Enterprise clients should be able to understand how we respond to material incidents without us publishing exploitable playbooks. This commitment describes the control principles Raeburn applies across security, privacy and material service incidents.
Severity classification
Security, privacy and material service incidents are assessed and severity-classified according to factors such as affected systems or data, exploitability, operational impact, scope, customer impact and legal or contractual significance.
Maintained response procedures
Raeburn maintains incident-response procedures covering triage, containment, escalation, investigation, remediation, recovery and communication. Operational playbooks are not published where doing so could weaken security or expose sensitive response detail.
Customer and regulatory assessment
Material incidents trigger an assessment of customer, contractual, insurer, supplier and regulatory notification obligations. Notifications are made where required by applicable law, contract or the circumstances of the incident.
Evidence preservation
Relevant logs, alerts, records, timelines and other evidence are preserved where practical and appropriate to support investigation, decision-making, legal or regulatory obligations and lessons learned.
Containment and recovery
Response priorities include limiting further harm, protecting affected data and systems, restoring safe service and validating that remediation has addressed the identified cause or exposure.
Post-incident review
Material incidents are followed by a proportionate review of root cause, contributing factors, control effectiveness, communication and recovery. Corrective actions are tracked so incidents drive measurable improvement rather than ending when service is restored.
Third-party incidents
Where a supplier or subprocessor incident may affect Raeburn or client services, Raeburn assesses the impact, coordinates with the relevant supplier and applies the same notification and risk principles to the affected service.
Confidentiality and need-to-know
Incident information is shared on a need-to-know basis while investigation is active. Public or customer communications aim to be accurate, timely and proportionate without exposing exploit details, personal data or information that could worsen risk.
Published 27 August 2026. Review after material process, regulatory or service changes.