Back to Legal
LG-01 · Legal

Incident Response Protocol

Public summary of how Alexa responds to security incidents.

DOCUMENT

LG-01

OWNER

Chief Information Security Officer

EFFECTIVE

January 1, 2026

REVIEWED

April 15, 2026

Class · PUBLIC·Review cycle · Semiannual

Purpose and scope

This Protocol describes the publicly-disclosable elements of Alexa Cybersecurity's incident response program. The full operational runbooks are classified RESTRICTED and not published; this document is intended for clients, regulators, and partners that require visibility into our incident-response posture.

It applies to any event that compromises, or has the reasonable potential to compromise, the confidentiality, integrity, or availability of Alexa systems or client data under our control.

Incident lifecycle

  • 01Detect — telemetry-driven detection across endpoint, network, identity, cloud, and SaaS surfaces, supplemented by external threat intelligence and customer reports.
  • 02Triage — Tier-1 SOC analysts validate, classify by severity (SEV-1 through SEV-4), and engage the Incident Commander for SEV-2 and above.
  • 03Contain — block, quarantine, isolate, or rotate as needed to halt active impact within established containment SLOs.
  • 04Eradicate — identify and remove the root cause, including persistence mechanisms.
  • 05Recover — restore affected services using verified-clean baselines; monitor for recurrence.
  • 06Learn — post-incident review (PIR) within 10 business days, with action items tracked to closure.

Severity definitions

  • 01SEV-1 — confirmed compromise of multi-tenant production data or a critical national-infrastructure client.
  • 02SEV-2 — confirmed compromise of a single tenant or significant disruption of Alexa services.
  • 03SEV-3 — limited exposure with effective containment in place.
  • 04SEV-4 — security event with no confirmed impact, retained for trend analysis.

Customer notification

For incidents affecting customer data, Alexa notifies the affected customer's designated security contact without undue delay and in any case no later than 72 hours after confirmation, consistent with GDPR Article 33 standards. Notification includes the nature of the incident, categories and approximate volume of data involved, likely consequences, and the measures taken or proposed to address the incident and mitigate adverse effects.

Regulatory notification

Where required by applicable law, Alexa or the affected client notifies the relevant supervisory authority within statutory timelines (e.g., GDPR 72 hours, U.S. state-specific breach notification laws, NIS2, DORA, SEC Item 1.05 of Form 8-K for material cybersecurity incidents).

Cooperation with law enforcement

Alexa cooperates with legitimate law-enforcement investigations under valid legal process. Customer data is disclosed only to the extent legally compelled or with the customer's express written consent.

Reporting an incident to Alexa

If you believe you have observed a security incident affecting Alexa systems or services, please contact us immediately: security@alexasecurity.net (PGP key on request), or for active in-progress incidents involving Alexa-managed services, the 24/7 SOC at the number provided in your service agreement.

/CONTROLLED_DOCUMENT

This document is the official, controlled version of LG-01 — Incident Response Protocol. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

April 15, 2026

NEXT REVIEW

Semiannual