Operational resilience

Incident Response Commitment

Enterprise clients should be able to understand how we respond to material incidents without us publishing exploitable playbooks. This commitment describes the control principles Raeburn applies across security, privacy and material service incidents.

Severity classification

Security, privacy and material service incidents are assessed and severity-classified according to factors such as affected systems or data, exploitability, operational impact, scope, customer impact and legal or contractual significance.

Maintained response procedures

Raeburn maintains incident-response procedures covering triage, containment, escalation, investigation, remediation, recovery and communication. Operational playbooks are not published where doing so could weaken security or expose sensitive response detail.

Customer and regulatory assessment

Material incidents trigger an assessment of customer, contractual, insurer, supplier and regulatory notification obligations. Notifications are made where required by applicable law, contract or the circumstances of the incident.

Evidence preservation

Relevant logs, alerts, records, timelines and other evidence are preserved where practical and appropriate to support investigation, decision-making, legal or regulatory obligations and lessons learned.

Containment and recovery

Response priorities include limiting further harm, protecting affected data and systems, restoring safe service and validating that remediation has addressed the identified cause or exposure.

Post-incident review

Material incidents are followed by a proportionate review of root cause, contributing factors, control effectiveness, communication and recovery. Corrective actions are tracked so incidents drive measurable improvement rather than ending when service is restored.

Third-party incidents

Where a supplier or subprocessor incident may affect Raeburn or client services, Raeburn assesses the impact, coordinates with the relevant supplier and applies the same notification and risk principles to the affected service.

Confidentiality and need-to-know

Incident information is shared on a need-to-know basis while investigation is active. Public or customer communications aim to be accurate, timely and proportionate without exposing exploit details, personal data or information that could worsen risk.

What this page does not expose

We do not publish internal escalation contacts, detection thresholds, containment techniques, credentials, forensic procedures, detailed architecture dependencies or other operational information that could help an attacker evade or disrupt response.

Reporting and assurance

Security concerns can be reported through our Responsible Disclosure programme. Procurement and due-diligence teams can review this commitment alongside our Supplier Assurance Pack, Delivery Assurance Statement and Trust Centre.

Published 27 August 2026. Review after material process, regulatory or service changes.