TierSphere
Breach Response Runbook
This runbook defines the minimum response steps for suspected or confirmed unauthorized access to protected customer data, including student, teacher, and principal PII.
1. Identify and Escalate
- Any team member who becomes aware of a suspected incident must escalate it immediately to engineering leadership and the designated privacy or security lead.
- Preserve available evidence, including logs, request identifiers, timestamps, affected systems, and relevant user reports.
2. Contain
- Revoke exposed credentials or tokens.
- Disable affected integrations, public links, or user access paths where necessary.
- Isolate affected infrastructure or workloads when containment requires it.
3. Investigate
- Determine what happened, when it started, what systems were involved, and what data may have been affected.
- Confirm whether student, teacher, or principal PII was involved.
- Maintain an incident log capturing timeline, responders, actions taken, and open questions.
4. Notify
- Notify the affected district or customer as promptly as possible after confirming an unauthorized release and no later than seven calendar days after confirmed discovery when a New York Section 2-d timeline applies.
- Use the customer-designated privacy or security contacts and document the time and method of notice.
- If law enforcement or legal process affects notice timing, document the reason for any delay.
5. Remediate
- Patch the root cause.
- Rotate impacted secrets, keys, or passwords.
- Remove unauthorized access and verify that containment is holding.
- Add monitoring or controls needed to prevent recurrence.
6. Support Follow-Up Obligations
- Cooperate with the customer's investigation and response process.
- Preserve records needed for contractual, regulatory, or insurance reporting.
- Coordinate any required downstream notifications according to contract and law.
7. Close and Learn
- Complete a post-incident review.
- Record corrective actions and owners.
- Update training, runbooks, or technical controls if the incident exposed a process gap.
Related Policies
For customer-facing privacy commitments, review our Student Data Privacy page.