Legal, Compliance & Risk
A breach isn't just an incident — it's a clock that starts ticking.
Security incidents share the discipline of outage response but carry different obligations — notification deadlines, evidence rules, and a regulator who will ask what you knew and when.
Other typical workflows in this domain: contract review & approval, data privacy compliance, and compliance framework management.
Sample workflow: Security incident response
Automation = deterministic, rule-based. AI = judgement at the step level — drafting, scoring, matching. Human = decision, relationship, or anything that sets a precedent.
01Detection
AutomationEndpoint, identity, and log monitoring with tuned alerting.
02Triage
AIAlerts triaged and classified against a severity ladder.
03Declaration
HumanIncident declared; the response team assembled with clear roles.
04Containment
AutomationAccounts disabled, sessions revoked, hosts isolated — automated where pre-approved.
05Investigation
AIScope established — entry point, lateral movement, what was accessed.
06Recovery
HumanThreat removed, systems restored clean, credentials rotated.
07Impact assessment
HumanPersonal-data impact assessed — the gate that starts the regulatory clock.
08Notification
HumanNotifications made per obligations — regulator, customers, insurers.
09Customer comms
HumanAffected customers told what happened, honestly.
10Evidence
AutomationEvidence preserved and the timeline logged throughout.
11Post-incident review
HumanBlameless review — how it got in, what slowed response, what changes.
12Hardening
HumanControl improvements implemented and tracked to completion.