We monitor systems and logs for signs of a security incident, and treat every credible report seriously.
Incidents are rated by severity and by whether personal data is affected, which decides how quickly and widely we respond.
We act to contain the incident, remove the cause, and restore normal, safe operation, using backups where needed.
Where personal data is affected, we notify the people involved and the authorities as the law requires, with what happened and what to do.
After an incident we review what happened and improve our defences to reduce the chance of it recurring.