4. Policy
Incident Reporting
All employees are required to report any incidents, suspected incidents, or potential
vulnerabilities as soon as they are discovered. Reports may be submitted through internal
incident management tools, via email to Teravent’s Security Team, or directly to the employee’s
Line Manager. Members of the public who identify security vulnerabilities related to Teravent
systems are encouraged to submit a report to the designated security contact.
The Security Team actively monitors these channels and initiates an investigation into any
reported incidents within three working days of notification.
Incident Response
Upon identification of an incident affecting Teravent’s protected or sensitive information, the
company will act immediately to contain the incident and remove any unintended access. A
coordinated response will be established through designated communication channels, such as
secure messaging platforms, and alternative channels will be used if these are suspected to be
compromised.
An Incident Manager, typically an on-call engineer or a senior staff member depending on the
severity of the incident, will coordinate the response. The response team may include
representatives from Technology, Legal, Communications, Client Services, Human Resources, the
affected operational departments, and any other personnel deemed necessary to address the
incident.
If the incident involves theft, breach, or exposure of sensitive information, it will be
escalated to Teravent’s Leadership Team. The Incident Manager role may then be assumed by a
member of Leadership, and all communication related to the incident will be restricted to secure
and private channels to prevent unauthorized disclosure.
If legal proceedings, such as prosecution of a criminal, are deemed necessary, Teravent will
engage the relevant law enforcement authorities and carefully preserve all evidence in
accordance with legal requirements.
Communication and Responsible Disclosure
The Incident Manager will work in collaboration with Teravent’s Legal, Communications, and Human
Resources teams to determine the appropriate communication plan for the incident. This plan will
cover internal notification to employees, external disclosure to the public, and notification to
any individuals or entities directly affected.
Where required by law or regulation, Teravent will notify affected customers and stakeholders
about breaches or exposure of sensitive information. For incidents involving third-party
providers, Teravent will require that the provider notify the company of any breaches, and
Teravent will ensure that affected parties are informed in compliance with regulatory
obligations.
If a law enforcement official advises that a notification could compromise a criminal
investigation or national security, Teravent will comply with the official guidance. Written
instructions specifying the duration of the delay will be followed, and any oral statements will
be documented, with notification delayed for no longer than thirty days unless further written
guidance is received.