What if CertNudge ever suffers a data breach?
CertNudge will investigate, contain and assess any suspected personal-data breach or security incident.
The actions taken, notifications required and timing will depend on the circumstances, the risks involved and the applicable legal requirements.
Not every security incident is a reportable breach
CertNudge must first investigate what happened, which information may be affected and the likely risk to the people involved.
How would CertNudge respond?
Investigate the incident
CertNudge would review the available information to understand what happened and which systems, accounts or records may be affected.
Contain the issue
Appropriate steps would be taken to limit further access, loss or misuse while the investigation continues.
Assess the risk
CertNudge would assess the type of information involved, the possible consequences and the level of risk to affected people.
Take required follow-up action
This may include remediation, notifications and additional account or security measures where appropriate.
Would the ICO be notified?
CertNudge will notify the Information Commissioner's Office when notification is required by applicable data-protection law.
The applicable deadline and information provided will depend on the incident and its legal assessment.
Not every security event or suspected incident requires an ICO notification.
Would affected users be contacted?
CertNudge will contact affected people when this is required by law or is otherwise appropriate to help them understand and reduce a meaningful risk.
The response will depend on the incident
CertNudge does not promise that every incident will result in notification to every user, a public report or a mandatory password reset. Those actions will be considered where relevant to the circumstances.
What should I do if I notice something suspicious?
- Change your password if you believe it may have been exposed.
- Enable authenticator-app two-factor authentication if it is not already active.
- Review organisation users and remove anyone who no longer needs access.
- Review active share links and revoke any that are no longer required.
- Record the date, time and details of any unusual activity you noticed.
Report suspected unauthorised access promptly
Email support@certnudge.co.uk with your organisation name and a description of the concern. Do not send passwords, recovery codes, full card details or unnecessary tenant personal data.