Security & Incident Procedure
How suspected security and personal-data incidents are reported, assessed and handled.
Last updated: 3 October 2026
Report urgent concerns immediately. Do not include passwords, private keys or full payment-card details in email.
1. Reporting
Report a suspected security or personal-data incident to admin@ipcom.ie with the time observed, affected service, what happened and a safe contact number. Preserve relevant messages and evidence. Do not investigate by accessing data without authority.
2. Response process
- Record and triage: assign an internal reference, record awareness time, systems, data and people potentially affected, and appoint the response owner.
- Contain: protect accounts and systems, revoke exposed credentials, isolate affected components and preserve evidence without unnecessarily altering it.
- Assess: confirm whether personal data is involved, IPcom Limited's controller or processor role, likely consequences, affected people and the risk level.
- Notify: where acting as processor, notify the customer controller without undue delay. Where acting as controller and risk exists, assess notification to the Data Protection Commission within 72 hours of awareness. Notify affected people without undue delay where high risk is likely.
- Recover: remove the cause, restore safely, validate integrity, increase monitoring and communicate service status through an appropriate channel.
- Review: document decisions, notifications, evidence, remediation and lessons learned, including the reason where notification was not required.
3. Customer cooperation
Customers must promptly provide information reasonably needed to investigate an incident and remain responsible for their own regulatory decisions where they act as controller. IPcom Limited will provide available facts and updates without making unsupported assurances about cause or impact.