Incident Response

Incident Response & Breach Notification

How security incidents and data breaches are handled, and when and how customers are told.

Trust & Compliance Centre · Last reviewed: January 2026

At a glance

Do you have a documented incident response plan covering security breaches and data incidents? Yes Documented plan; summary below, full plan available under NDA
Can you commit to notifying customers of data breaches within 24 hours of discovery? Yes Affected customers are notified without undue delay, and within 24 hours of a breach being confirmed

Our incident response process

Assemblysoft maintains a documented incident response plan covering security breaches, data incidents, and service-affecting events on systems we build or operate for customers. The plan follows the recognised incident lifecycle:

  1. Detect and triage — incidents are identified through monitoring, alerts, platform notifications, or reports from customers and team members, and assessed for severity and scope.
  2. Contain — immediate steps to limit impact, such as isolating affected resources, revoking credentials, or taking a service offline where necessary.
  3. Investigate and eradicate — root cause analysis using audit logs and platform diagnostics, and removal of the cause.
  4. Recover — restoration of normal service, using backups and redeployment where required (see Business Continuity & Disaster Recovery).
  5. Review — a post-incident review recording what happened, what was affected, and what changes prevent recurrence.

Incidents are classified by severity, which determines response priority and who is engaged. Where an incident involves the Azure platform itself, Microsoft's incident process and status communications also apply.

Customer notification commitment

Where an incident affects a customer's systems or data, we notify that customer without undue delay, and in any event within 24 hours of confirming that a breach has occurred. Notification includes what is known at the time: the nature of the incident, the data or systems affected, actions taken so far, and a point of contact — with updates as the investigation progresses rather than waiting for a complete picture.

UK GDPR obligations

For personal data breaches, we support customers in meeting their own regulatory obligations under UK GDPR and the Data Protection Act 2018:

  • Where Assemblysoft acts as a processor, we notify the customer (the controller) without undue delay after becoming aware of a personal data breach, as required by Article 33(2), within the 24-hour commitment above.
  • Where Assemblysoft acts as a controller, notifiable breaches are reported to the Information Commissioner's Office (ICO) without undue delay and within 72 hours where required by Article 33(1), and affected individuals are informed where the breach is likely to result in a high risk to them (Article 34).
  • All breaches, notifiable or not, are recorded internally with their facts, effects, and remedial action.

Full plan available on request

The complete Incident Response Plan contains internal escalation contacts and technical playbooks, so it is not published. Customers can request it under NDA via hello@assemblysoft.com.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor