Overview
This runbook covers incident response for PensionsPortal.ie, an IORP II compliance platform handling GDPR-protected personal data (including AES-256 encrypted PPS numbers) for Irish pension trustees. Incidents must be handled in compliance with GDPR Art. 33 (72-hour breach notification), DORA Art. 17 (ICT incident reporting), and DORA Art. 13 (post-incident review).1. Incident Classification Matrix
When in doubt, escalate up. Downgrading a P0 to a P1 after assessment is always safer than under-escalating a genuine data breach. GDPR Art. 33 clock starts from when you “become aware” — not from when you finish your assessment.
2. On-Call Contacts
3. P0 — Data Breach Response Procedure
Follow these steps sequentially. Time targets are maximums — act faster where possible.Step 1 — Detect
An incident may be detected via:- Automated monitoring alerts (Vercel, Neon, Cloudflare)
- User or broker report
- Internal team discovery
- Third-party security researcher notification
#incident-YYYY-MM-DD) and assign an Incident Commander.
Step 2 — Contain (within 15 minutes)
Act to stop the bleeding before completing the full assessment. If an active external attack or breach is suspected:Step 3 — Assess (within 1 hour)
Query audit logs to identify the scope of suspicious activity:- Identify the attack vector (how did the breach occur?)
- Identify affected data categories (PII? PPS numbers? Compliance records? Documents?)
- Estimate the number of affected data subjects (members, users)
- Identify which tenants (brokers) are affected
- Determine whether PPS encryption key may be compromised
- Determine whether AUTH_SECRET may be compromised
Step 4 — Notify (within 72 hours — GDPR Art. 33)
Data Protection Commission (DPC) — GDPR Art. 33:- Notify at dpc.ie if any personal data is involved
- Use the DPC’s online breach notification form
- Include: incident date/time, data categories affected, estimated number of subjects, containment actions taken, remediation plan
- Notify if the incident qualifies as a “significant ICT incident” (see Section 4 below)
- Email: supervision@pensionsauthority.ie
- Subject line:
DORA Incident Notification — PensionsPortal.ie — [YYYY-MM-DD]
- Notify affected broker firms via their registered contact email
- Use the communication template in Section 7
Step 5 — Remediate
PPS_ENCRYPTION_KEY may be compromised, follow the PPS Encryption Key Rotation Procedure in Section 5 before anything else.
Additional remediation steps:
- Patch the identified vulnerability
- Reset credentials for any compromised accounts
- Review and tighten Cloudflare WAF rules
- Run full audit log review for the affected period
- Verify all containment measures are still active
- Re-enable normal operations only after remediation is confirmed
Step 6 — Post-Incident Review (within 5 business days — DORA Art. 13)
Write a post-mortem document covering:
File the completed post-mortem with the DPO for GDPR Art. 30 Records of Processing Activities.
4. DORA ICT Incident Reporting
Per DORA Art. 17, significant ICT incidents affecting pension scheme operations must be reported to the Pensions Authority.Classification as “Significant”
An ICT incident is significant if it:- Causes service unavailability affecting trustees’ ability to meet compliance obligations
- Results in data loss or corruption affecting pension records
- Involves a security breach affecting member PII or scheme data
- Disrupts critical functions for more than a defined threshold period
Reporting Timeline
DORA Notification Email Format
Send to: supervision@pensionsauthority.ie5. PPS Encryption Key Rotation Procedure
Follow these steps in order: Step 1 — Generate new encryption key:- Log in as a BrokerAdmin and view a member with a PPS number
- Confirm PPS decrypts and displays correctly
- Confirm the decryption is logged in
audit_logs - Log key rotation completion in
audit_logswith actorsystem
6. Rollback Procedure
For application rollback steps (reverting to a previous deployment), see Vercel Deployment Runbook. For database rollback (restoring to a pre-incident state), see Backup & Restore Runbook.7. Customer Communication Template
Use this template for communicating with broker firms and trustees during incidents. Send via email to the broker’s registered contact address.For confirmed data breaches involving a broker’s client data, the DPO must review and approve all external communications before they are sent. Do not send breach-related communications without DPO sign-off.