Version 1.0 · Draft · Owner: Security Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Next review: 11 July 2027
Define how Touch2Sign detects, responds to, contains, and recovers from information security incidents, including personal data breaches under GDPR Articles 33–34.
All incidents affecting:
| Level | Description | Examples | Response target | P1 Critical | Active breach, data exfiltration, full outage | DB exposed publicly, ransomware, mass document leak | Immediate — all hands |
|---|---|---|---|
| P2 High | Limited data exposure, partial outage, admin compromise | Single tenant data leak, signing API down | 1 hour |
| P3 Medium | Attempted attack, vulnerability with exploit path | Failed brute force, critical CVE in production dep | 4 hours |
| P4 Low | Minor issue, no data impact | Phishing email reported, scan noise | 24 hours |
| Role | Person | Responsibilities | Incident Commander (IC) | Robert | Coordinates response; comms; escalation |
|---|---|---|
| Technical Lead | Robert | Containment; forensics; remediation |
| DPO / Privacy Lead | Robert | Breach assessment; ICO/DPC notification; DSAR impact |
| Comms | Robert | Customer notification; status page |
| Legal | External counsel | Regulatory advice; law enforcement |
On-call rotation: Robert (sole operator) — email security@touch2sign.com; escalate to external counsel for P1 personal data breaches.
Sources: CloudWatch alarms, customer report, staff report, sub-processor notification, pentest finding.
| Scenario | Actions | Compromised admin account | Disable Cognito user; rotate sessions; review audit_log |
|---|---|
| Leaked API key / secret | Rotate in Secrets Manager; revoke old key; review access logs |
| Suspected document access | Identify affected document IDs; block signing tokens; notify customer |
| Sub-processor breach | Contact vendor; assess Touch2Sign data affected |
| DDoS / outage | AWS support; scale App Runner; CloudFront rules |
GDPR breach assessment worksheet:
```
INCIDENT [P1/P2/P3/P4]: [Short title]
Detected: [time UTC]
Impact: [description]
IC: [name]
Status: Investigating / Contained / Resolved
Next update: [time]
```
```
Subject: Touch2Sign security incident notification
We are writing to inform you of a security incident affecting Touch2Sign
services on [date].
What happened: [brief factual description]
Data affected: [categories — avoid overstating]
Actions taken: [containment steps]
Your actions: [if any — rotate tokens, notify signers, etc.]
Contact: security@touch2sign.com
We will provide updates within [24/48] hours.
```
Use official breach notification forms:
Include: nature of breach, DPO contact, likely consequences, measures taken.
recipients table audit_log for access from token | Field | Description | ID | INC-YYYY-NNN |
|---|---|
| Date detected | UTC timestamp |
| Severity | P1–P4 |
| Description | |
| Data breach? | Y/N |
| Subjects affected | Count / range |
| ICO/DPC notified? | Y/N/NA |
| Customers notified? | Y/N |
| Status | Open / Closed |
| Closed date | |
| Lessons learned |
| Contact | Email / phone | Security Lead | security@touch2sign.com |
|---|---|
| DPO | privacy@touch2sign.com |
| AWS Support | [Enterprise support case] |
| Legal counsel | [Firm contact] |
| ICO | 0303 123 1113 |
| DPC Ireland | +353 578 684 800 |
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com