Incident Response Protocol
Public summary of how Alexa responds to security incidents.
DOCUMENT
LG-01
OWNER
Chief Information Security Officer
EFFECTIVE
January 1, 2026
REVIEWED
April 15, 2026
Purpose and scope
This Protocol describes the publicly-disclosable elements of Alexa Cybersecurity's incident response program. The full operational runbooks are classified RESTRICTED and not published; this document is intended for clients, regulators, and partners that require visibility into our incident-response posture.
It applies to any event that compromises, or has the reasonable potential to compromise, the confidentiality, integrity, or availability of Alexa systems or client data under our control.
Incident lifecycle
- 01Detect — telemetry-driven detection across endpoint, network, identity, cloud, and SaaS surfaces, supplemented by external threat intelligence and customer reports.
- 02Triage — Tier-1 SOC analysts validate, classify by severity (SEV-1 through SEV-4), and engage the Incident Commander for SEV-2 and above.
- 03Contain — block, quarantine, isolate, or rotate as needed to halt active impact within established containment SLOs.
- 04Eradicate — identify and remove the root cause, including persistence mechanisms.
- 05Recover — restore affected services using verified-clean baselines; monitor for recurrence.
- 06Learn — post-incident review (PIR) within 10 business days, with action items tracked to closure.
Severity definitions
- 01SEV-1 — confirmed compromise of multi-tenant production data or a critical national-infrastructure client.
- 02SEV-2 — confirmed compromise of a single tenant or significant disruption of Alexa services.
- 03SEV-3 — limited exposure with effective containment in place.
- 04SEV-4 — security event with no confirmed impact, retained for trend analysis.
Customer notification
For incidents affecting customer data, Alexa notifies the affected customer's designated security contact without undue delay and in any case no later than 72 hours after confirmation, consistent with GDPR Article 33 standards. Notification includes the nature of the incident, categories and approximate volume of data involved, likely consequences, and the measures taken or proposed to address the incident and mitigate adverse effects.
Regulatory notification
Where required by applicable law, Alexa or the affected client notifies the relevant supervisory authority within statutory timelines (e.g., GDPR 72 hours, U.S. state-specific breach notification laws, NIS2, DORA, SEC Item 1.05 of Form 8-K for material cybersecurity incidents).
Cooperation with law enforcement
Alexa cooperates with legitimate law-enforcement investigations under valid legal process. Customer data is disclosed only to the extent legally compelled or with the customer's express written consent.
Reporting an incident to Alexa
If you believe you have observed a security incident affecting Alexa systems or services, please contact us immediately: security@alexasecurity.net (PGP key on request), or for active in-progress incidents involving Alexa-managed services, the 24/7 SOC at the number provided in your service agreement.
/CONTROLLED_DOCUMENT
This document is the official, controlled version of LG-01 — Incident Response Protocol. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.
VERSION
2026.1
REVIEWED
April 15, 2026
NEXT REVIEW
Semiannual


