe for that device.
- For suspicious infrastructure activity (e.g., unauthorized firewall or server changes): Contact designDATA and notify Director of IT & Security. Review recent configuration change logs.
- Preserve evidence: capture system logs, memory dumps, and screenshots before making further changes, when feasible and safe to do so. Note: Do not power off a compromised system unless instructed by the IT Manager or Director of IT & Security — powering off can destroy volatile evidence needed for forensic analysis. Network isolation is generally preferred over shutdown.
6.3 Phase 3 — Eradication
- Identify and remove the root cause (e.g., malware, unauthorized access point, malicious email, vulnerable software).
- Patch or reconfigure the exploited vulnerability (e.g., apply security updates, close open ports, revoke leaked credentials/API keys).
- Run full antivirus/EDR scans on affected and adjacent systems to confirm no remaining threats.
- Reset credentials for all accounts that may have been exposed, including service accounts if applicable.
6.4 Phase 4 — Recovery
- Restore affected systems from known-clean backups where applicable, verifying backup integrity before restoration.
- Reconnect systems to the network in a staged, monitored manner rather than all at once.
- Re-enroll the employee's MFA device per the Duo Mobile Setup SOP if credentials or devices were reset.
- Monitor affected systems and accounts closely for 48–72 hours following recovery for signs of recurring compromise.
- Confirm with the employee/business unit that normal operations have resumed successfully.
6.5 Phase 5 — Notification & Escalation
- The Director of IT & Security determines, in consultation with Management and Legal/Compliance, whether the incident requires notification to customers, regulators, insurers, or law enforcement.
- For incidents involving suspected exposure of personal, financial, or customer data, escalate to Legal/Compliance immediately regardless of severity classification.
- Follow ALTA's external communications policy — only designated spokespeople may communicate with media, customers, or regulators.
6.6 Phase 6 — Post-Incident Review
-
Within 5 business days of resolution, the Director of IT & Security schedules a post-incident review ("lessons learned") meeting with internal IT team.
-
Document a full incident timeline, root cause, response actions taken, and impact assessment.
-
Identify process, tooling, or training gaps and assign owners/deadlines for corrective actions.
-
Update this SOP and related security controls based on findings, as needed.
-
Close the incident ticket with a final summary and archive supporting evidence per the data retention policy.
-
Incident-Specific Quick Reference Phishing email Do not click links or open attachments. Report via "Report Phishing" button or forward to itsupport@alta.com. Incident Type Immediate Actions
-
Communication Guidelines Limit incident details to those with a need to know; do not discuss active incidents on public or unsecured channels. If clicked/credentials entered, treat as a compromised account (see below). Compromised account Disable the account and revoke active sessions immediately. Force password reset and re-enroll MFA. Review mailbox rules/forwarding for signs of persistence (e.g., auto-forwarding to an external address). Malware / ransomware Isolate the device from the network; do not power off. Identify and disconnect any shared drives that may be affected. Escalate to Critical severity if file servers or multiple endpoints are impacted. Lost/stolen device Remotely lock/wipe immediately. (Contact MSP) Disable the associated user account and MFA device. Determine what data was stored locally on the device. Unauthorized infrastructure access Revoke the credentials/keys used for access. Review logs for scope of access and changes made. Escalate to Critical severity if production systems were altered. DDoS / availability attack Engage Director of IT & Security and MSP (designDATA) and enable DDoS mitigation (e.g., traffic scrubbing, rate limiting). Notify ALTA team of expected downtime. Monitor for a secondary attack used as a diversion. Keep the reporting employee informed of general status without disclosing sensitive investigative details.
-
Revision History 1.0 May 1, 2026 IT Security Team Initial release Version Date Author Description