Know before you click

Incident Response Plan (IRP)

Organization: CliqSpend

Version: 1.0

Effective Date: October 2023 / Updated for 2026

Document Classification: Internal / Confidential

1. Purpose & Objectives

The purpose of this Incident Response Plan (IRP) is to establish a structured, repeatable framework for detecting, containing, eradicating, and recovering from cybersecurity incidents at CliqSpend.

The primary objectives are to:

  • Minimize operational disruption and financial loss.
  • Protect sensitive customer data, payment information, and authentication credentials.
  • Ensure regulatory compliance (e.g., GDPR, CCPA, PCI-DSS, and local financial regulations).
  • Facilitate clear internal and external communication during an emergency.

2. Scope

This plan applies to all systems, networks, applications (web, mobile, and API endpoints), cloud infrastructure (AWS/GCP/Azure), third-party integrations, and physical assets owned, operated, or managed by CliqSpend, as well as all employees, contractors, and third-party vendors.

3. The Incident Response Team (IRT) & Roles

The CliqSpend IRT is a cross-functional unit responsible for executing this plan.

RoleResponsibilitiesPrimary Contact
Incident Commander (IC)Overall coordination, resource allocation, and final decision-making.Head of Security / CTO
Lead Technical InvestigatorRoot cause analysis, log analysis, containment strategy, and digital forensics.Senior Security Engineer / DevOps Lead
Communications LeadManaging internal updates, customer notifications, and PR statements.Head of Communications / Marketing
Legal & Compliance LeadManaging regulatory reporting, legal risk, and law enforcement liaison.General Counsel / Compliance Officer
Customer Support LeadHandling user queries, providing scripts, and tracking affected accounts.Head of Customer Success

4. NIST Incident Response Lifecycle Phases

CliqSpend adopts the standard NIST 800-66/2-61 framework consisting of five phases:

Phase 1: Preparation

  • Tooling: Continuous monitoring tools, SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), and WAF (Web Application Firewall) must be active and logging.
  • Access Control: Enforce Principle of Least Privilege (PoLP) and Multi-Factor Authentication (MFA) across all administrative and production dashboards.
  • Training: Conduct annual security awareness and phishing simulations for all CliqSpend employees.
  • Regular Testing: Perform table-top exercises semi-annually and penetration testing annually.

Phase 2: Identification (Detection & Analysis)

An incident is identified through alerts from automated tools, customer support tickets, third-party disclosures, or employee observation.

  • Triage: The on-call engineer evaluates the alert to determine if it’s a false positive or a legitimate security event.
  • Severity Matrix:
    • Sev 1 (Critical): Active data breach, unauthorized access to core financial databases, system-wide ransomware, or major financial fraud.
    • Sev 2 (High): Targeted attack on a single high-profile user account, isolated malware infection, or unauthorized API scraping.
    • Sev 3 (Medium): Non-exploited vulnerability discovered, minor policy violation, or failed brute-force attack.
    • Sev 4 (Low): Spam, reconnaissance traffic, or negligible events.

Phase 3: Containment

The goal is to limit the scope and impact of the incident immediately.

  • Short-term Containment:
    • Isolate compromised servers or virtual machines from the network.
    • Revoke compromised API keys, OAuth tokens, and administrative sessions.
    • Temporarily freeze suspicious user accounts or suspicious card-spending transactions if financial fraud is suspected.
  • Evidence Preservation: Take memory dumps, snapshot compromised cloud instances, and preserve logs before making disruptive configuration changes to ensure chain of custody for forensics.

Phase 4: Eradication

Find and eliminate the root cause of the incident.

  • Remove malware, backdoors, unauthorized user accounts, or malicious web shells.
  • Patch vulnerabilities or misconfigurations (e.g., exposed S3 buckets, unpatched API endpoints) that allowed the attacker entry.
  • Rebuild compromised systems from known-clean golden images or code repositories.

Phase 5: Recovery

Bring systems back to normal operations securely.

  • Restore clean databases and systems from secure, offline/immutable backups if data integrity was compromised.
  • Gradually bring services back online while closely monitoring network traffic, database queries, and system logs.
  • Enforce a mandatory password and token reset for affected or all users if credential stuffing or widespread compromise occurred.

Phase 6: Lessons Learned (Post-Incident Activity)

  • Post-Mortem Meeting: Conduct a blameless post-incident review within 5 business days of resolution.
  • Documentation: Answer key questions: What happened? At what times? How did our defenses respond? What gaps were exposed?
  • Action Items: Update security controls, rewrite detection rules, improve automation, and patch documentation gaps to prevent recurrence.

5. Communication Plan

Clear, accurate, and timely communication is vital to maintaining user trust and regulatory compliance.

  • Internal Communication: The IRT will use an out-of-band communication channel (e.g., dedicated secure messaging/backup workspace) to prevent attackers from monitoring internal response discussions.
  • Customer Notification: If user PII (Personally Identifiable Information), financial information, or credentials are compromised, CliqSpend will notify affected users via email and in-app alerts within statutory timeframes (e.g., GDPR 72-hour rule). Notifications will include:
    • What happened.
    • What data was involved.
    • Steps CliqSpend has taken.
    • Actionable steps the user should take (e.g., change passwords, monitor bank statements).
  • Regulatory & Law Enforcement Notification: The Legal Lead will notify relevant data protection authorities, financial regulators, and law enforcement agencies as mandated by applicable laws.